Fact Sheet - The PPIP Act: Agency systems, policies and practices
Read the document below or download it here Fact Sheet - The PPIP Act: Agency systems, policies and practices, updated August 2026
|
Who is this information for? NSW public sector agencies Why is this information important? This guidance is provided to assist agencies in the performance of their responsibilities under the Privacy and Personal Information Protection Act 1998 (PPIP Act) and Health Records and Information Privacy Act 2002 (HRIP Act). It provides suggested actions and guidance to support an effective privacy governance framework. |
Strong privacy governance helps agencies build public trust and confidence, manage risk and comply with their responsibilities under the PPIP Act and HRIP Act.
The protection of privacy requires more than just complying with the legislation. It requires effective leadership, clear governance, well designed systems, staff capability and continuous oversight.
Agencies should establish and maintain policies, systems and practices that support an effective privacy framework. Those arrangements should also be responsive to emerging technologies, like artificial intelligence, automated decision making and evolving cyber security risks.
Operating environment in the public sector
The PPIP and HRIP Acts outline the obligations to protect the personal and health information agencies collect about individuals and creates responsibilities for the management and handling of personal information. The Information Protection Principles (IPPs) together with the Health Privacy Principles (HPPs) are legal obligations which NSW government agencies must abide by when they collect, store, use or disclose personal and /or health information. These obligations and responsibilities apply to all NSW government agencies, whether they are a state government agency, local council, university, state owned corporation or Staff of a Minister’s Office.
To ensure agencies can confidently uphold their responsibilities under the PPIP and HRIP Acts, the statutory requirements must be well supported by leadership, investment in training, systems and processes, including assurances, certifications and a privacy respectful culture.
Managing privacy
The suggested actions set out below aim to assist and guide agencies in the exercise of privacy functions and respond to risks that may arise in the performance of those functions and decision-making arrangements:
- Leadership and stewardship: senior leaders must drive privacy strategies, set the culture, assign roles and responsibilities and establish and ensure clear lines of authority are in place.
- Delegations: Agencies should regularly review their delegations to ensure that they reflect the requirements of the PPIP and HRIP Acts. Agencies are not permitted to delegate their obligations under the PPIP or HRIP Act to other agencies, even if the other agency is within the same principal department. Where a person seeks internal review of an agency’s conduct under Part 5 of the PPIP Act, the review is to be undertaken by that agency.
- Websites: Agencies should regularly review their website content to update forms and information relevant to the operation of the PPIP Act and HRIP Act, including where agencies have been impacted by machinery of government changes.
- Policies and procedures: Agencies should regularly review all their policies relevant to privacy responsibilities to ensure that they accurately reflect any changes because of principal department arrangements. Following review of these policies, agencies should circulate and actively promote the location of updated policies to all staff.
Agencies should ensure that privacy policies are clear, and transparent. - Systems and Controls: Agencies should implement both technical and administrative safeguards that includes role-based access rights, audit controls, regular review and updating of access rights and login protocols.
Privacy Management Plans
The PPIP Act requires agencies to prepare and implement a Privacy Management Plan (PMP).
A PMP should comply with section 33 of the PPIP Act and contain provisions relating to:
-
the agency’s policies and practices for complying with the PPIP Act and the HRIP Act
-
how the agency will make its staff aware of these policies and practices
-
the agency’s procedures and practices for dealing with privacy internal reviews under Part 5 of the PPIP Act and section 21 of the HRIP Act respectively
-
other relevant matters relating to the protection of the personal and health information that the agency holds.
-
the procedures and practices used by the agency for complying with its obligations and responsibilities under Part 6A Mandatory Notification of Data Breaches.
Agencies should ensure that their PMP is current, regularly reviewed and up to date.
The PMP should provide a clear policy statement that describes the types of personal and health information that the agency collects, the purposes of the use of that personal information and where that information is stored and how it can be accessed, particular to the agency’s operating context.
Automated Decision Making (ADM) and Artificial Intelligence (AI)
Where agencies are using AI or ADM as part of their functions which involves the use of personal and/ or health information, agencies should include information about its use and the policies and practices used to comply with the IPP/HPPs in their PMP.
A PMP should include clear information about how personal and/or health information is used, how decisions are made, and the safeguards to protect individual rights.
Training and systems
Agencies should implement a program of regular training to support the performance of functions under the PPIP and HRIP Acts, which may also include information management more broadly, including:
-
the agency Code of Conduct and Public Service Commission’s Ethical Framework as they relate to the PPIP and HRIP Act
-
Privacy Management and Governance
-
the offence provisions under the PPIP Act.
-
the offence provisions under the HRIP Act
Training should be tailored appropriately for specific roles and responsibilities, particularly those charged with responsibility for collecting, using and disclosing personal information. That training should extend to all employees, including contractors and temporary employees, senior managers and executives. For all staff, training should be contextualised and specific to the functions of staff in their particular roles.
Agencies should develop a mechanism to ensure that their training content and policies are regularly reviewed to ensure currency, and that there is a process in place for staff to undertake refresher training at regular intervals and at least on an annual basis.
Agencies should review and consider application of targeted and specific training that is contextualised to the functional policies in place, with focus on the privacy aspects of those roles and responsibilities. Agencies should implement a mechanism to ensure privacy training is available to new staff as part of the induction process.
PPIP Act - Governance for authorised disclosure of personal information
Agencies should develop processes to inform the management of the authorised disclosure of personal information. Processes should include when, how and in what circumstances an authorised disclosure may be permissible and any authorisation approvals that must be in place to permit such disclosures.
PPIP Act - Data Breach Policy (DBP) and Response
Agencies should have a comprehensive data breach management process and procedure in place that includes a risk assessment for any unauthorised disclosures, unauthorised access or loss of personal information should they occur. The plan and DBP should align with the Mandatory Notification of Data Breaches Scheme under Part 6A of the PPIP Act.
That process and procedure should:
-
be a single and comprehensive policy for management of data breaches
-
address the particularity of roles and responsibilities as appropriate to principal department (where applicable), agency and functional areas
-
provide for an escalation model
-
include reporting obligations to the Privacy Commissioner
-
address management of cyber security breaches which involve personal information
-
clearly define what is personal information and what is a data breach
-
specify the process in which persons affected by a privacy breach will be notified
-
include a mechanism of assurance for ensuring that the remedial actions have been implemented.
Agency DBP’s are required to be publicly available.
Risk management and Privacy Reporting
Agencies should establish internal reporting requirements for data breaches to be reported to Senior Officers on at least a quarterly basis, including the number of breach notifications notified to the Privacy Commissioner. The report should include actions taken in response to advice suggested by the Privacy Commissioner, including where a decision is made to not adopt such advice, the reasons for not doing so, and the number of internal reviews/complaints received as a direct response to the data breach. More information on data breaches can be found on the IPC website.
For more information
Contact the Information and Privacy Commission NSW (IPC):
Free call: 1800 472 679
Email: ipcinfo@ipc.nsw.gov.au
Website: www.ipc.nsw.gov.au
NOTE: The information in this fact sheet is to be used as a guide only. Legal advice should be sought in relation to individual circumstances.
- Sections 8-19 PPIP Act
- Schedule 1 HRIP Act
- Section 33 PPIP Act
- Section 4 PPIP Act
- Sections 62-63 PPIP Act
- Sections 68-70 HRIP Act
