WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Something changed in October 2025 that most privacy content aimed at Sydney businesses has not caught up with. ISO/IEC 27701 stopped being an extension to ISO 27001 and became a standalone management system standard. An organisation can now be certified to it on its own.

The commercial consequence is direct. A Sydney organisation whose exposure sits in personal data rather than in systems and intellectual property can now certify against the thing that actually matters, without first funding a full security programme it did not need. Clinics, colleges, member associations, staffing platforms and customer data businesses all fall into that bracket.

Nathan ISO Consulting implements privacy information management systems for Sydney organisations, standalone or alongside an existing ISO 27001 certification.

Looking for an ISO 27701 Privacy Consultant in Sydney?

Why ISO 27701 Matters for Sydney Businesses

Sydney concentrates the sectors that hold the most sensitive personal information in the country: financial services, health, insurance, education and the technology businesses serving all of them. It also concentrates the regulatory attention that follows, because the OAIC’s largest matters tend to involve organisations headquartered here.

The obligations have been sharpening steadily rather than dramatically. Penalties increased at the end of 2024. A statutory tort for serious invasions of privacy came into force in June 2025, meaning individuals can now sue directly rather than relying on a regulator to act. And the automated decision-making transparency obligation comes out of its grace period on 10 December 2026, which will require many Sydney organisations to disclose something they have never mapped.

Against that, the practical problem in most organisations is not attitude but visibility. Very few Sydney businesses can say precisely what personal information they hold, where it came from, who processes it and how long it stays. Everything a privacy programme does depends on answering that, and it is where we start.

Legal and Regulatory Compliance in NSW

ObligationWhat It Involves
Privacy Act 1988 and the 13 Australian Privacy PrinciplesCollection, use, disclosure, quality, security, access and correction obligations for organisations above the turnover threshold and targeted small businesses
Notifiable Data Breaches schemeAssessment and notification where a breach is likely to result in serious harm. Australian law imposes no 72-hour deadline, unlike the GDPR
Statutory tort for serious invasions of privacyIn force since June 2025, allowing individuals to bring direct claims for intentional or reckless serious invasions of privacy
Automated decision-making transparencyPrivacy policies must disclose where automated systems make or substantially assist decisions significantly affecting rights, with the grace period ending 10 December 2026
Privacy and Personal Information Protection Act 1998 (NSW)Information protection principles applying to NSW public sector agencies and, through contract, to their service providers
Health Records and Information Privacy Act 2002 (NSW)Health privacy principles applying to health information held by NSW public and private sector organisations
Cross-border disclosure under APP 8Accountability for personal information disclosed to overseas recipients, including offshore processing and cloud arrangements
Privacy Amendment (Personal Data Protection) Bill 2026An exposure draft proposing changes to the definition of personal information, a fair and reasonable test and tightened breach obligations. Not law

The Health Records and Information Privacy Act catches many private Sydney health providers who assume only the Commonwealth Privacy Act applies to them. We check this during scoping.

Sydney Industries and Economic Zones We Work Across

Precinct or ZoneWho Operates TherePrivacy Exposure
Sydney CBD and BarangarooBanks, insurers, wealth managers, advisory firmsCustomer financial data, credit information, automated decisioning
North Sydney and ChatswoodInsurance, corporate shared services, health insurersClaims data, health information held by insurers, offshore processing
Westmead and RandwickHospitals, medical research, pathology, health technologyHealth information under both Commonwealth and NSW health privacy law
Surry Hills, Pyrmont and AlexandriaSaaS platforms, martech, adtech, digital agenciesProcessor obligations, tracking data, cross-border transfers
Parramatta and Western SydneyNSW agency offices, health administration, community servicesPPIP Act obligations reaching contracted service providers
Macquarie ParkPharmaceuticals, medical devices, technologyClinical trial data, research participants, employee information
Education precinctsUniversities, colleges, training providers, edtechStudent records, international student data, research data
Recruitment and workforce servicesStaffing platforms, assessment providers, payroll bureausCandidate data, background checking, automated screening

Which Route Suits a Sydney Business?

The standalone option is new, which does not automatically make it right. The decision usually resolves within one conversation once two things are established: what your customers are actually naming in their contracts, and whether you carry information security exposure that exists independently of personal data.

Route One – Privacy on Its Own

Fits where personal information is the exposure and nobody has asked for security certification. Sydney clinics and allied health groups, independent schools and colleges, membership and professional bodies, recruitment and workforce platforms, and customer data businesses commonly sit here. The scope is narrower and the ongoing maintenance lighter.

Route Two – Privacy Alongside Security

Fits where you hold ISO 27001 already or a buyer has named it. Governance, risk methodology, audit and review are built once and serve both, so the incremental effort is modest compared with either project standing alone. Most Sydney financial services and SaaS clients end up here.

A quick diagnostic if you are undecided: pull the last three supplier questionnaires you completed and see which standard the buyer named. That answers it more reliably than an internal debate.

