Something changed in October 2025 that most privacy content aimed at Sydney businesses has not caught up with. ISO/IEC 27701 stopped being an extension to ISO 27001 and became a standalone management system standard. An organisation can now be certified to it on its own.
The commercial consequence is direct. A Sydney organisation whose exposure sits in personal data rather than in systems and intellectual property can now certify against the thing that actually matters, without first funding a full security programme it did not need. Clinics, colleges, member associations, staffing platforms and customer data businesses all fall into that bracket.
Nathan ISO Consulting implements privacy information management systems for Sydney organisations, standalone or alongside an existing ISO 27001 certification.
Looking for an ISO 27701 Privacy Consultant in Sydney?
Why ISO 27701 Matters for Sydney Businesses
Sydney concentrates the sectors that hold the most sensitive personal information in the country: financial services, health, insurance, education and the technology businesses serving all of them. It also concentrates the regulatory attention that follows, because the OAIC’s largest matters tend to involve organisations headquartered here.
The obligations have been sharpening steadily rather than dramatically. Penalties increased at the end of 2024. A statutory tort for serious invasions of privacy came into force in June 2025, meaning individuals can now sue directly rather than relying on a regulator to act. And the automated decision-making transparency obligation comes out of its grace period on 10 December 2026, which will require many Sydney organisations to disclose something they have never mapped.
Against that, the practical problem in most organisations is not attitude but visibility. Very few Sydney businesses can say precisely what personal information they hold, where it came from, who processes it and how long it stays. Everything a privacy programme does depends on answering that, and it is where we start.
Legal and Regulatory Compliance in NSW
| Obligation | What It Involves |
|---|---|
| Privacy Act 1988 and the 13 Australian Privacy Principles | Collection, use, disclosure, quality, security, access and correction obligations for organisations above the turnover threshold and targeted small businesses |
| Notifiable Data Breaches scheme | Assessment and notification where a breach is likely to result in serious harm. Australian law imposes no 72-hour deadline, unlike the GDPR |
| Statutory tort for serious invasions of privacy | In force since June 2025, allowing individuals to bring direct claims for intentional or reckless serious invasions of privacy |
| Automated decision-making transparency | Privacy policies must disclose where automated systems make or substantially assist decisions significantly affecting rights, with the grace period ending 10 December 2026 |
| Privacy and Personal Information Protection Act 1998 (NSW) | Information protection principles applying to NSW public sector agencies and, through contract, to their service providers |
| Health Records and Information Privacy Act 2002 (NSW) | Health privacy principles applying to health information held by NSW public and private sector organisations |
| Cross-border disclosure under APP 8 | Accountability for personal information disclosed to overseas recipients, including offshore processing and cloud arrangements |
| Privacy Amendment (Personal Data Protection) Bill 2026 | An exposure draft proposing changes to the definition of personal information, a fair and reasonable test and tightened breach obligations. Not law |
The Health Records and Information Privacy Act catches many private Sydney health providers who assume only the Commonwealth Privacy Act applies to them. We check this during scoping.
Sydney Industries and Economic Zones We Work Across
| Precinct or Zone | Who Operates There | Privacy Exposure |
|---|---|---|
| Sydney CBD and Barangaroo | Banks, insurers, wealth managers, advisory firms | Customer financial data, credit information, automated decisioning |
| North Sydney and Chatswood | Insurance, corporate shared services, health insurers | Claims data, health information held by insurers, offshore processing |
| Westmead and Randwick | Hospitals, medical research, pathology, health technology | Health information under both Commonwealth and NSW health privacy law |
| Surry Hills, Pyrmont and Alexandria | SaaS platforms, martech, adtech, digital agencies | Processor obligations, tracking data, cross-border transfers |
| Parramatta and Western Sydney | NSW agency offices, health administration, community services | PPIP Act obligations reaching contracted service providers |
| Macquarie Park | Pharmaceuticals, medical devices, technology | Clinical trial data, research participants, employee information |
| Education precincts | Universities, colleges, training providers, edtech | Student records, international student data, research data |
| Recruitment and workforce services | Staffing platforms, assessment providers, payroll bureaus | Candidate data, background checking, automated screening |
Which Route Suits a Sydney Business?
