Privacy and Responsible Information Sharing Act 2024

Privacy and Responsible Information Sharing (Information Sharing) Amendment Regulations 2026

 

 

Privacy and Responsible Information Sharing (Information Sharing) Amendment Regulations 2026

Contents

1.Citation1

2.Commencement1

3.Regulations amended1

4.Part 3 replaced2

Part 3 — Key concepts

25.Exempt information (Act s. 158)2

26.Handling of information for purpose of prescribed community policing functions (Act s. 159)3

Part 4 — Information sharing agreements

27.Additional matters to be included in information sharing agreements (Act s. 170)3

28.Privacy impact assessments not required to be made publicly available (Act s. 176)4

29.Content of notification of Chief Data Officer4

30.Content of register of information sharing agreements (Act s. 183)5

Part 5 — Authorisations to share information and related matters

31.Secrecy provisions not overridden (Act s. 187)6

32.Safeguards (Act s. 190)6

Part 6 — Miscellaneous

33.Making documents publicly available (Act s. 209)7

34.Giving documents by electronic means7

Part 7 — Transitional provisions

35.Information sharing agreements entered into before relevant Act provisions commence9

36.Information not required to be included in annual report before relevant Act provisions commence10

 

Privacy and Responsible Information Sharing Act 2024

Privacy and Responsible Information Sharing (Information Sharing) Amendment Regulations 2026

Made by the Governor in Executive Council.

1.Citation

These regulations are the Privacy and Responsible Information Sharing (Information Sharing) Amendment Regulations 2026.

2.Commencement

These regulations come into operation as follows —

(a)regulations 1 and 2 — on the day on which these regulations are published on the WA legislation website;

(b)the rest of the regulations — on 1 July 2026.

3.Regulations amended

These regulations amend the Privacy and Responsible Information Sharing (Information Sharing) Regulations 2025.

4.Part 3 replaced

Delete Part 3 and insert:

 

Part 3 — Key concepts

25.Exempt information (Act s. 158)

(1)For the purposes of section 158(1)(r) of the Act, information of the following classes is exempt information —

(a)information that is subject to an order under the Corruption, Crime and Misconduct Act 2003 section 114;

(b)information of a kind referred to in the Corruption, Crime and Misconduct Act 2003 section 115;

(c)information of a kind referred to in the Criminal Investigation (Covert Powers) Act 2012 section 75;

(d)information the disclosure of which could reasonably be expected to reveal, or enable to be ascertained, investigative measures or procedures under the Procurement Act 2020 Part 7.

(2)For the purposes of section 158(2)(h) of the Act, the following special information sharing entities are prescribed —

(a)the Electoral Distribution Commissioners referred to in the Electoral Act 1907 section 16B;

(b)the State Solicitor, but only in relation to documents originating with or received by the State Solicitor in connection with functions under the High Risk Serious Offenders Act 2020.

26.Handling of information for purpose of prescribed community policing functions (Act s. 159)

For the purposes of section 159(3)(a) of the Act, information may be handled under an information sharing agreement for a purpose that relates to a community policing function of the Police Force of Western Australia that is undertaken in connection with family violence.

Part 4 — Information sharing agreements

27.Additional matters to be included in information sharing agreements (Act s. 170)

(1)For the purposes of section 170(j) of the Act, and without limiting section 170(h) or 171(3)(c) of the Act, an information sharing agreement must —

(a)provide for the destruction, retention or transfer of the disclosed information, and any derived information, by the recipient; and

(b)without limiting paragraph (a), include a requirement for the recipient to provide written notice to the provider if the disclosed information is destroyed.

(2)A requirement included in an information sharing agreement under subregulation (1) must not be inconsistent with —

(a)any applicable duties the recipient has under the State Records Act 2000; or

(b)any applicable duties in relation to the destruction, retention or transfer of information that the recipient has under another written law or a law of the Commonwealth, another State or a Territory.

28.Privacy impact assessments not required to be made publicly available (Act s. 176)

For the purposes of section 176(6)(b) of the Act, a privacy impact assessment report is not required to be made publicly available if —

(a)the Chief Data Officer considers that making the report publicly available would be likely to reveal, or enable to be ascertained —

(i)confidential or commercially sensitive information; or

(ii)information that is exempt matter for the purposes of the Freedom of Information Act 1992 under Schedule 1 clause 1 of that Act; or

(iii)information about weaknesses in security measures protecting personal information that could be used for the purposes of circumventing those measures;

and

(b)a redacted or summary form of the report, approved by the Chief Data Officer, is made publicly available.

29.Content of notification of Chief Data Officer

A written notice under section 182(1) or (2) of the Act of an information sharing agreement or a variation agreement must include —

(a)whether a privacy impact assessment report has been prepared under section 176 of the Act; and

(b)if a privacy impact assessment report has been prepared under section 176 of the Act, the following information about the report —

(i)whether the report is publicly available;

(ii)if it is publicly available — where it is made available;

(iii)if it is not publicly available — the grounds on which it is not required to be made publicly available under section 176(6) of the Act.

30.Content of register of information sharing agreements (Act s. 183)

(1)For the purposes of section 183(2)(f) of the Act, the register must include, in relation to each information sharing agreement that is in force, whether a privacy impact assessment report has been prepared under section 176 of the Act and, if so, whether the report is publicly available.