Not sure whether standalone or combined suits your organisation?

How Nathan ISO Consulting Helps

Implementation

Everything begins with mapping the data itself: what arrives, from where, on what basis, who handles it downstream and when it is supposed to disappear. Role determination follows, taken activity by activity rather than declared once for the whole business, since a platform company handling client records under instruction stands in a different position from the same company deciding how to use its own candidate database. The build then covers external notices, the applicability statement, access and correction handling, an incident runbook calibrated to the serious harm threshold, assessment methodology, retention scheduling and controls over offshore disclosure.

Certification Support

Assessor coverage for the standalone route is still catching up with the revision, so not every accredited body can currently take it on. We verify who genuinely holds scope before making a recommendation, run the commercial process, and prepare you through an audit tested against the standard and your principle-level obligations together, with a documented review. Both assessment stages are attended.

Ongoing Consulting

Australian privacy law is in active reform, and a system built to today’s obligations will need adjusting. We run annual internal audits, prepare you for surveillance, monitor reform developments that affect your scope, and update the inventory as products, suppliers and data flows change.

What You Receive

  • Personal information inventory. What you hold, where it came from, where it lives, who touches it and how long it stays. The foundation everything else depends on.
  • Role determination. Controller or processor, documented activity by activity and mapped back to your obligations under Australian law.
  • Statement of Applicability. Standalone, or combined with an existing ISO 27001 Statement where both are held.
  • Breach assessment runbook. Built to the serious harm test in Australian law rather than to a European clock that does not apply here.
  • Privacy impact assessment methodology. Templates, thresholds and worked assessments for your highest-risk processing activities.
  • Automated decision-making register. Where automated systems make or substantially assist significant decisions, ahead of the December 2026 disclosure obligation.

Where Sydney ISO 27701 Projects Go Wrong

  • Starting with a policy rather than an inventory, which produces a document describing processing the organisation may or may not perform
  • A breach runbook copied from a GDPR template, applying a 72-hour deadline that Australian law does not impose and missing the serious harm assessment that it does
  • Role determination made once at organisation level rather than activity by activity, which puts the wrong controls in scope
  • Retention schedules written and never operationalised, so the organisation still holds records it committed to destroying
  • Offshore processing and cloud arrangements left out of cross-border disclosure controls under APP 8
  • Automated decisioning unmapped, with the December 2026 obligation approaching and no inventory to disclose from

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

We shortlist JAS-ANZ accredited certification bodies against your scope, sector and preferred audit approach, manage the quote process on your behalf, and attend Stage 1 and Stage 2 with you. Findings raised at either stage are ours to close out, not yours to inherit. Before engaging anyone, check the JAS-ANZ register and confirm the body is accredited for the scope you need, because unaccredited certificates are cheap, quick and routinely rejected by procurement teams.

Start With Your Data Map

Send us whatever data mapping exists, however rough. If none does, building it is the first thing we do together, and it remains valuable to the organisation regardless of whether certification follows.

Ready to start your ISO 27701 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

You can, following the 2025 revision. Anything telling you otherwise describes the previous version, which functioned only as an add-on. For Sydney organisations whose exposure is personal data rather than systems, going standalone is frequently the cheaper route.

Compliance is a legal state; certification is evidence of a managed approach to reaching it. We cross-reference the control set against each Australian Privacy Principle so you can point to where a given obligation is discharged when someone asks.

No deadline is specified here. What is required is a serious harm assessment and then notification of individuals and the regulator without undue delay once you are aware. Teams working to a 72-hour rule have imported a European obligation that does not apply.

It can. The Health Records and Information Privacy Act 2002 applies to health information held by private as well as public sector organisations in NSW, alongside Commonwealth obligations. Many private providers assume only the Privacy Act applies, which is incomplete.

Almost always both, and the answer changes by activity. Handling data on a client instruction puts you in one role; deciding how your own staff or prospect data is used puts you in the other. We record it activity by activity for that reason.

A cause of action in force since June 2025 allowing individuals to sue directly for intentional or reckless serious invasions of privacy. It shifts some exposure away from regulator action and toward direct claims, which changes the risk calculation.

Identify where automated systems make or substantially assist decisions significantly affecting people's rights, then update your privacy policy to disclose it. Most organisations we speak to have not yet built the inventory that disclosure depends on.

Meaningfully, since the standard borrows European concepts and the current edition tightened that alignment further. Sydney businesses serving European customers generally find it the most workable way to operate a single privacy system across both jurisdictions.

Your assessor sets the transition window. Substantive content largely survives. The work is structural: rebuilding the applicability statement to stand alone and unpicking the dependencies the earlier version assumed on the security standard.

Roughly three and a half to six months on its own, and materially quicker where a security certificate already exists. Building the data inventory sets the schedule, and it is the phase clients underestimate more than any other.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance