Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
One of the important changes in the Privacy Amendment Act 2025 is the addition of Information Privacy Principle (IPP) 3A. IPP3A changes an agency’s obligations when it collects personal information indirectly. Collecting personal information indirectly means that the agency collects the personal information from someone other than the person themself.
Watch our short video on YouTube.(external link)
Read our IPP3A guidance: notification requirements for indirect collection of personal information.
Read our IPPA(5) guidance: archiving in the public interest.
If you're an organisation and have a privacy breach that is likely to cause anyone serious harm, you are legally required to notify us and any affected persons as soon as you can.
As a guide, our expectation is that a breach notification should be made to our Office no later than 72 hours after agencies are aware of a notifiable privacy breach. Work out whether you need to notify us.