The standalone option is new, which does not automatically make it right. The decision usually resolves within one conversation once two things are established: what your customers are actually naming in their contracts, and whether you carry information security exposure that exists independently of personal data.
Fits where personal information is the exposure and nobody has asked for security certification. Sydney clinics and allied health groups, independent schools and colleges, membership and professional bodies, recruitment and workforce platforms, and customer data businesses commonly sit here. The scope is narrower and the ongoing maintenance lighter.
Fits where you hold ISO 27001 already or a buyer has named it. Governance, risk methodology, audit and review are built once and serve both, so the incremental effort is modest compared with either project standing alone. Most Sydney financial services and SaaS clients end up here.
A quick diagnostic if you are undecided: pull the last three supplier questionnaires you completed and see which standard the buyer named. That answers it more reliably than an internal debate.
Not sure whether standalone or combined suits your organisation?
How Nathan ISO Consulting Helps
Everything begins with mapping the data itself: what arrives, from where, on what basis, who handles it downstream and when it is supposed to disappear. Role determination follows, taken activity by activity rather than declared once for the whole business, since a platform company handling client records under instruction stands in a different position from the same company deciding how to use its own candidate database. The build then covers external notices, the applicability statement, access and correction handling, an incident runbook calibrated to the serious harm threshold, assessment methodology, retention scheduling and controls over offshore disclosure.
Assessor coverage for the standalone route is still catching up with the revision, so not every accredited body can currently take it on. We verify who genuinely holds scope before making a recommendation, run the commercial process, and prepare you through an audit tested against the standard and your principle-level obligations together, with a documented review. Both assessment stages are attended.
Australian privacy law is in active reform, and a system built to today’s obligations will need adjusting. We run annual internal audits, prepare you for surveillance, monitor reform developments that affect your scope, and update the inventory as products, suppliers and data flows change.
What You Receive
Where Sydney ISO 27701 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
We shortlist JAS-ANZ accredited certification bodies against your scope, sector and preferred audit approach, manage the quote process on your behalf, and attend Stage 1 and Stage 2 with you. Findings raised at either stage are ours to close out, not yours to inherit. Before engaging anyone, check the JAS-ANZ register and confirm the body is accredited for the scope you need, because unaccredited certificates are cheap, quick and routinely rejected by procurement teams.
Start With Your Data Map
Send us whatever data mapping exists, however rough. If none does, building it is the first thing we do together, and it remains valuable to the organisation regardless of whether certification follows.
Ready to start your ISO 27701 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
You can, following the 2025 revision. Anything telling you otherwise describes the previous version, which functioned only as an add-on. For Sydney organisations whose exposure is personal data rather than systems, going standalone is frequently the cheaper route.
Compliance is a legal state; certification is evidence of a managed approach to reaching it. We cross-reference the control set against each Australian Privacy Principle so you can point to where a given obligation is discharged when someone asks.
No deadline is specified here. What is required is a serious harm assessment and then notification of individuals and the regulator without undue delay once you are aware. Teams working to a 72-hour rule have imported a European obligation that does not apply.
It can. The Health Records and Information Privacy Act 2002 applies to health information held by private as well as public sector organisations in NSW, alongside Commonwealth obligations. Many private providers assume only the Privacy Act applies, which is incomplete.
Almost always both, and the answer changes by activity. Handling data on a client instruction puts you in one role; deciding how your own staff or prospect data is used puts you in the other. We record it activity by activity for that reason.
A cause of action in force since June 2025 allowing individuals to sue directly for intentional or reckless serious invasions of privacy. It shifts some exposure away from regulator action and toward direct claims, which changes the risk calculation.
Identify where automated systems make or substantially assist decisions significantly affecting people's rights, then update your privacy policy to disclose it. Most organisations we speak to have not yet built the inventory that disclosure depends on.
Meaningfully, since the standard borrows European concepts and the current edition tightened that alignment further. Sydney businesses serving European customers generally find it the most workable way to operate a single privacy system across both jurisdictions.
Your assessor sets the transition window. Substantive content largely survives. The work is structural: rebuilding the applicability statement to stand alone and unpicking the dependencies the earlier version assumed on the security standard.
Roughly three and a half to six months on its own, and materially quicker where a security certificate already exists. Building the data inventory sets the schedule, and it is the phase clients underestimate more than any other.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving