Privacy Act controller and processor rules: is your MSP ready?

By Greg Markowski / Sep 2, 2026 / Cybersecurity & Compliance

On 31 August 2026 the Attorney-General’s Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, a package of roughly 40 proposed changes to the Privacy Act. Most of the commentary so far has come from lawyers, and fair enough. But buried in the draft is one change that lands squarely on the desk of every Perth business that outsources its IT: the introduction of controller and processor roles into the Privacy Act, borrowed from the EU’s GDPR.

Here is the short version. If these changes pass in their current form, your business would be the controller, your IT provider would be a processor, and you would carry primary responsibility for what they do with your data. Your MSP’s privacy failures would become your problem, legally and financially.

What the exposure draft actually proposes

The draft bill is open for public consultation through the Attorney-General’s Department, with submissions closing 18 September 2026. That is a window of under three weeks, which tells you the government wants this moving quickly.

The headline reforms include a new “fair and reasonable” test for handling personal information and, for the first time, a formal distinction between the organisation that decides why data is collected (the controller) and the organisation that handles it on their behalf (the processor). We covered the broader reform picture in our earlier guide to the Privacy Act changes for small business. This post focuses on the piece that changes your relationship with your IT provider.

None of this is law yet. Exposure drafts change, and this one will attract plenty of submissions. But the controller and processor concept has been on the reform agenda since the Privacy Act Review Report in 2023, so the direction of travel is clear even if the details shift.

Privacy Act controller and processor roles, in plain English

If your business collects customer, patient, client or employee information, you decide why that data exists and what it gets used for. Under the draft, that makes you the controller.

Your IT provider, your cloud vendors, your payroll platform and your marketing tools all handle that data on your instructions. Under the draft, they are processors.

The bit that should get your attention: under the proposed model, controllers would be primarily responsible for their processors’ breaches of the Australian Privacy Principles. In practice, if your IT provider mishandles your customer data, the regulator’s first phone call is to you.

This mirrors how the GDPR has worked in Europe since 2018. The difference is that European controllers can rely on regulator-approved Standard Contractual Clauses to manage that risk. The Australian draft, as it stands, offers no equivalent. That leaves every business negotiating its own data processing agreement (DPA) with every provider, and the quality of those agreements will vary wildly.

Why this matters for Perth businesses specifically

Perth’s SMB economy runs on outsourced IT. Law firms, medical practices, construction companies and financial services businesses across WA hand their most sensitive data to managed service providers every day, usually with an agreement that says plenty about response times and nothing about privacy compliance.

That has been fine, because the current Privacy Act does not formally split responsibility this way. If the reform passes, the businesses most exposed will be the ones handling sensitive personal information at volume. If you run a legal practice or a healthcare business, the data your IT provider touches is exactly the kind regulators care about most.

The uncomfortable question is not whether the reform affects you. It is whether you actually know what your current IT provider does with your data, and whether they could prove their security posture if you asked.

The controller and processor questions to ask your IT provider

You do not need to wait for the bill to pass. If these changes land, the businesses in good shape will be the ones that did their due diligence early. Put these questions to your MSP:

Where does our data live, and who can access it? A competent provider can answer this in specifics: which datacentres, which countries, which staff, which third-party tools. If the answer is vague, that is a gap.

What security framework do you actually operate under, and can you prove it? Not “we take security seriously”. A named framework with independent evidence: ISO 27001 certification, an SMB1001 certification tier, or a demonstrable Essential Eight maturity level. If they name a framework, ask to see the certificate.

What happens when you have a breach? How fast do they notify you, in what detail, and who is responsible for notifying the OAIC and affected individuals? Under the proposed model, “we’ll let you know” is nowhere near good enough, because the notification obligation would sit with you.

Who are your subcontractors? Your processor almost certainly uses other processors. Under a controller and processor regime, their supply chain becomes your risk.

Will you sign a data processing agreement? This is the real test. A provider that hesitates to put its privacy and security obligations in writing is telling you something.

Where we stand as a processor

We are on the other side of this equation. If the reform passes, Epic IT becomes a processor for every client we manage, and we think that is exactly the right pressure to put on our industry.

The MSP market has always had a quiet problem: businesses cannot easily tell a provider with genuine security discipline from one with a good sales deck. A liability regime that forces controllers to check changes that. Providers who cannot evidence their security posture, name their subcontractors or commit to breach notification timeframes will find those conversations difficult.

We will not. Epic IT is ISO 27001 certified and holds SMB1001 Gold, which means our security controls are independently audited rather than self-declared. We run our clients on the same frameworks we hold ourselves to, and our managed cyber security services are built around demonstrable controls rather than assurances. When the processor due diligence questions start, we can answer every one of the five above in writing, today.

What you should do now

Read your current IT agreement. Look for anything covering data handling, breach notification and subcontractors. Most managed services agreements written before 2024 say almost nothing on these points, and that tells you the size of the gap you would need to close.

Ask your provider the five questions above. Their answers, and how quickly they can produce evidence, tell you whether you have a processor problem before the law makes it official. Do this in writing so you have a record.

Get an independent view of your exposure. We offer a free IT assessment that covers where your data sits, who touches it and how your current provider’s security posture stacks up against the frameworks regulators expect.

Frequently asked questions

What are the proposed Privacy Act changes in 2026?

The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released on 31 August 2026, proposes around 40 changes to the Privacy Act, including a new fair and reasonable test for handling personal information and the introduction of controller and processor roles similar to the GDPR. The draft is open for consultation until 18 September 2026.

What is a controller and a processor under the Privacy Act?

Under the proposed Privacy Act controller and processor model, a controller is the organisation that decides why and how personal information is collected, typically the business that owns the customer relationship. A processor handles that information on the controller’s behalf, such as an IT provider, cloud platform or payroll service. Controllers would carry primary responsibility for their processors’ privacy breaches.

Is my business liable if my IT provider has a data breach?

Under the current Privacy Act, responsibility depends on the circumstances. Under the proposed controller and processor rules, a business acting as controller would be primarily responsible for breaches of the Australian Privacy Principles by its processors, including IT providers. That makes provider due diligence and a written data processing agreement far more important.

What is a data processing agreement (DPA)?

A DPA is a contract that sets out how a processor must handle personal information on a controller’s behalf, covering security measures, breach notification, subcontractors and data location. They are standard practice under the GDPR and would become common in Australia if the controller and processor reforms pass.

When would the Privacy Act changes take effect?

There is no fixed date. The bill is at exposure draft stage, with consultation closing 18 September 2026. It would then need to be finalised, introduced to Parliament and passed, with a transition period likely to follow. Businesses that start their provider due diligence now will be ahead of the deadline whenever it lands.

Not sure how exposed you are?

Our Perth-based, ISO 27001 certified team can map where your data sits, who handles it and how your provider’s security posture measures up. Book a free IT assessment today, or contact us on 1300 EPIC IT.

Book a Free Assessment

About the Author
Written by Greg Markowski, Founding Director of Epic IT, a CRN Fast50-recognised Microsoft Solutions Partner managing IT and cybersecurity for Perth businesses since 2003. Greg holds a Degree in Computer Science and a Diploma in Computer Systems Engineering from Edith Cowan University, and is ITIL certified.

Further Reading

Previous

Best AI Consulting Companies in Australia: Who Does What in 2026

Return to News
Back to News
Next

Best IT support companies in Brisbane: how to choose in 2026