Privacy and Responsible Information Sharing Act 2024 and Record Keeping Obligations

Frequently Asked Questions FAQs - PRIS and Record Keeping
Last updated:

From 1 July 2026 most of the privacy obligations contained in the Privacy and Responsible Information Sharing Act 2024 (PRIS Act), including the Information Privacy Principles (IPPs) will commence. The notifiable breach obligations contained in Part 2 Division 6 commence later on 1 January 2027.

The PRIS Act regulates how public entities covered under the Act (called IPP entities) collect, use and disclose personal information.

Please refer to the Office of the Information Commissioner website for more information about the PRIS Act.

The State Records Office acknowledges the Department of Premier and Cabinet, the State Solicitor's Office, the Department of Justice, the Office of the Information Commissioner and the State Records Advisory Committee for contributing to the development of these FAQs.

Is my organisation required to comply with the PRIS Act when handling records containing personal information?

The Information Privacy Principles (IPPs) guide the handling of personal information by ‘IPP entities’, including collection, use, disclosure, and security.

An IPP entity is a public entity, a Minister, a Parliamentary Secretary, or a contracted service provider as defined under the PRIS Act.

Refer to:

Can my organisation keep State records which contain personal information?

IPP 4.2 of the PRIS Act requires that IPP entities must take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for any purpose authorised under the IPPs, unless its retention is expressly required or authorised by or under another law. This includes solicited or unsolicited personal information (e.g. an email sent to the organisation by mistake).

Most State organisations have record keeping obligations under the State Records Act 2000 (WA). State records may only be destroyed or permanently de-identified in accordance with an approved retention and disposal authority approved by the State Records Commission.

State records are retained for different periods of time depending on the government activity to which the record relates. Some State records will be retained permanently as a State archive. The retention period of a State record is determined by the circumstances of its creation and use, not merely by the fact that it contains personal information.

A State organisation is not required to destroy or permanently de-identify personal information if it is authorised or required to retain that information by the State Records Act 2000. 

When a State record containing personal information is no longer authorised or required to be retained, it should be destroyed or permanently de-identified in accordance with IPP 4.2, having regard to an organisation’s documented procedures.

Refer to Records Management Guideline - Records Retention, Disposal and Destruction 

My organisation only does standard disposal once a year. If we receive unsolicited personal information, should we continue to store it until the standard disposal is signed off?

If you have received personal information that was not requested by your organisation (i.e. unsolicited information), it may be redacted or destroyed upon receipt, as set out in item 71.3 of the General Retention and Disposal Authority for State Government Information (GRDASG 2023-004) and item 88.3 of the General Retention and Disposal Authority for Local Government Information (GRDALG 2023-005). This practice should be clearly documented in your relevant procedures.

Does my organisation have to retain copies of proof-of-identity documents?

It is not necessary to make copies of or retain documents that are sighted as proof of an individual’s identity. An officer should create a record that the relevant documents were sighted to verify an individual’s identity. Once the verification and validation process is complete, such documents should be returned to the individual and any unsolicited copies immediately destroyed or de-identified. 

This is authorised under GRDASG 71.2 or GRDALG 88.2 and the practice should be clearly documented in your relevant procedures. 

Refer to Records Management Advice - Retention of Personal Information

A client has written to request that we delete their personal information. Can their personal information be redacted or can the records be removed from our record keeping systems?

A State record, or personal information contained in a State record, cannot be deleted upon request. 

The State Records Act 2000 sets out the requirements for record keeping for all State organisations in Western Australia. There are many retention and disposal authorities for different categories of State records. These authorities set the minimum time each type of record must be retained and authorises records to be destroyed or archived after this period has expired. When a State record containing personal information is no longer required to be retained, it should be destroyed or permanently de-identified in accordance with IPP 4.2, having regard to an organisation’s documented procedures.

Additionally, section 45 of the Freedom of Information Act 1992 (FOI Act) provides that individuals have a right to apply to an agency (as defined under the FOI Act) for amendment of personal information about them, if the information is inaccurate, incomplete, out of date or misleading. The amendment application must state the form of the amendment which includes whether the person wishes the amendment to be made by striking out or deleting the information. However, an agency cannot destroy or remove information, or amend a document that results in its destruction, without written certification from the Information Commissioner.

For completeness, the PRIS Act also permits individuals to request an IPP entity correct their personal information if it is inaccurate, incomplete and out of date under IPP 6. However, IPP 6 only applies to contracted service providers. 

Refer to:

A client has written to request that we correct their personal information. Can State records be altered?

In accordance with IPP 3 of the PRIS Act, organisations should take reasonable steps to ensure that personal information they collect, use or disclose is accurate, complete and up to date.

Section 45 of the Freedom of Information Act 1992 (FOI Act) provides that individuals have a right to apply to an agency for amendment of personal information about them, if the information is inaccurate, incomplete, out of date or misleading.

Section 48 of the FOI Act specifies the ways in which personal information may be amended in response to an amendment application.  Among other things, it provides that an agency is not to obliterate or remove information or destroy a document without written certification from the Information Commissioner. 

The PRIS Act also provides that individuals have a right to access or correct personal information that a contracted service provider to the WA government holds about them under IPP 6. 

Please note: If an individual applies to access or correct their personal information under the FOI Act or the PRIS Act but uses the wrong legislation, the organisation must treat their application as having been made under the correct law. See section 98A of the FOI Act and section 44 of the PRIS Act. 

Refer to:

Records Management Advice - Retention of Personal Information
Privacy guidance issued by the WA Office of the Information Commissioner

Should personal information in State archives be redacted before release?

Access to State archives is provided for under the State Records Act 2000 Part 6.

Section 22 of the PRIS Act provides that the Information Privacy Principles do not apply to the handling of information contained in a document that is, among other things, a State archive to which a person has a right to be given access under the State Records Act 2000 Part 6.

Can State records containing personal information be published on websites?

Some laws may require an organisation to publish (or “make available”) particular government records that may contain personal information, such as names or contact details.  For example, Local Government Council Minutes and Agendas and Gift Registers are required under legislation, to be posted on a Local Government’s website. 

Section 22 of the PRIS Act provides that the Information Privacy Principles (IPPs) do not apply to the handling of information contained in a document that is, among other things, published or available for inspection (whether for a fee or charge or not) under a written law. 

However, if agencies maintain a public register, Part 2 Division 7 of the PRIS Act contains additional obligations regarding the handling of personal information. 

From 1 July 2026, organisations responsible for administering a public register must not disclose personal information in the public register unless it complies with the purpose of the register or the law under which it is maintained. 

Section 77 of the PRIS Act provides that individuals may request that their personal information is removed from the public register if their safety or wellbeing is, or would be, substantially affected by the publication of their information. 

Where organisations include internal publications such as record keeping plans or policies and procedures on their websites, organisations should consider publishing an outward facing version without personal and security-based information.

Our organisation collects a lot of information about client interactions. If we de-identify this information, can we continue to keep it longer than the retention period shown in a retention and disposal authority?

IPP 4.2 provides that IPP entities must take reasonable steps to destroy or permanently de-identify personal information no longer needed for any purpose authorised under the IPPs, unless its retention is expressly required or authorised by or under another law.

Once personal information is properly de-identified, it no longer constitutes personal information. 
However, in accordance with IPP 11.1, an IPP entity must take reasonable steps to protect de-identified information from misuse and loss, and from unauthorised re-identification, access, modification or disclosure. 

In addition, organisations will need to be mindful of other record keeping obligations under a retention and disposal authority that may still apply to the de-identified information.

Have a question or want to report a problem?

Fill in the form to get assistance or tell us about a problem with this information or service.

Send feedback