Beyond the Federal Privacy Act: State-Level Obligations

Most discussions about data destruction compliance in Australia focus on the federal Privacy Act 1988. But several states and territories have their own privacy and data protection legislation that creates additional obligations, particularly for health service providers, state government agencies, and organisations contracted to deliver state government services.

For organisations operating across multiple states, these varying requirements add complexity to IT disposal processes. The safest approach is to understand the most stringent requirements across all jurisdictions where you operate and build your disposal process to meet that highest standard.

Victoria

Victoria has some of the most comprehensive state-level privacy legislation in Australia.

The Health Records Act 2001 (Vic) establishes Health Privacy Principles (HPPs) that apply to all health service providers in Victoria regardless of size. This is broader than the federal Privacy Act, which generally only applies to organisations with turnover exceeding $3 million. HPP 4 requires security of health information, and HPP 2 governs use and disclosure. Both are directly relevant to disposal of equipment containing patient data.

The Privacy and Data Protection Act 2014 (Vic) applies to Victorian public sector organisations and establishes Information Privacy Principles (IPPs). IPP 4 requires data security measures, and the Act’s protective data security regime covers information classified under the Victorian Protective Data Security Framework. State government agencies and their contractors must comply with these requirements when disposing of IT equipment.

Victoria’s e-waste landfill ban (effective 1 July 2019) adds an environmental compliance dimension. All e-waste, regardless of whether it contains personal data, must be recycled rather than sent to landfill. This intersects with data destruction obligations: you can’t just throw equipment in a skip, and the recycling process must include proper data handling.

Key state privacy legislation affecting disposal:

  • Victoria: Health Records Act 2001, Privacy and Data Protection Act 2014
  • NSW: Health Records and Information Privacy Act 2002, Privacy and Personal Information Protection Act 1998
  • Queensland: Information Privacy Act 2009
  • ACT: Health Records (Privacy and Access) Act 1997, Information Privacy Act 2014
  • Tasmania: Personal Information Protection Act 2004
  • NT: Information Act 2002

New South Wales

NSW has dedicated legislation for both health information and public sector personal information.

The Health Records and Information Privacy Act 2002 (NSW) creates Health Privacy Principles that apply to health service providers in NSW. These principles cover the full lifecycle of health information, including its destruction. Health service providers must take reasonable steps to ensure health information is destroyed or de-identified when no longer needed.

The Privacy and Personal Information Protection Act 1998 (NSW) applies to NSW public sector agencies and establishes Information Protection Principles. These principles require agencies to ensure personal information is disposed of securely when no longer required. NSW government agencies and their contractors must comply when disposing of IT equipment used in the delivery of government services.

The NSW Cyber Security Policy also creates expectations for state government agencies regarding the secure disposal of IT assets, including requirements for data sanitisation aligned with the ASD Information Security Manual.

Queensland

Queensland’s Information Privacy Act 2009 applies to Queensland government agencies and bound contracted service providers. The Act contains Information Privacy Principles that mirror many of the federal APPs but apply specifically to the state government sector.

IPP 4 under the Queensland Act requires agencies to take reasonable steps to protect personal information, including during disposal. Queensland agencies disposing of IT equipment must ensure that data destruction methods are adequate for the sensitivity of the information held.

Queensland’s Information Security Policy (IS18:2018) provides specific guidance for government agencies on information security, including disposal requirements. Agencies are expected to align their disposal practices with the ASD ISM’s media sanitisation controls.

ACT, Tasmania, and Northern Territory

The ACT’s Health Records (Privacy and Access) Act 1997 was one of the earliest state-level health privacy laws in Australia. It governs health records in the ACT and includes requirements for secure handling throughout the information lifecycle.

The ACT’s Information Privacy Act 2014 applies to ACT public sector agencies and establishes Territory Privacy Principles. These principles include security obligations that extend to disposal.

Tasmania’s Personal Information Protection Act 2004 applies to Tasmanian government agencies and creates Personal Information Protection Principles that include data security requirements applicable to disposal.

The Northern Territory’s Information Act 2002 covers both freedom of information and privacy for NT government agencies. It includes Information Privacy Principles with security requirements that extend to the disposal phase.

South Australia and Western Australia

South Australia and Western Australia do not have comprehensive state privacy legislation, though both have administrative policies and frameworks that apply to state government agencies.

South Australia’s Information Privacy Principles Instruction (known as PC012) applies to SA government agencies on an administrative rather than legislative basis. It includes security principles that cover disposal of IT equipment containing personal information.

Western Australia relies on administrative policy rather than legislation for public sector privacy. The WA Information Classification Policy and associated guidelines include requirements for secure disposal of classified and personal information.

The absence of legislative privacy requirements in these states doesn’t eliminate disposal obligations. The federal Privacy Act still applies to private sector organisations meeting its coverage thresholds, and contractual requirements from government clients often impose disposal standards regardless of state legislation.

Implications for Multi-State Organisations

Organisations operating across multiple states face a patchwork of requirements that can complicate IT disposal. A healthcare provider operating in Victoria and NSW, for example, must comply with both the Victorian Health Records Act and the NSW Health Records and Information Privacy Act, in addition to the federal Privacy Act.

The practical approach for multi-state organisations is to identify the most stringent requirements across all jurisdictions where you operate. Build your disposal process to meet the highest standard. This avoids the complexity and risk of maintaining state-specific processes and ensures compliance everywhere.

For most organisations, this means applying the same disposal process nationally: certified data destruction to recognised standards, comprehensive documentation, chain of custody records, and certificates of destruction for every batch. This level of practice satisfies all current state requirements.

Government Contractors

Organisations contracted to deliver services on behalf of state governments are typically bound by the relevant state’s privacy legislation through their contract. This extends the reach of state privacy laws well beyond the public sector itself.

IT companies providing managed services to a Victorian government department, for example, must comply with the Victorian Privacy and Data Protection Act for any personal information they handle as part of that contract. When equipment used in delivering those services is disposed of, the state Act’s requirements apply.

Contract terms may go further than the legislation itself. Many government contracts include specific data destruction requirements, such as mandating NIST 800-88 compliance, requiring physical destruction for classified data, or specifying that disposal must occur within Australia. Review your government contracts carefully for disposal-specific clauses.

Multi-state disposal compliance strategy:

  • Map all jurisdictions where you collect or process personal information
  • Identify the state-level legislation that applies in each jurisdiction
  • Determine the most stringent requirement across all applicable frameworks
  • Build a single disposal process that meets the highest standard
  • Apply that process consistently across all locations
  • Review government contracts for additional disposal-specific requirements
  • Document your compliance approach for audit purposes

State privacy legislation adds layers to the disposal compliance picture, but the fundamental principle remains consistent: personal information must be securely destroyed when no longer needed, and the destruction must be verifiable. An organisation that meets this standard across the board will satisfy both federal and state requirements.

For more on building a nationally compliant disposal process, see our complete guide to data destruction and our guide to building an IT asset disposal policy.

EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.