August 2026 General Legal Update: A Practical Privacy Health Check

August 4, 2026
A Practical Privacy Health Check

A Practical Privacy Health Check for Organisations

Privacy compliance is often viewed as a legal or administrative requirement. Increasingly, however, it is becoming a matter of organisational trust, reputation and risk management.

One of the more significant developments this year was the introduction of Information Privacy Principle 3A (IPP 3A), which came into force on 1 May 2026. In broad terms, organisations that collect personal information indirectly, meaning from someone other than the individual concerned, may now have additional obligations to notify that individual.

For many organisations, that makes now a good time to review how personal information enters the organisation and whether existing privacy practices remain fit for purpose.

Why does this matter?

Many organisations regularly receive personal information from third parties. This might include:

  • customer or client information;
  • employee or recruitment information;
  • supplier and contractor details;
  • referral information;
  • information shared as part of a wider service delivery arrangement.

Historically, organisations have often focused on what information they collect directly. The newer requirements are a reminder that privacy obligations can also arise when information is obtained from another organisation, provider or individual. 

Privacy issues rarely arise because an organisation intentionally mishandles information. More commonly, they occur because:

  • information is shared across multiple organisations;
  • responsibility for privacy is unclear;
  • information is used for purposes beyond those originally contemplated;
  • privacy notices have not kept pace with operational practices; or
  • processes and contracts have not been reviewed for some time.

Accountability doesn’t stop with outsourcing

A common misconception is that privacy responsibility transfers to a service provider once information is outsourced. In practice, privacy accountability often extends much further. Whether information is stored by a cloud provider, managed by a contractor, administered by a third-party platform, or shared across a service delivery network, organisations should understand their privacy obligations and ensure they are properly addressed in contracts and operational processes.

Privacy should be considered whenever organisations are:

  • engaging service providers;
  • implementing new technology platforms;
  • entering information-sharing arrangements;
  • outsourcing functions; or
  • reviewing governance and risk management frameworks.

A practical privacy health check

A useful starting point is to ask:

  • Where does personal information enter our organisation?
  • Do we receive information from third parties?
  • Would affected individuals know we hold their information?
  • Are our privacy notices and collection statements up to date?
  • Do our supplier and service provider contracts adequately address privacy obligations?
  • Who is responsible for managing privacy requests and privacy breaches?
  • Would staff know how to identify and escalate a privacy issue?

For many organisations, a simple review of privacy notices, collection processes, contracts and staff awareness is enough to identify areas requiring attention.

Takeaway

Privacy compliance is no longer simply about having a privacy policy sitting on a website. Organisations are increasingly expected to understand what personal information they hold, where it came from, who has access to it, and how individuals can exercise their privacy rights. The introduction of IPP 3A is a timely reminder that organisations need to understand not only what personal information they collect, but also where it comes from, who has access to it, and how individuals are informed about its use.

A proactive privacy health check and review today is generally far easier than responding to a privacy complaint, Privacy Commissioner investigation or notifiable privacy breach tomorrow.

Contact Your Legal Counsel today to discuss a privacy health check for your team.

Further information

Other Recent Legal Updates