IAPP ANZ Summit 2026
Privacy | AI governance | Cybersecurity law
Sydney
1-4 December
Cultivating Compliance: How Public Sector Agencies Weed Out Third-party Risks
Friday, 4 Dec.
15:00 - 16:00 AEDT
Intermediate level
Third-party providers are essential to public sector service delivery but are also where regulators often see privacy issues arise. Contracts without meaningful privacy protections, risk assessments that never get revisited, and oversight that stops at onboarding, are recurring themes in complaints, breach notifications and investigations. In this session, representatives from state and commonwealth privacy regulators share their perspectives on vendor-related privacy risk, with a focus on issues arising in public agencies. They will discuss common gaps that lead to regulatory trouble, what satisfies regulator’s expectations versus what falls short, and where their compliance and enforcement focus is heading.
What you will learn:
• Vendor management failures that most frequently surface in complaints and investigations.
• What regulators look for when assessing whether an agency met its privacy obligations.
• How to embed privacy requirements into procurement, use risk assessment, and review compliance in a way that helps avoid problems.
Moderator and speakers

Annan Boag
General Manager, Regulatory Action
Office of the Australian Information Commissioner

Nina Skewes
Privacy Deputy Commissioner
Office of the Information Commissioner, Western Australia

Alexander White
CIPP/A, CIPP/C, CIPP/E, CIPP/G, CIPP/US, CIPM, CIPT, FIP
Privacy Commissioner
Office of the Information Commissioner, Queensland