State agencies have different privacy rules
Commonwealth-compliant isn’t state-compliant. Check before you deploy.
State and territory agencies are not governed by the Commonwealth Privacy Act 1988 for their own handling of personal information. Each jurisdiction has its own framework. NSW: Privacy and Personal Information Protection Act 1998. Victoria: Privacy and Data Protection Act 2014. Queensland: Information Privacy Act 2009. SA: Information Privacy Principles Instruction. Tasmania: Personal Information Protection Act 2004. ACT: Information Privacy Act 2014. NT: Information Act 2002. WA: Privacy Principles via administrative policy.
The core obligations are broadly consistent: collection notification, purpose limitation, security, access rights, retention and destruction. But specifics differ. A system designed for Commonwealth APP compliance may not automatically satisfy state requirements.