AI Framework

Information Privacy Act 2009 (Qld): Who It Covers Now

The Information Privacy Act 2009 (Qld) is Queensland public sector privacy law - it doesn't directly cover private business. Since 1 July 2025, it runs a single set of Queensland Privacy Principles (QPPs), replacing the old Information and National Privacy Principles split. A private business is only bound as a contracted service provider to Queensland Government.

The Information Privacy Act 2009 (Qld) is Queensland's own privacy framework, separate from the Commonwealth Privacy Act 1988. It's administered by the Office of the Information Commissioner Queensland (OIC Qld) - and as of 1 July 2025, it works quite differently than it did a year ago.

The Information Privacy Act 2009 is Queensland state law, separate from the Commonwealth instruments AI Framework maps to a business's profile. For most private businesses, those Commonwealth obligations are the ones that matter.

Who it actually applies to

The Information Privacy Act 2009 binds Queensland public sector agencies directly: departments, local governments, statutory bodies, public hospitals and Hospital and Health Services. OIC Qld states it plainly: the Act "does not cover private healthcare providers or private companies and businesses, even if they're in Queensland." A private business in Queensland isn't governed by this Act for general personal information handling - the Australian Privacy Principles under the Commonwealth Act are, the same as in every other state.

Who the IP Act 2009 actually covers

The one way a private business does get pulled in

A private business becomes bound by the Queensland Privacy Principles only as a contracted service provider to Queensland Government - and there's no small-business exemption. Once an agency's contract binds a provider, that provider must comply with the QPPs "as if it were the agency," and its compliance can be enforced the same way. If the agency fails to bind a contractor that should have been bound, the agency carries the liability instead - but a properly bound contractor carries enforceable obligations under the QPPs, regardless of size.

For businesses holding, or pursuing, Queensland Government contracts - especially those involving AI systems - this is the part of Queensland privacy law that applies.

Businesses holding or pursuing Queensland Government work involving AI still carry obligations under the Information Privacy Act 2009 and the Commonwealth framework. AI Framework maps the Commonwealth and state instruments that apply to a business's own profile.

What actually changed on 1 July 2025

Queensland's privacy framework used to run two separate principle sets - Information Privacy Principles for most agencies, National Privacy Principles for health agencies - and that split no longer exists. The Information Privacy and Other Legislation Amendment Act 2023 abolished both and replaced them with a single unified set, the Queensland Privacy Principles, deliberately modelled on the Commonwealth's Australian Privacy Principles. Queensland Health and Hospital and Health Services now sit on the same QPP set as every other agency, though they retain a separate confidentiality layer under the Hospital and Health Boards Act 2011 that non-health agencies don't carry.

One small, genuinely confusing detail worth clearing up: the QPP list skips numbers 7, 8 and 9. That's deliberate - the Commonwealth APPs do have principles at those numbers (direct marketing, cross-border disclosure and government identifiers), but Queensland didn't adopt them because they're not relevant to public sector agencies. The numbering was kept aligned rather than renumbered sequentially.

The 13 Queensland Privacy Principles (QPPs) - current since 1 July 2025

The reform also brought in a mandatory data breach notification scheme, live for agencies since 1 July 2025 and for local government from 1 July 2026 - agencies now have to assess a suspected breach within 30 days and notify affected individuals and the Information Commissioner where there's reasonable grounds to believe serious harm is likely.

AI and the Information Privacy Act 2009

OIC Qld has published AI-related material, though it's less developed than the Commonwealth OAIC's guidance or Victoria's OVIC equivalent. OIC Qld's own published commentary - from the Information Commissioner, on the government use of AI in Queensland - touches on AI needing to be designed and used in a way that's open, transparent and accountable, alongside a "Generative AI and privacy" guidance item and a 2026 Privacy Awareness Week theme built around AI.

The sharpest, most current example: a September 2025 Queensland Audit Office report found real gaps. The Audit Office's Managing the ethical risks of artificial intelligence examined the Department of Transport and Main Roads' handling of two live AI systems - its image-recognition mobile phone and seatbelt detection tool, and its generative AI tool, QChat - and found the department "is not effectively identifying and managing aspects of ethical risks" associated with them. The report recommended structured AI ethical-risk-assessment processes across the public sector.

The more concrete artefact is the FAIRA framework - the Foundational Artificial Intelligence Risk Assessment, issued through Queensland Government's enterprise architecture standards in September 2024. It runs three parts: mapping an AI system's technical architecture and data flows, assessing potential harms including to privacy, and identifying controls to reduce the risk found.

How this compares to the Commonwealth framework

Queensland's 13 QPPs are now closely modelled on the Commonwealth's 13 Australian Privacy Principles - deliberately, following the 2025 reform - but they're still a separate framework, administered separately, for a different scope (Queensland public sector, not the whole economy). Similarity in structure doesn't mean the two are interchangeable.

FAQ

Does the Information Privacy Act 2009 apply to my business? Not directly, unless you're a contracted service provider to Queensland Government. Private Queensland businesses are otherwise governed by the Commonwealth Privacy Act 1988.

What's the difference between the Information Privacy Act 2009 and the Privacy Act 1988? The Queensland Act covers Queensland public sector agencies. The Commonwealth Act covers private business generally (above the turnover threshold) and Commonwealth agencies. Separate, parallel frameworks.

What happened to the Information Privacy Principles and National Privacy Principles? As of 1 July 2025, both were replaced with a single set - the Queensland Privacy Principles (QPPs) - modelled on the Commonwealth APPs. If you've read about IPPs or NPPs elsewhere, that structure no longer applies.

Do I have to notify a data breach in Queensland? Queensland Government agencies do, under the mandatory notification scheme live since 1 July 2025 (local government from 1 July 2026). Private businesses generally follow the Commonwealth notifiable data breach scheme instead, unless bound by a Queensland Government contract.

Is Queensland Health covered by a different privacy law? Queensland Health and Hospital and Health Services are now on the same QPP set as other agencies, but carry an additional confidentiality layer under the Hospital and Health Boards Act 2011 that other agencies don't.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

The Information Privacy Act 2009 covers the Queensland public sector, not private business. If your business handles personal information and uses AI, address it today with AI Framework.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights