Image

What WA’s new privacy laws mean for injury management

What WA’s new privacy laws mean for injury management

What WA’s new privacy laws mean for injury management

Legislation

Western Australia now has its first general privacy law. The Privacy and Responsible Information Sharing Act 2024 (WA) - the PRIS Act - had its substantive privacy provisions commence on 1 July 2026, bringing WA into line with every other Australian jurisdiction.

The Act applies broadly across the WA public sector, including government departments, statutory authorities, local governments, universities, government trading enterprises, WA Police, courts and tribunals, and SES organisations.

For organisations managing workplace injuries or workers' compensation claims, this is more than a compliance update. It changes who is accountable, what information is in scope, and how AI can be used in decision-making.


Three things that matter when procuring injury management software:

Your vendor may be directly accountable under the Act.

Under Part 2 Division 11 of the Act, where a State services contract applies the PRIS Act to a supplier, that supplier becomes an IPP entity in its own right - directly exposed to enforcement, rather than only contractually accountable to the agency.

These obligations also flow down to subcontractors. Choosing a vendor that cannot meet the Information Privacy Principles may therefore create a compliance exposure for the agency, rather than simply being a procurement consideration.

There's no employee records exemption.

Unlike the Commonwealth Privacy Act, the PRIS Act does not carve out employee records. Injured worker information held for workers' compensation purposes is in scope, meaning the same privacy standards that protect the public also apply to your own people.

Automated decision-making is regulated - a first in Australia.

IPP 10 applies where a system uses personal information collected on or after 1 July 2026 to help make a significant decision. This includes a recommendation, assessment, conclusion or inference that materially assists a human decision-maker - not only fully automated outcomes.

Where IPP 10 applies, the entity must complete an ADM impact assessment, be transparent with the individual, and provide a pathway for human review.

There are also two important upcoming dates: WA's mandatory information breach notification scheme commences on 1 January 2027, while the Commonwealth's ADM transparency obligations (APP 1.7–1.9) commence on 10 December 2026.


How Safer supports the new requirements


Requirement
SAFER’s position

Australian data residency

All customer data and AI inference remain in Australia. Application and database infrastructure run in Sydney, while AI processing uses AWS Bedrock in the Sydney region via the au. inference profile, which constrains inference to Australian regions.

No model training on your data

Customer data is not used to train or fine-tune foundation models. Model isolation is the default, with no cross-client data pooling.

ADM transparency (IPP 10)

Safer can provide an ADM register documenting each function of Elara, our embedded AI assistant - including what personal information it uses, whether it makes or materially assists a decision, and the human review pathway. Every Elara output is advisory: a person makes the decision.

Security (IPP 4 / APP 11)

ISO 27001 aligned controls, encryption in transit and at rest, role-based access, tenant isolation and audit logging. Certification via Vanta is in progress.

Collection and use limits

Data is handled only to deliver the service and in accordance with your documented instructions. Purpose limitation, sub-processor disclosure and audit rights are set out in our subscription terms.

Breach response

Safer has a defined notification process and will notify you within 2 business days of a confirmed incident, helping you meet your own statutory timeframes under the Commonwealth NDB scheme and, from 1 January 2027, the WA IBN scheme.

Access and correction

User access is supported through the platform with a full audit trail. Data corrections can be made to all data items also with a full audit trail.


Best practice we recommend to every client

Complete a Privacy Impact Assessment for your injury management function before go-live. We provide data flow diagrams, our sub-processor list and a residency statement to support this process.

  • Include a PRIS compliance clause in the contract. We have a standard WA addendum ready.

  • Register your ADM use. Our ADM register for Elara is designed to support your own register without duplicating the work.

  • Set retention rules deliberately for each record class, rather than relying on a single default.

  • Rehearse your breach response process with Safer included before 1 January 2027.

  • Collect consent appropriately at claim lodgment, using the statutory certificate and claim form authorisations, and keep secondary use within those bounds.

The new privacy requirements introduce additional considerations for injury management teams, particularly around data handling, vendor accountability and the use of AI.

Safer has been designed with these requirements in mind: clear controls, transparent AI and human decision-making remain central to how the platform operates.

Have questions about the PRIS Act or how Safer supports your privacy requirements? Contact our team at hello@safer.app

Injury management insights,
direct to your inbox

Thought leadership for injury management professionals navigating the future of return to work, claims and AI-powered case management.

Injury management insights,
direct to your inbox

Thought leadership for injury management professionals navigating the future of return to work, claims and AI-powered case management.

Injury management insights,
direct to your inbox

Thought leadership for injury management professionals navigating the future of return to work, claims and AI-powered case management.