(2)For the purposes of section 183(3)(b) of the Act, the register is not required to include the information referred to in section 183(2)(c) and (d) of the Act in relation to an information sharing agreement if the Chief Data Officer considers that making that information publicly available would be likely to reveal, or enable to be ascertained —

(a)confidential or commercially sensitive information; or

(b)information that is exempt matter for the purposes of the Freedom of Information Act 1992 under Schedule 1 clause 1 of that Act.

Part 5 — Authorisations to share information and related matters

31.Secrecy provisions not overridden (Act s. 187)

For the purposes of section 187(3)(b) of the Act, section 187(1) of the Act does not apply to the following secrecy provisions —

(a)the Contaminated Sites Act 2003 section 96(3);

(b)the Environmental Protection Act 1986 section 120;

(c)the Waste Avoidance and Resource Recovery Act 2007 section 91.

32.Safeguards (Act s. 190)

(1)If information is disclosed by a provider to a recipient under an information sharing agreement, the recipient must ensure that the information is designated as having been disclosed under the information sharing agreement.

(2)Subregulation (3) applies if, in accordance with section 172 of the Act, an information sharing agreement provides for a recipient to be permitted to further disclose information it collects under the agreement to another person (the third party) who is not a party to the agreement.

(3)The recipient must, before further disclosing the information, enter into a contract, agreement or other arrangement with the third party under which the third party agrees to collect, hold, manage and use the information in compliance with the applicable provisions of the information sharing agreement.

Part 6 — Miscellaneous

33.Making documents publicly available (Act s. 209)

If a provision of Part 3 of the Act requires or permits the Chief Data Officer to make a document publicly available, the Chief Data Officer must comply with that requirement or exercise that power by —

(a)publishing the document on a website maintained by, or on behalf of, the information sharing Department; and

(b)making a hard copy of the document available for inspection on request during business hours at the principal office of the information sharing Department.

Example for this regulation:

Chief Data Officer guidelines must be made publicly available under section 201(4) of the Act.

34.Giving documents by electronic means

(1)A notice or other document that is required or permitted to be given to the Chief Data Officer under Part 3 of the Act may be given by —

(a)sending it in an electronic form to an email address of the Chief Data Officer specified on a website maintained by, or on behalf of, the information sharing Department for that purpose; or

(b)lodging it in an electronic form using an online system maintained by, or on behalf of, the information sharing Department for that purpose.

(2)A notice or other document that is required or permitted to be given to a person by the Chief Data Officer under Part 3 of the Act may be given by —

(a)if the person has provided an email address for giving documents — sending it in an electronic form to the email address provided by the person; or

(b)making it available to the person in an electronic form using an online system maintained by, or on behalf of, the information sharing Department for that purpose and notifying the person by email sent to an email address provided by the person that it is available.

(3)An information sharing request may be given to the holding entity by sending it in an electronic form to an email address of the holding entity specified on a website maintained by, or on behalf of, the holding entity for that purpose.

(4)A written notice responding to an information sharing request under section 161 of the Act may, if the requesting entity has provided an email address for giving documents, be given to the requesting entity by sending it in an electronic form to the email address provided by the requesting entity.

(5)The notice or other document is taken to be given —

(a)if given under subregulation (1)(a) — at the time it reaches the email address of the Chief Data Officer; or

(b)if given under subregulation (2)(a) — at the time it reaches the email address provided by the person; or

(c)if given under subregulation (1)(b) or (2)(b) — at the time it is lodged or made available in the online system; or

(d)if given under subregulation (3) — at the time it reaches the email address of the holding entity; or

(e)if given under subregulation (4) — at the time it reaches the email address provided by the requesting entity.

(6)This regulation does not limit the application of the Interpretation Act 1984 sections 75 and 76 to the notice or other document.

Part 7 — Transitional provisions

35.Information sharing agreements entered into before relevant Act provisions commence

If section 170 of the Act requires a matter relating to a provision of the Act to be included in an information sharing agreement, but the provision has not come into operation when the agreement comes into force —

(a)the matter must still be included in the agreement; but

(b)the agreement has no effect in relation to the matter for the period —

(i)beginning on the day the agreement comes into force under section 178(1) of the Act; and

(ii)ending on the day immediately before the provision comes into operation.

Example for this regulation:

Under section 170(e) of the Act, an information sharing agreement must require each recipient under the agreement to comply with sections 192, 193 and 194(4) of the Act in relation to a shared information breach or suspected shared information breach involving information disclosed under the agreement. An agreement entered into before those sections of the Act come into operation must still include that matter, but will have no effect in relation to that matter until sections 192, 193 and 194(4) of the Act come into operation.

36.Information not required to be included in annual report before relevant Act provisions commence

(1)In this regulation —

annual report means an annual report required under the Financial Management Act 2006 Part 5 in respect of the information sharing Department.

(2)Section 211 of the Act does not require an annual report for a financial year to include any information about a matter relating to a provision of the Act if the provision has not come into operation before the end of that financial year.

Example for this regulation:

The annual report for a financial year is not required to include information about the number of shared information breaches notified to the Chief Data Officer in the financial year if section 193 of the Act has not come into operation before the end of the financial year.

 

N. HAGLEY, Clerk of the Executive Council

© State of Western Australia 2026.

This work is licensed under a Creative Commons Attribution 4.0 International Licence (CC BY 4.0). To view relevant information and for a link to a copy of the licence, visit www.legislation.wa.gov.au.

Attribute work as: © State of Western Australia 2026.

By Authority: ANDREW JONES, Government Printer