In this episode, privacy experts Richard Wells and Suzy McMillan discuss key privacy law obligations when engaging service providers, including who remains responsible for personal information under the Privacy Act 2020, the often-overlooked requirements of IPP 5, and practical steps organisations should take to manage security risks.
[01:18] Richard and Suzy discuss who remains responsible for personal information when it is handed over to a third-party service provider. Suzy explains that, under section 11 of the Privacy Act, organisations generally retain responsibility for personal information, even when it is stored or processed by a third party on their behalf.
[05:47] Suzy explains the requirements of IPP 5(a) and (b), which require organisations to implement reasonable security safeguards to protect personal information and to take reasonable steps to prevent its unauthorised use or disclosure by service providers.
[08:25] They discuss security safeguards organisations should implement in practice, covering not only technical measures such as access controls, multi-factor authentication and monitoring, but also organisational controls. They highlight the importance of thorough procurement due diligence, robust contractual protections, ongoing governance and oversight, privacy impact assessments, and embedding privacy-by-design principles throughout the project lifecycle.
[12:03] Suzy highlights that, to meet their IPP 5 obligations, organisations must independently verify a service provider’s security controls rather than relying solely on marketing claims or assurances. While certifications such as ISO 27001 can provide useful evidence of a provider’s security posture, she notes that they are only one part of the picture and should be supported by ongoing due diligence and regular verification.
[16:22] They consider some practical steps organisations can take to strengthen IPP 5 compliance, including mapping suppliers that hold or process your organisations personal information, reviewing contracts, understanding breach notification processes, independently verifying security controls, and conducting regular reviews.
[18:26] Lastly Richard highlights the importance of organisations maintaining a tested incident response plan so they can respond quickly and effectively if a privacy incident occurs.
Information in this episode is accurate as at the date of recording, 23 September 2026.
Please contact Richard Wells, Suzy McMillan or our Data protection team if you need legal advice and guidance on any of the topics discussed in the episode.
You can also email us directly at [email protected] and sign up to receive technology updates via your inbox here.
Additional resources