New South Wales · GIPA, PPIP and HRIP Acts

Run GIPA's public interest test as a documented decision

For NSW agencies, councils, and universities — AccessPoint runs formal access applications on the 20-working-day clock with the public interest test recorded, plus PPIP and HRIP privacy and the Part 6A mandatory data breach scheme.

Australia — New South Wales at a glance

Decision deadline
20 working days, extendable in the circumstances the GIPA Act allows
Application fee
$30 for a formal access application, with processing charges beyond the included hours
Test
The public interest test — a presumption of disclosure rebutted by overriding considerations against
Privacy
PPIP and HRIP, including the Part 6A mandatory data breach scheme
Review
Internal review, IPC review, or NCAT
Languages
English

Built for Australia — New South Wales

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

The public interest test, recorded

GIPA does not offer exemptions to claim — it requires a balancing of considerations for and against disclosure, with the presumption favouring release. AccessPoint captures the considerations relied on against each piece of information, which is exactly what an IPC review examines.

20 working days, tracked

Computed on receipt over the NSW public-holiday calendar, with extensions for consultation or retrieval recorded with their ground and any agreed variation.

Informal release, not just formal applications

GIPA expects agencies to release information informally where they can. Log informal releases alongside formal applications, so the agency's disclosure record reflects everything it actually released.

The Part 6A breach scheme

NSW made data breach notification mandatory for public sector agencies. Assess an eligible data breach, notify the Privacy Commissioner and affected individuals, and maintain the public notification register the scheme requires.

PPIP and HRIP together

Run internal reviews of privacy conduct under the PPIP Act and health privacy under HRIP on the same platform as your GIPA work, with one audit ledger across both.

In your own tenant

Information, applications, and audit history stay inside your own Microsoft 365 and Azure tenant — no third-party cloud and no vendor access.

A test, not a list

GIPA gives you no exemptions to hide behind — only a balance you have to show your working on.

New South Wales deliberately built its access law without a conventional exemption schedule. Instead there is a presumption in favour of disclosure, a table of considerations that may weigh against it, and a requirement that the decision-maker actually weigh them for the particular information in question. That design makes NSW decisions unusually dependent on documentation: the IPC and NCAT are not asking whether an exemption was available, they are asking whether the balancing was genuinely performed and reasonably explained. Agencies that record only a conclusion — the label of a consideration, with nothing behind it — lose reviews they might have won. AccessPoint makes the considerations for and against, and the reasoning that resolved them, a recorded part of the decision.

Both sides recorded Considerations for and against, per item of information.
Presumption respected Disclosure as the default the decision must displace.
Review-ready The reasoning an IPC or NCAT review reads.

Configured out of the box

Installing the au-nsw jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The GIPA Act as the legal-authority spine, with PPIP and HRIP alongside
  • The 20-working-day decision clock with NSW public holidays and the Act's extensions
  • A structured public interest test recording considerations for and against disclosure
  • The $30 application fee and processing charges, with the included hours applied first
  • Informal release logging alongside formal access applications
  • Internal review, IPC review, and NCAT tracking with grounds and outcomes
  • PPIP internal reviews and the Part 6A mandatory data breach scheme with its register
  • HRIP health privacy handling on the same platform

Australia — New South Wales Questions

How is GIPA different from other Australian access laws?

It has no conventional exemption schedule. NSW built the Act around a presumption in favour of disclosure that can only be displaced where the public interest considerations against release outweigh those in favour, assessed for the specific information. That makes the recorded reasoning the substance of the decision rather than a formality attached to it.

Does the pack cover the Part 6A data breach scheme?

Yes. The mandatory notification of data breaches scheme applies to NSW public sector agencies under the PPIP Act. AccessPoint runs the eligible-data-breach assessment, the notifications to the Privacy Commissioner and affected individuals, and the public notification register the scheme requires.

Can we track informal releases as well as formal applications?

Yes, and NSW agencies should. GIPA expects information to be released informally where it can be, and an agency that only records formal applications systematically understates what it discloses. AccessPoint logs both, so reporting reflects the agency's actual openness.

Where does the information reside?

Entirely within your own Microsoft 365 and Azure tenant, in the Australian region you choose. Applications, records, redactions, and audit history never leave your control — no third-party cloud and no cross-border data transfers.

Run the GIPA Act in Your Own Tenant

Try AccessPoint free for 30 days, configured for New South Wales. No credit card required.

Start Free Trial