Data Quality Advisory

← Back to home

PRIS Readiness Assessment

The PRIS Act is now in force. Know where your organisation stands.

Since 1 July 2026, Western Australia’s Privacy and Responsible Information Sharing Act 2024 has applied to WA public sector organisations, including local governments. Your community can already exercise their new rights: to receive collection notices, to access and correct their personal information, and to lodge privacy complaints. We assess whether you are ready to respond, and give you a clear, prioritised plan for what to fix next.

Book a PRIS Scoping Discussion Request a sample assessment scope
What changed on 1 July 2026

Privacy in WA is now law, with rights attached.

Western Australia was the last state without privacy legislation. That ended on 1 July 2026.

Any resident, ratepayer or community member can now start a legal clock with your organisation: an access request, a correction request or a privacy complaint. Most WA entities, and most local governments in particular, have never had to run these processes before. Here is what is now in force.

The IPPs are binding law

Eleven Information Privacy Principles now govern how personal information is collected, used, disclosed, secured, retained and disposed of. Practices that were merely untidy in June became non-compliant in July.

Residents can access and correct their information

Any individual can request access to the personal information you hold about them and ask for corrections. Your organisation has 45 days to decide, and refusals require reasons.

Privacy complaints have a legal pathway

Complaints go first to your organisation, and then to the Information Commissioner if the person is not satisfied. Every entity now needs a complaints process that works in practice.

Collection notices and privacy policies are required

People must receive a collection notice when their personal information is collected, and your privacy policy must be published in clear, plain language.

A privacy officer and PIAs are mandatory

Every IPP entity must designate a privacy officer, and a privacy impact assessment must be completed before any high privacy impact function or activity begins.

Breach notification arrives 1 January 2027

Serious information breaches must then be reported to the Information Commissioner and affected individuals. Registers, response plans and escalation paths need to be built now, in this window.

What we assess

A structured review across six areas.

We assess whether your governance, privacy practices, information-sharing arrangements and supporting documents are ready to operate in practice, not simply whether policies exist.

Governance and accountability

Whether PRIS responsibilities are clearly assigned, accountable executives and operational owners are identified, privacy risks are escalated appropriately, decisions can be evidenced and staff understand their responsibilities.

Information Privacy Principles

How personal information is collected, used and disclosed, stored and protected, accessed and corrected, retained and disposed of. We test whether documented requirements are reflected in day-to-day processes.

Privacy impact assessments

Whether your organisation can identify high privacy impact functions and activities and conduct appropriate assessments before new activities begin. Existing or draft PIAs can be reviewed for evidence, reasoning, controls, ownership and approval.

Responsible information sharing

Your readiness to receive and evaluate sharing requests, apply the responsible sharing principles, establish safeguards, define responsibilities between participating organisations, and document and approve sharing arrangements.

Information breach readiness

Preparation for the notifiable information breach requirements commencing 1 January 2027, including identification and triage, escalation, assessment and notification processes, registers, response plans, communication and staff awareness.

Contractors, AI and automated decisions

Privacy responsibilities in service contracts, oversight of contracted service providers, the use of AI in privacy and governance work, and automated decision processes, including whether a named person can explain and stand behind the result.

How it works

Our assessment approach.

01

Define the scope

We agree on the organisations, business areas, activities and documents to be assessed.

02

Review the evidence

We examine policies, assessments, agreements, procedures, registers, templates, governance records and other relevant material.

03

Speak with the people doing the work

Short interviews and process walkthroughs help establish whether documented arrangements operate in practice.

04

Test accountability

Our Human Accountability Framework tests whether important documents and decisions have genuine ownership, traceable evidence, explainable judgments and meaningful approval. If AI assisted, the question is not whether AI was used. It is whether the organisation can account for the result.

05

Validate the findings

Relevant staff have an opportunity to provide context and additional evidence before findings are finalised.

06

Provide a practical roadmap

The final report identifies what is working, what requires attention and what should happen next.

What you receive

Practical outputs your organisation can act on.

Executive Readiness Report

A concise account of your current position, key risks and the priority decisions in front of your organisation.

Readiness Scorecard

A visual assessment across the review domains, using graduated findings rather than a simplistic pass-or-fail rating.

Evidence and Findings Register

Every finding records the expected practice, the evidence reviewed, what is working, the gap, the risk, the recommended action and a proposed accountable owner.

Prioritised Implementation Roadmap

Actions organised into immediate, near-term and longer-term priorities, so your organisation knows exactly what to address first.

Executive Briefing

A facilitated briefing for senior leaders covering the findings, material risks and the decisions required.

Validated with your team

Before the report is finalised, relevant staff can confirm evidence, correct factual inaccuracies and provide additional context.

Focused PRIS reviews

Targeted reviews, without the full assessment.

PIA Quality Review

An independent review of a draft or completed privacy impact assessment, covering the activity description, information involved, necessity and purpose, risks, controls, responsibility and a defensible basis for approval.

Privacy Policy and Notice Review

A practical review of privacy policies, collection notices and related procedures for clarity, consistency, ownership and operational usability.

Information Sharing Readiness Review

A focused review of a proposed information-sharing initiative, including governance, assessments, safeguards, decision records and agreement readiness.

Information Breach Readiness Review

A review of breach policies, escalation pathways, registers, notification processes and operational preparedness. A facilitated breach scenario or tabletop exercise can be included.

AI and Automated Decision Accountability Review

A review of an AI-assisted or automated process to determine whether its purpose, information use, controls, human oversight, review rights and accountability arrangements can be clearly explained and evidenced.

Implementation support

Governance roles, action-plan delivery, policy improvement, PIA processes, information-sharing workflows, breach response preparation and workshops. Engage us for the assessment alone or retain support through implementation.

Why Data Quality Advisory

PRIS implementation is not only a legal exercise.

It requires governance, information management, data quality, risk management and operational accountability to work together.

Data Quality Advisory brings more than 20 years of experience translating public sector requirements into practical governance, processes and evidence. Our focus is straightforward: clear accountability, defensible decisions, reliable evidence, practical implementation, and documents that people can explain and use.

Get started

Start with a 20-minute scoping discussion.

If you are unsure whether you need a full readiness assessment or a focused review, we can begin with a short discussion about your organisation, current work and immediate priorities.

Book a PRIS Scoping Discussion Enquire by email

Data Quality Advisory provides governance, readiness and document-assurance services. These services do not constitute legal advice or certification of legal compliance. Legal interpretations should be confirmed with appropriately qualified legal advisers.