AI Framework

Privacy and Data Protection Act 2014 (Vic): Who It Covers

The Privacy and Data Protection Act 2014 (Vic) is a Victorian public sector privacy law - it binds government departments, councils, Victoria Police and statutory authorities. It doesn't directly cover private businesses. A private business is only bound if it's a contracted service provider to Victorian government and the contract specifically says so.

The Privacy and Data Protection Act 2014 (Vic) - sometimes searched as the "Data and Privacy Protection Act 2014," same Act, transposed name - set up Victoria's own privacy framework, separate from the Commonwealth Privacy Act 1988. It's administered by the Office of the Victorian Information Commissioner (OVIC), not the OAIC.

The Privacy and Data Protection Act 2014 is Victorian state law, separate from the Commonwealth instruments AI Framework maps to a business's profile. For most private businesses, those Commonwealth obligations are the ones that matter.

Who it actually applies to

The PDP Act binds Victorian public sector organisations directly: government departments, ministers, local councils, Victoria Police, and statutory authorities carrying out public functions. It doesn't reach private business the way the Commonwealth Privacy Act does. A private business in Victoria isn't governed by this Act for general personal information handling - the Australian Privacy Principles under the Commonwealth Act are the relevant framework.

Who the PDP Act 2014 actually covers

The one way a private business does get pulled in

A private business becomes bound by the PDP Act's Information Privacy Principles only as a contracted service provider to Victorian government - and only if the contract itself contains a clause saying so. OVIC states it plainly: without that clause, the government agency carries the compliance responsibility for its contractor's conduct, not the contractor itself. With the clause, the obligation flows directly to the business.

This matters more than it might sound. Victorian Government procurement policy - OVIC's own guidance and the state's "Navigating AI in Procurement" material - increasingly asks buyers to require evidence of supplier AI governance before a contract is signed: transparency about how AI is used, training-data restrictions, human oversight, model evaluation, incident notification. For businesses supplying, or wanting to supply, AI-powered services into Victorian government, this is the real reason to understand this Act specifically.

Businesses supplying AI-powered services to Victorian government still carry obligations under the Privacy and Data Protection Act 2014 and the Commonwealth framework. AI Framework maps the Commonwealth and state instruments that apply to a business's own profile.

What OVIC's own AI guidance says

OVIC has current, substantive guidance on AI and privacy - flagging five of the ten IPPs as the ones AI use puts pressure on: Collection, Use and Disclosure, Data Quality, Data Security and Openness. A few specifics worth knowing:

The 10 Information Privacy Principles (IPPs)

Privacy risk in the Victorian public sector is rising fast

OVIC's own 2024-25 Annual Report shows both incident and complaint volumes jumped sharply: 1,094 information security incidents, up 50% on the year before, and 162 privacy complaints, up 51%. OVIC doesn't break these out by cause, so there's no verified "X% involved AI" figure to point to - but the volume of personal information now flowing through AI-assisted systems in the Victorian public sector is part of the wider picture those numbers sit inside.

How this compares to the Commonwealth framework

Victoria's 10 IPPs cover similar ground to the Commonwealth's 13 Australian Privacy Principles - collection, use, quality, security, access - but they're a separate set, administered separately, and built for a different scope (public sector, not the whole economy). The two are not interchangeable, and compliance with one does not automatically satisfy the other.

FAQ

Does the Privacy and Data Protection Act 2014 apply to my business? Not directly, unless you're a contracted service provider to Victorian government with an IPP clause in your contract. Otherwise your business is governed by the Commonwealth Privacy Act 1988.

Is it the "Privacy and Data Protection Act 2014" or the "Data and Privacy Protection Act 2014"? Privacy and Data Protection Act 2014 (Vic) is the correct name - "Data and Privacy Protection Act 2014" is a common transposition of the same Act, not a separate law.

What are the 10 Information Privacy Principles? Collection, Use and Disclosure, Data Quality, Data Security, Openness, Access and Correction, Unique Identifiers, Anonymity, Transborder Data Flows, and Sensitive Information - Victoria's own set, distinct from the Commonwealth's 13 APPs.

How does this Act relate to the Commonwealth Privacy Act? They're separate, parallel frameworks. The PDP Act covers the Victorian public sector; the Commonwealth Act covers private business generally (above the turnover threshold) and Commonwealth agencies.

I supply services to Victorian government - am I covered? Only if your contract specifically binds you to the IPPs. Check the contract terms directly rather than assuming either way - and be ready to show AI governance evidence, since Victorian procurement policy increasingly requires it.

For a broader view of how Australian privacy law applies to AI, see Data privacy regulations in Australia.

The Privacy and Data Protection Act 2014 covers the Victorian public sector, not private business. If your business handles personal information and uses AI, address it today with AI Framework.

This post is general information, not legal advice.

Current as at September 2026.

← Back to Insights