WA’s privacy principles are live. The breach-notification clock starts 1 January 2027.

WA’s privacy principles went live this week. But the deadline that will actually make headlines is six months away.

The Information Privacy Principles commenced on 1 July 2026, but the Act’s notifiable information breach scheme is set to commence separately, on 1 January 2027. That gap is a runway, and it is the part most organisations will underuse.

The scheme will be familiar to anyone who knows the Commonwealth notifiable data breaches regime: an eligible breach must be assessed and notified to the Information Commissioner, and to affected individuals, within defined timeframes. There are differences in the WA version, and they matter, but the operational reality is the same. If you cannot detect a breach, scope it and notify quickly, the deadline will find you unprepared.

Six months is enough time to get the fundamentals in place: an incident response plan that names who does what, logging that lets you reconstruct what happened, and contracts with providers that make breach reporting an obligation, not a favour. Start before January, not after your first incident.
About Nguma

AI interview management and transcription built for Australian Government compliance.

Nguma automates APS interview scribing, Selection Reports, and meeting transcription. Everything processed onshore in Australia. No AI decision-making. Full audit trail for Merit Protection review. 51% Indigenous-owned.

Learn about Nguma →