IAPP ANZ Summit 2026

Privacy | AI governance | Cybersecurity law

Sydney

1-4 December

Back to conference agenda

Same Data, Different Duties: Controller and Processor Models Compared

Friday, 4 Dec.

11:15 - 12:15 AEDT

Intermediate level

BREAKOUT SESSIONPRIVACYLAW AND REGULATIONPROGRAM MANAGEMENTRISK MANAGEMENTSTRATEGY AND GOVERNANCEFINANCE AND BANKINGGOVERNMENTHEALTH CARELEGALPROFESSIONAL SERVICESTECHNOLOGY

This panel will explore the practical and legal distinctions between data controllers and data processors, comparing the European/GDPR and Asian approaches with positions in Aotearoa New Zealand and Australia. Under the GDPR, controllers bear primary accountability and must impose prescriptive contractual requirements on processors. New Zealand and many Asian regimes acknowledge a similar distinction, but with less prescriptive obligations, particularly on processors. Australia does not currently adopt a controller–processor distinction under the Privacy Act 1988, although reform proposals signaled an intention to introduce a more GDPR-like allocation of responsibilities. We will examine how these legislative differences affect risk allocation, vendor due diligence and liability exposure.

What you will learn:

• Different approaches in Australia, New Zealand, Asia and Europe.

• Where accountability sits in outsourced arrangements.

• Appropriate governance and oversight structures to manage the risks.

Moderator and speakers

headshot of Frith Tweedie

Frith Tweedie

AIGP

Partner

Simply Privacy

headshot of Kate Colleary

Kate Colleary

CIPP/E, CIPM, FIP

Country Leader, Ireland, IAPP; Director

Pembroke Privacy

headshot of Anna Gamvros

Anna Gamvros

CIPP/A, CIPT, FIP

Partner, Privacy and Cybersecurity Lead, Asia-Pacific

A&O Shearman

headshot of Claire Knight-Whiting

Claire Knight-Whiting

AIGP, CIPP/E

General Manager Legal, Data, Privacy and AI Governance

Xero