Western Australia spent decades as the only mainland state without public sector privacy legislation. That changed in July 2026, and the transition is unusually abrupt because there was nothing to transition from. Agencies did not adjust an existing framework; they acquired one.
The businesses supplying those agencies are in the same position. Contracted service providers here have never been asked to demonstrate how they handle personal information on behalf of the state, and they are now being asked with a breach reporting scheme arriving in January 2027 behind the question.
Nathan ISO Consulting implements privacy information management systems for Western Australian organisations, standalone under the 2025 revision of the standard or alongside an existing ISO 27001 certification.
Three features of the WA regime worth understanding early
First, it sets out Information Privacy Principles governing how public entities collect, store, use and disclose personal information, and those obligations extend to contracted service providers through their agreements. Second, a notifiable information breach scheme commences in January 2027, requiring serious breaches to be reported to the Information Commissioner and to affected individuals. Third, and unusually, the legislation includes provisions supporting Aboriginal data governance, requiring Aboriginal communities to be involved where information affecting them is shared. That third element has no direct equivalent elsewhere in Australian privacy law and should be approached with care rather than treated as a compliance checkbox.
Why ISO 27701 matters for Western Australian organisations
The starting position explains most of it. Organisations in other states built privacy capability incrementally over twenty years. Western Australian suppliers are being asked to demonstrate it having never been required to have it, against principles published recently, with limited local precedent about what agencies will accept as sufficient.
A certified privacy management system resolves that ambiguity efficiently. Rather than negotiating what adequate looks like with each agency, a supplier presents an assessed structure and maps it to the principles. That saves considerable effort across a portfolio of agency contracts, and it is defensible in a way that a privacy policy is not.
The change in the standard makes it accessible. Since October 2025, ISO 27701 can be certified independently. An organisation whose exposure is personal information rather than broad information security no longer has to fund a full security programme first, which matters for the community services, health and education providers who deliver a large share of WA government services.
Legal and regulatory compliance in Western Australia
| Obligation | What it involves |
|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles | Federal rules on collection, use, disclosure, accuracy, protection and access for private organisations above the turnover threshold |
| Notifiable Data Breaches scheme (Cth) | Assessing whether serious harm is likely and notifying affected individuals and the federal regulator, with no fixed period specified |
| Privacy and Responsible Information Sharing Act 2024 (WA) | Information Privacy Principles applying to WA public entities and reaching contracted service providers through agreements |
| Notifiable information breach scheme (WA) | Reporting of serious information breaches to the Information Commissioner and affected individuals, commencing January 2027 |
| Responsible information sharing framework | Structured decision-making and transparency where public entities share information for permitted purposes |
| Aboriginal data governance provisions | Involvement of Aboriginal communities where information affecting them is shared, described as the first such mechanism in Australian legislation |
| Statutory tort for serious invasions of privacy | In force federally since June 2025, allowing individuals to bring direct claims |
| Automated decision-making disclosure | Privacy policies must disclose significant automated decisioning, with the grace period ending 10 December 2026 |
WA obligations reach suppliers through their agency agreements rather than by direct operation of the Act, so the contract determines what applies. We read it during scoping.
Perth and regional WA coverage
| Location | Activity | Privacy exposure |
|---|---|---|
| Government precincts | Departments, agencies, statutory bodies | New Information Privacy Principles and the approaching breach scheme |
| Perth CBD and West Perth | Professional services, corporate functions, contracted providers | Agency agreements and workforce information |
| Murdoch and QEII precinct | Hospitals, health services, medical research | Patient information handled under federal and now state frameworks |
| Subiaco and Osborne Park | Health technology, education services, community organisations | Client records held on behalf of agencies |
| Joondalup and Rockingham | Education, community and disability services, local government | Service delivery on behalf of public entities |
| Regional WA service providers | Health, community and remote service delivery | Information about people in small communities where re-identification risk is high |
| Aboriginal community controlled organisations | Health, community and land management services | Data governance provisions requiring community involvement in information sharing |
| Technology and platform businesses | Software, analytics, managed services | Processor obligations and cross-border transfers |
| Resources and engineering | Workforce administration, contractor management | Employee and contractor information at scale across rosters |
Standalone or combined
Independent certification arrived with the 2025 revision, which does not make it right for every organisation. Two questions usually settle it.
