Queensland · RTI Act 2009 and IP Act 2009

Queensland's push model, run the way the Act intends

For Queensland departments, councils, universities, and hospital and health services — AccessPoint runs RTI applications on the 25-business-day clock, IP Act privacy under the QPPs, and the Chapter 3A mandatory data breach scheme.

Australia — Queensland at a glance

Decision deadline
25 business days, extendable where the Act allows
Model
Push model — administrative access first, formal application as a last resort
Application fee
The statutory RTI application fee; personal-information applications under the IP Act are free
Breach scheme
Chapter 3A, reaching local government from 1 July 2026
Review
Internal review, OIC external review, then QCAT
Languages
English

Built for Australia — Queensland

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

25 business days

Computed on receipt over the Queensland public-holiday calendar, with processing-period extensions and any agreed variation recorded on the file.

The push model, supported properly

Queensland intends most information to be released administratively, with a formal RTI application as the last resort. Log administrative releases alongside formal applications so the agency's real disclosure record is visible.

Chapter 3A data breaches

Run the mandatory notification scheme — the eligible-breach assessment, notification to the Information Commissioner and affected individuals, and the register — with local government coming into scope on 1 July 2026.

Two access paths, correctly separated

An application for your own personal information runs under the IP Act; everything else runs under the RTI Act. The pack keeps the fee, the scope, and the vocabulary right for each rather than treating them as one queue.

External review to the OIC

Track internal review, OIC external review, and QCAT appeals with their filing windows, correspondence, and outcomes linked to the originating application.

In your own tenant

Documents, applications, and audit history stay inside your own Microsoft 365 and Azure tenant — no third-party cloud and no vendor access.

1 July 2026

Queensland councils are about to acquire a breach-notification duty they have never had.

Chapter 3A of the IP Act brought mandatory data breach notification to Queensland state agencies, and it extends to local government from 1 July 2026. For a council that has run privacy as an occasional policy question, that is a genuine operational change: an eligible data breach must be assessed against a defined threshold within a defined period, the Information Commissioner and affected individuals must be notified, and a register must be maintained and, in part, published. None of that survives being handled by email. The work is not large in volume, but it is time-bound and evidentiary — exactly the shape that goes wrong without a system. Councils putting RTI on a platform this year should bring the breach scheme onto the same one, because the deadline is fixed and it is close.

A fixed date Local government in scope from 1 July 2026.
Assessed, not debated The eligible-breach test run against a threshold.
A register that exists Maintained as work happens, not assembled later.

Configured out of the box

Installing the au-qld jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The RTI Act 2009 and IP Act 2009 as the legal-authority spine
  • The 25-business-day processing period with Queensland public holidays and the Act's extensions
  • Separate RTI and IP Act access paths with the correct fees, scope, and vocabulary for each
  • Administrative-access logging to support the push model
  • The RTI Act exemptions and public interest factors, colour-coded for redaction
  • Internal review, OIC external review, and QCAT tracking
  • The Chapter 3A mandatory data breach scheme with assessment, notification, and register
  • The Queensland Privacy Principles and privacy complaint handling

Australia — Queensland Questions

What is the Queensland RTI deadline?

25 business days from receipt of a compliant application, with extensions available where the Act allows, including by agreement with the applicant and for third-party consultation. AccessPoint computes the processing period over the Queensland public-holiday calendar and records extensions with their ground.

When does the data breach scheme apply to councils?

Chapter 3A of the IP Act extends the mandatory notification of data breaches scheme to Queensland local government from 1 July 2026. AccessPoint ships the eligible-breach assessment, the notifications to the Information Commissioner and affected individuals, and the register the scheme requires.

How do RTI and IP Act applications differ?

An application for access to your own personal information is made under the IP Act and is free; other applications for government information are made under the RTI Act and attract the statutory application fee. The scope and vocabulary differ too, so AccessPoint runs them as distinct request types rather than one generic queue.

Where do documents reside?

Entirely within your own Microsoft 365 and Azure tenant, in the Australian region you choose. Applications, documents, redactions, and audit history never leave your control — no third-party cloud and no cross-border data transfers.

Run Queensland RTI in Your Own Tenant

Try AccessPoint free for 30 days, configured for Queensland. No credit card required.

Start Free Trial