PPIP Act (NSW): Who It Actually Covers
13 September 2026
The PPIP Act 1998 (NSW) - the Privacy and Personal Information Protection Act - covers NSW public sector agencies: departments, councils, universities and statutory bodies. It doesn't directly cover private businesses. A private business only picks up obligations under it if a specific NSW Government contract requires compliance with its Information Protection Principles.
The PPIP Act sits within NSW's own privacy framework - separate from the Commonwealth's 13 Australian Privacy Principles, administered separately by the NSW Information and Privacy Commission (IPC NSW), and covering a different scope entirely.
The PPIP Act is NSW state law, separate from the Commonwealth instruments AI Framework maps to a business's profile. For most private businesses, those Commonwealth obligations are the ones that matter.
Who it actually applies to
The PPIP Act binds NSW public sector agencies directly: departments, local councils, universities, statutory bodies, and other bodies whose accounts are subject to the Auditor General. It doesn't reach private business the way the Commonwealth Act does. For private business in NSW, the PPIP Act isn't the relevant framework for handling personal information generally - the Australian Privacy Principles under the Commonwealth Act are.
Who the PPIP Act 1998 actually covers
The one way a private business can get pulled in
A private business only picks up obligations under the PPIP Act if its specific NSW Government contract requires compliance with the Information Protection Principles - it isn't an automatic statutory bind the way it can be in some other states. The actual contract terms determine whether compliance is required - it isn't automatic. For businesses supplying, or looking to supply, services to NSW Government, this is the part of NSW privacy law worth understanding on its own terms.
The 12 Information Protection Principles
The IPPs are the core of the PPIP Act - 12 principles that describe what covered agencies must do when handling personal information.
- 1 - Lawful collection
- 2 - Direct collection from the individual
- 3 - Open - tell people why and what happens to it
- 4 - Relevant, accurate, complete, not excessive
- 5 - Secure storage and disposal
- 6 - Transparent - individual can find out what's held
- 7 - Accessible - individual can access their own information
- 8 - Correctable on request
- 9 - Checked for accuracy before use
- 10 - Limited to the purpose collected
- 11 - Restricted disclosure
- 12 - Extra safeguards on sensitive information
These cover similar ground to the Commonwealth's 13 Australian Privacy Principles - collection, use, access, security - but they're a separate set, administered separately, for a different scope (NSW public sector, not the whole economy). The two frameworks aren't interchangeable.
What about private health providers?
Private health service providers in NSW are covered by a different law entirely - the Health Records and Information Privacy Act 2002. That Act does bind private businesses handling health information directly, with its own 15 Health Privacy Principles. Private health service providers - GP practices, allied health providers and others handling health information - fall under the HRIP Act, not the PPIP Act.
What IPC NSW's own AI guidance says
IPC NSW has published AI-specific guidance for agencies - a generative AI privacy risk guide (May 2026) and a separate Privacy Impact Assessment guide for AI systems and projects. The generative AI guide covers the risk of personal or health information ending up in prompts, uploads or outputs sent to tools like ChatGPT, Gemini, Claude or Copilot, the added risk of offshore processing, and recommended controls: privacy impact assessments, acceptable-use policies, staff training, and vetting third-party AI vendors' privacy controls and contractual safeguards.
This is guidance for agencies and their contractors specifically - not a general AI law, and not something that applies to a private business outside that relationship.
Data breach numbers
NSW's mandatory data breach notification scheme for the public sector has been live since November 2023, and the numbers are trending up. 52 eligible breaches were notified in the scheme's first partial period (November 2023 to June 2024), rising to 118 for the full 2024-25 financial year. The most common cause in the earlier reporting period was human error at 79% - misdirected emails and incorrect attachments - well ahead of malicious attacks. IPC NSW also finalised 944 information access and privacy reviews and complaints in 2024-25.
FAQ
Does the PPIP Act apply to my NSW business? Not directly, unless your contract with NSW Government specifically requires compliance with its Information Protection Principles. Otherwise your business is governed by the Commonwealth Privacy Act 1988.
What's the difference between the PPIP Act and the Privacy Act 1988? The PPIP Act covers NSW public sector agencies. The Commonwealth Act covers private business generally (above the turnover threshold) and Commonwealth agencies - separate, parallel frameworks.
Does the PPIP Act cover health information? No - that's a separate NSW law, the Health Records and Information Privacy Act 2002, which does apply directly to private health service providers.
I supply services to NSW Government - am I covered? Only if the contract specifically requires compliance with the Information Protection Principles. The contract terms determine whether compliance is required - it isn't automatic either way.
Has the PPIP Act been reformed recently? NSW's most recent major reform was the 2022 amendment that introduced the mandatory data breach notification scheme, which commenced November 2023. No further NSW-specific overhaul is currently underway.
For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.
The PPIP Act covers the NSW public sector, not private business. If your business handles personal information and uses AI, address it today with AI Framework.
This post is general information, not legal advice.
Current as at September 2026.