02 Sep 2026

Privacy meets recordkeeping: WA’s PRIS Act

Western Australia’s new privacy regime is now in effect, bringing privacy and recordkeeping obligations into much closer focus for government agencies and Records and Information Management practitioners.

privacy.png 1

 

Most privacy obligations under the Privacy and Responsible Information Sharing Act 2024 (PRIS Act), including the Information Privacy Principles (IPPs), commenced on 1 July 2026. Notifiable data breach obligations will follow from 1 January 2027.

To help agencies navigate the intersection between the new privacy requirements and existing recordkeeping responsibilities, the State Records Office of Western Australia has released updated FAQs addressing some very practical questions.

And they are questions many R&IM practitioners will recognise.

Privacy does not remove recordkeeping obligations

The PRIS Act regulates how public entities covered by the legislation collect, use and disclose personal information. However, agencies also have obligations governing how State records are created, retained and lawfully disposed of.

This means requests involving personal information cannot necessarily be treated as simple instructions to delete or alter a record.

The State Records Office guidance addresses questions including whether State records containing personal information can continue to be retained, what happens when an individual requests deletion or correction of their information, how unsolicited personal information should be managed and whether proof-of-identity documents need to be kept.

It also considers the treatment of personal information in State archives, publication of records online and whether de-identifying information allows an organisation to retain it beyond an authorised retention period.

A balancing act for R&IM practitioners

For R&IM professionals, the guidance reinforces the importance of understanding the relationship between privacy, retention, disposal and the integrity of the official record.

Holding personal information for longer than necessary can create privacy, cybersecurity and organisational risk. At the same time, destroying information simply because it contains personal information could conflict with statutory recordkeeping requirements.

The key is knowing what information the organisation holds, why it holds it, what authority governs its retention and when lawful disposal can occur.

It also reinforces why disposal should be an active and ongoing information governance process rather than something addressed only periodically. As privacy expectations increase, retaining unnecessary personal information can become an increasingly significant organisational liability.

R&IM at the centre of privacy compliance

The introduction of the PRIS Act demonstrates how closely privacy and R&IM are now connected.

R&IM practitioners have an important role to play in helping organisations establish defensible retention and disposal practices, manage personal information appropriately, preserve the integrity of State records and ensure privacy requirements are considered throughout the information lifecycle.

For WA practitioners in particular, now is a good time to review policies, disposal processes and information governance arrangements ahead of the notifiable data breach requirements commencing on 1 January 2027.

The State Records Office FAQs provide practical guidance for navigating these overlapping responsibilities and are well worth adding to the R&IM toolkit.

Visit the website here to read