By Sam Fiddian and Christa Queern; members of the Technology and Law Committee of the Law Society
Western Australia’s Privacy and Responsible Information Sharing Act 2024 (WA) (PRIS Act) commenced on 1 July 2026. This marks a pivotal milestone in establishing a comprehensive legal framework for privacy and responsible information sharing in the Western Australian public sector.
The PRIS Act addresses a long-standing legislative gap in the State’s privacy landscape and introduces an innovative responsible information sharing framework, described by the Western Australian Government as an “Australian-first” initiative.
With the potential for the PRIS Act to impact both a practitioner’s clients and their own practice, we discuss below who must comply with the PRIS Act before introducing its two key components: the privacy component and the responsible information sharing framework.
Who must comply with the PRIS Act?
The PRIS Act imposes obligations on an “IPP entity”, which includes both Western Australian public entities and contracted service providers.
Western Australian public entities are defined broadly and include government trading enterprises, government departments, and local and regional governments.
Contracted service providers are organisations that deliver services to, or on behalf of, public entities under State services contracts that include a clause requiring compliance with the privacy provisions of the PRIS Act. Not only are the primary contractors caught, but any subcontractors engaged under such arrangements are also classified as contracted service providers.
Notably, there is no exemption for small businesses, meaning individuals, sole traders and small enterprises entering into State services contracts containing PRIS compliance clauses need to be conscious of their status as contracted service providers.
If a State services contract does not include a compliance clause, the relevant public entity will be responsible for any acts or practices of the service provider that breach the PRIS Act as though they were its own. As a result, PRIS compliance clauses are expected to become standard inclusions in State services contracts.
Privacy under the PRIS Act
Many readers will be familiar with the operation of the Privacy Act 1988 (Cth) (Commonwealth Privacy Act), with its associated Australian Privacy Principles (APPs) having guided Commonwealth and private sector privacy compliance for over a decade. The PRIS Act and in particular its 11 Information Privacy Principles (IPPs) continue the theme of Australian privacy based legislation of adopting a principle-based structure, although the IPPs more closely resemble the information privacy principles in Victoria’s privacy legislation than the APPs.
The 11 IPPs govern each step of the personal information lifecycle, from collection through to destruction:
- IPP 1: governs the collection of personal information, requiring it to be necessary for the IPP entity’s functions or activities, conducted fairly and reasonably, without unreasonably intrusive methods, and with individuals informed of the purpose and intended use or disclosure at or before the time of its collection;
- IPP 2: governs the use and disclosure of personal information, including the circumstances in which personal information may be used or disclosed for a secondary purpose;
- IPP 3: governs the obligation to take reasonable steps to ensure personal information that is collected, used or disclosed is correct, complete and up to date;
- IPP 4: governs the obligation to take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification or disclosure, and the requirement to destroy or permanently de-identify personal information when it is no longer needed;
- IPP 5: governs the requirement to maintain a publicly available privacy policy that sets out what personal information is collected and held, how and why it is handled, and whether any personal information is used in automated decision making;
- IPP 6: governs the right of individuals to request access to, and correction of, personal information held about them, and the obligation on public entities to respond to such requests within 45 days;
- IPP 7: governs the assignment, adoption, use, and disclosure of unique identifiers, including requiring that they not be assigned to an individual unless necessary for the efficient performance of the IPP entity’s functions or activities;
- IPP 8: requires that IPP entities give individuals the opportunity to interact with them without identifying themselves save where doing so is impracticable;
- IPP 9: prohibits the disclosure of personal information outside Australia unless one or more exceptions applies;
- IPP 10: governs the use of automated decision-making processes, requiring IPP entities to assess the risks of such processes to minimise harm, bias, and discrimination, to inform individuals when automated decision-making is being used, and to provide a mechanism for individuals to request human involvement in the decision; and
- IPP 11: governs the handling and security of de-identified information, including the obligation to protect such information from misuse, loss, unauthorised re-identification, access, modification or disclosure.
Some of the other primary features of the privacy component of the PRIS Act include:
- Broadly defining personal information:the definition of “personal information” under the PRIS Act includes a non-exhaustive list of contemporary types of information, such as technical or behavioural data. The definition of “sensitive information” explicitly includes biometric information.
- Personal information collected before 1 July 2026: several of the IPPs apply to personal information collected before 1 July 2026, including in particular IPP 4, IPP 5, IPP 9 and IPP 11.
- Mandatory Privacy Impact Assessments: IPP entities are required to undertake a Privacy Impact Assessment when performing a function or activity that involves the handling of personal information and is likely to have a significant impact on the privacy of individuals.
- Automated decision-making requirements: as noted briefly above, IPP 10 introduces the requirement for IPP entities to ensure due process, transparency, and procedural fairness in the use of personal information for automated decision-making, which is the first obligation of its kind to be codified in Australia.
Further, while there are broad conceptual similarities between the PRIS Act and the Privacy Act, the two frameworks differ in several key respects:
- Necessary collection: under the PRIS Act, personal information must not be collected unless it is “necessary” and “fair and reasonable”, taking into account prescribed factors. This is a stricter standard than the “reasonably necessary” threshold under the APPs.
- De-identified information: under the Commonwealth Privacy Act, information that has been permanently de-identified no longer meets the definition of “personal information”, meaning its handling falls outside the scope of the Commonwealth Privacy Act. In contrast, the PRIS Act introduces IPP 11, which extends certain privacy protections to de-identified information. This marks a significant departure from the Commonwealth Privacy Act, under which privacy obligations cease once information is de-identified.
- Limited exceptions:unlike those that exist under the Commonwealth Privacy Act, the PRIS Act does not provide an exemption for employee data or, as noted above, for small businesses.
Responsible information sharing framework
The PRIS Act also establishes a responsible information sharing framework that enables Western Australian public entities to share “government information” under prescribed circumstances with specified entities. These entities can include other Western Australian public entities, Commonwealth and State agencies, higher education providers, health-related research organisations, and contracted service providers.
The framework is designed to unlock public benefit from information that has historically been siloed within individual collecting entities and has often been of limited utility, despite its potential to be better leveraged to inform government policy and improve government services. Information may be shared for “permitted purposes”, including informing government policy, government programs and services, research and development with clear public benefits, or emergency management. It may not be shared under the framework for law enforcement purposes, national security purposes, or for the primary purpose of obtaining commercial gain.
At its heart, the framework requires information sharing to be consistent with five responsible sharing principles (RSPs), which assess the:
- appropriateness of the proposed activities;
- suitability of the recipient;
- nature of the information to be shared;
- adequacy of the security and handling settings; and
- appropriateness of any outputs derived from the shared information.
The framework established by the PRIS Act demands that those sharing and seeking government information follow a detailed and structured process. This includes the submission of a formal written request, the preparation of an information sharing agreement and one or more assessments (depending on the context) that may include an RSP assessment, a privacy impact assessment, and an Aboriginal information assessment.
Executed information sharing agreements must be provided to the Chief Data Officer (CDO) within 30 days, with the agreement then recorded on a publicly accessible register.
Regulatory architecture
The PRIS Act will be overseen by two public bodies. The Office of the Information Commissioner (OIC) was established under the Information Commissioner Act 2024 and is led by Information Commissioner Annelies Moens, supported by Privacy Deputy Commissioner Nina Skewes and Information Access Deputy Commissioner Patrick Ky.
The OIC oversees those parts of the PRIS Act which concern privacy (as well as assuming responsibility for the Freedom of Information Act 1992 (WA)). The Chief Data Officer, Natalia Kacperek, is responsible for overseeing the responsible information sharing aspects of the PRIS Act.
The Information Commissioner has an expansive tool-kit enabling the Commissioner to investigate and resolve privacy complaints or instances of non-compliance, including the ability to award compensation of up to $75,000 to individual complainants or the issuance of compliance notices to IPP entities. These powers underscore the significant risks associated with non-compliance, particularly in cases where the acts or practices in question affect multiple individuals.
Practical significance for legal practitioners
The introduction of the PRIS Act marks a fundamental shift in the WA public sector. Whether practitioners have spent many years advising clients on the Commonwealth Privacy Act or are stepping into the world of privacy law for the first time, they will need to carefully examine the PRIS Act in order to understand the demands placed on their clients.
Practitioners advising public entities will need to guide their clients through the considerable task of achieving and maintaining PRIS compliance, including dealing with the retrospective application of certain IPPs to considerable personal information already held.
For lawyers advising private sector clients that engage with the WA public sector, a key question is whether those clients are or may become contracted service providers, and if so, ensuring their privacy policies and practices are aligned with the new requirements.
Careful attention should also be paid to guidance released by the OIC in the coming months, which should shed further light on how the Information Commissioner intends to approach her role and make use of her regulatory tool-kit.