Recently, our Corporate Commercial lawyers, Elizabeth Tylich, Ariel Bastian and Anna Kosterich, wrote an article for the Law Society of Western Australia on the Privacy and Responsible Information Sharing Act 2024 (WA) (PRIS Act).
The article looks at how the PRIS Act moves beyond a simple compliance obligation, covering the 11 new Information Privacy Principles, the shift toward using privacy impact assessments as strategic risk tools rather than paperwork, and what organisations contracting with government need to know about managing privacy risk with service providers.
Read the full article below:
The commencement of the privacy provisions of the Privacy and Responsible Information Sharing Act 2024 (WA) (PRIS Act) marks a significant shift in the privacy landscape in Western Australia. For the first time, WA has a comprehensive statutory privacy regime governing the handling of personal information across the public sector and, in certain circumstances, contracted service providers.
But the PRIS Act is more than another piece of legislation to add to the compliance register. At its heart, it is a framework for better privacy governance, accountability and risk management.
The policy intent behind the legislation is particularly noteworthy. In the Second Reading Speech for the PRIS Act, the Attorney General observed that personal information is now collected, used and disclosed “at unprecedented rates” and that Western Australians should be able to say that government values and respects their privacy.
He also acknowledged that the existing patchwork of privacy protections had resulted in inconsistent practices across the public sector and that a contemporary legislative framework was required to respond to the realities of the digital age.
Importantly, the WA Government did not present the legislation merely as a privacy compliance regime. Rather, it was intended to deliver both strong privacy protections and a framework for responsible information sharing, recognising that effective public services increasingly rely upon the appropriate use and sharing of information.
That creates an opportunity for organisations to do more than simply comply. Properly implemented, the PRIS Act can strengthen information handling, improve decision-making, build community trust and support responsible innovation in public service delivery.
At the centre of the regime are the 11 Information Privacy Principles (IPPs). Together, they span the entire information lifecycle – from collection and use through to disclosure, security, access and correction, overseas disclosures, automated decision-making and de-identified information.
Importantly, the IPPs are intended to be technology-neutral, designed to remain relevant as technologies, business practices and service delivery models continue to evolve. They do not attempt to prescribe particular systems or technical controls. Instead, they establish enduring principles and outcomes that can be applied regardless of how information is collected, stored, analysed or shared.
Now more than ever we know that tech-neutrality matters. Technology changes quickly. Good governance should not have to be rewritten every time a new platform, tool or capability emerges. This is particularly relevant as government agencies increasingly explore artificial intelligence, advanced analytics, cloud-based platforms and digital service delivery. A highly prescriptive regime could quickly become outdated.
A principles-based framework instead requires organisations to keep asking the more important questions:

The inclusion of automated decision-making provisions demonstrates just how far privacy regulation has evolved. Privacy is no longer simply about who can access information. It is increasingly about transparency, fairness and accountability where personal information is used to influence decisions about individuals.
Parliament recognised this ambition during debate, describing the legislation as “the first of its kind in Australia” and highlighting WA’s opportunity to establish privacy protections and information-sharing practices that are “fit for the digital age”.
For this reason, the PRIS Act can fairly be regarded as one of the most modern privacy frameworks currently operating in Australia.
One of the most significant aspects of the PRIS Act is its emphasis on proactive privacy management. The legislation contains a dedicated framework for privacy impact assessments (PIAs), reflecting an expectation that privacy risks should be identified and managed before they materialise, rather than after harm has occurred.
There is a tendency for organisations to treat PIAs as a procedural requirement that must be completed before a project can proceed. When approached in this way, a PIA often becomes little more than a compliance checklist.
A well-executed PIA should instead operate as a strategic risk management tool. It should assist organisations to:

This is particularly important for projects involving artificial intelligence, automated decision-making, data matching, large-scale data integration, cloud migrations or new digital service delivery models.
Lawyers advising on PIAs should encourage clients to see them as governance tools rather than legal documents. When undertaken early and integrated into project design, PIAs can reduce implementation costs, improve operational outcomes and provide evidence that privacy risks were appropriately considered and managed.
Ultimately, the most valuable PIAs are not those that identify no risks. They are those that facilitate better decisions and outcomes.
The PRIS Act also recognises a reality that many organisations have already experienced the hard way: privacy risk rarely stays neatly within an organisation’s own four walls.
Government agencies routinely rely on technology providers, managed service providers, consultants and outsourced private service providers, many of which handle significant volumes of personal information.
The PRIS Act addresses this through its provisions dealing with contracted service providers (CSPs). Where a State services contract contains a PRIS compliance clause, a CSP may assume responsibility for complying with certain privacy obligations and may itself be subject to regulatory oversight under the PRIS Act.
But outsourcing the handling of information does not mean outsourcing accountability. The Office of the Information Commissioner has emphasised that entities remain responsible for managing privacy risks associated with their service providers, even where contractual privacy obligations are imposed on the CSP. Community expectations do not change simply because someone else is holding the information.
For lawyers involved in procurement and contracting, that means privacy risk needs to be considered well beyond the standard privacy clause. Agencies should be thinking about supplier due diligence, allocation of responsibilities, incident notification, audit rights, subcontracting, information security and ongoing monitoring.
Privacy complaints are another area where agencies can shift their thinking from compliance to governance.
The PRIS Act establishes mechanisms for individuals to raise concerns about interferences with privacy and seek redress.
In the past, agencies have fallen foul of proper complaint handling by simply treating each complaint as an isolated issue to investigate, resolve and close. But that misses an important opportunity. Complaints are a valuable source of organisational intelligence.
Complaints can provide an early warning system for broader organisational problems. They may reveal weaknesses in collection practices, gaps in staff training, ineffective privacy notices, poor information-sharing practices or deeper governance failures.
This concept has only just recently been foreshadowed at the Commonwealth level. The Office of the Australian Information Commissioner (OAIC) developed its entire “Privacy Awareness Week 2026” campaign on complaint handling. The OAIC has emphasised that effective complaint handling is a critical component of a mature privacy management framework.
An effective complaints framework can therefore help organisations identify systemic risks, detect recurring issues, improve community experience, demonstrate accountability and strengthen trust. The key is making sure that the information does not stop with the operational team. Trends and lessons from privacy complaints should feed into senior leadership discussions, organisational risk management and continuous improvement.
The broader policy objective of the PRIS Act is perhaps best understood through its attempt to balance two ideas: information is an asset that must be protected, but it is also a resource that can be used to improve public services when handled responsibly. That balance is at the heart of modern privacy governance.
The organisations that derive the greatest value from the new regime will be those that move beyond technical compliance and treat privacy as a governance discipline.
This article was written by Elizabeth Tylich, Partner, Ariel Bastian, Special Counsel and Anna Kosterich, Lawyer Corporate Commercial.