Read the last few contracts and check which certificate appears by name, if any. In a market where the regime is new, agencies are still forming expectations, and some are asking for privacy capability specifically while others default to security language. That distinction determines which route serves you better.
If not, going independent means a tighter build and less to maintain afterwards. Community service organisations, allied health practices, training providers and membership bodies usually fall into this group. Once commercially sensitive material enters the picture, or systems where downtime genuinely hurts, pairing the two becomes the better economics since the governance layer gets built a single time.
Our delivery model in Western Australia
Everything starts with tracing the information itself: what comes in, its origin, the authority relied on, who touches it afterwards, whether it crosses state or national borders, and the point at which it should cease to exist. Western Australian engagements add a further step here, separating what you hold for an agency from what you hold on your own account, since distinct principles attach to each. Role determination is then done activity by activity, followed by notices, the applicability statement, handling of individual rights, a breach runbook answering both the federal harm test and the state reporting obligation, and retention scheduling.
Independent scope remains limited among accredited bodies. Confirming who actually holds it precedes any recommendation from us. We then agree commercial terms and timing, and build readiness through an audit run against the standard and your principle-level duties in one pass. We attend throughout.
The state framework is new enough that guidance keeps arriving, and the reporting obligation lands in January 2027. Periodic audits, surveillance preparation and tracking developments that touch your position all remain ours, as does refreshing the information map whenever services, suppliers or arrangements shift.
Your deliverables
Where Perth ISO 27701 projects go wrong
Who certifies you, and where we fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Which accredited body you engage, on what terms and to what timetable, is work we take off you, matched against scope, sector and the audit approach that fits how you operate. Both assessment stages are attended by our people, and resolving whatever gets raised belongs to us rather than arriving as a list once the assessor leaves. Check one thing yourself first: that the JAS-ANZ register lists the body as accredited for your particular scope. Certificates from unaccredited providers cost little and take days, and procurement teams reject them regularly enough that the check pays for itself.
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Correct. Western Australia was the last mainland state without one. Agencies and their suppliers are acquiring privacy capability rather than adjusting an existing framework, which makes this transition sharper than reforms elsewhere.
Through your agency agreements rather than by direct operation of the Act. Public entities pass obligations to contracted service providers, and what you have taken on depends on the contract wording. We review it during scoping.
The notifiable information breach scheme commences in January 2027, requiring serious information breaches to be reported to the Information Commissioner and affected individuals. Suppliers are already being asked how they would support that obligation.
Independent certification became available with the 2025 edition. Material saying otherwise describes the earlier version, which operated only as an extension. For WA community services, health and education providers the standalone route often fits better.
The legislation includes a mechanism requiring Aboriginal communities to be involved where information affecting them is shared, described as the first of its kind in Australia. It warrants genuine engagement rather than treatment as a documentation requirement.
Compliance is a legal state; certification evidences a managed approach toward it. We map the control set against both the state and federal principles so each obligation can be traced to where it is satisfied.
Nearly always both, and it shifts depending on what you are doing. Handling agency material under direction puts you in one category; choosing how your own staff or customer records get used puts you in the other. The determination is made per activity.
You need an account of which automated systems drive or substantially influence decisions that matter to people, together with policy wording that says so. Assembling that record is the work most organisations have yet to begin.
Follow the timetable your certification body issues. Most of what you have written remains sound. The work is architectural, turning the applicability statement into a document that functions independently and clearing out dependencies on a companion security certificate.
Independently, expect fourteen to twenty-six weeks, less if a security certificate is already held. Mapping the information governs timing, and anyone holding both agency-entrusted and own-account records should plan for the longer end.
Send us the agency agreement
The contract schedule setting out your information handling obligations tells us more in one reading than a scoping workshop would. If none exists yet, the data map is where we begin.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving