Australia
Outside the EEA. A customer here pulls on the regimes below by its sector; the rest are named and not quoted.
By customer sector
read on a SaaS subscription that names personal data| A bank | CPS 230, CPS 234, ISO 27001, ISO 27701expected on a SaaS subscription with personal data: CPS 230 terms, security schedule, audit right, breach clock |
|---|---|
| An insurer | CPS 230, CPS 234, ISO 27001, ISO 27701expected on a SaaS subscription with personal data: CPS 230 terms, security schedule, audit right, breach clock |
| A hospital or health system | ISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock |
| A retailer | ISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock |
| A government department | ISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock |
| A technology company | ISO 27001, ISO 27701expected on a SaaS subscription with personal data: security schedule, audit right, breach clock |
| Named, not quoted | the Australian Privacy Act and its notifiable data breaches scheme. |
Codes the register reads for this country: AU, Australia, sydney, melbourne, brisbane, perth, adelaide, canberra, ballarat.
The clauses, quoted
24Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
CPS 230 para 40 Mandatory Minimum Classification of Material Service ProvidersUnless it can justify otherwise the entity must classify as material service providers at least those supplying credit assessment, funding and liquidity management and mortgage brokerage for an ADI, underwriting, claims management, insurance brokerage and reinsurance for an insurer, fund administration, custodial services, investment management and arrangements with promoters a...
Where it usually falls short: Internal audit or risk management providers not classified as material
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 para 45 APRA Access Provisions in Formal AgreementsFormal agreements must also give APRA access to documentation, data and other information relating to the service, give APRA the right to conduct an on site visit to the provider, and secure the provider agreement not to impede APRA in performing its duties as prudential regulator.
Where it usually falls short: Legacy contracts never uplifted
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 para 50 Formal Agreement Content for Material ArrangementsEvery material arrangement must be covered by a formal legally binding agreement specifying the services and service levels, the rights, responsibilities and expectations of each party including asset ownership, data ownership and control, dispute resolution, audit access, liability and indemnity, provisions securing the entity legal and compliance obligations, notification of ...
Where it usually falls short: Verbal or intra group arrangements with no formal agreement
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P33 APRA Notification of Operational Risk Incidents within 72 HoursThe entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an operational risk incident it determines is likely to have a material financial impact or a material impact on its ability to maintain critical operations.
Where it usually falls short: Clock started at incident classification rather than awareness
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P42 APRA Notification of Disruption Outside Tolerance within 24 HoursThe entity must notify APRA as soon as possible and no later than 24 hours after suffering a disruption to a critical operation outside tolerance, covering the nature of the disruption, the action taken, the likely impact on business operations and the timeframe for returning to normal operations.
Where it usually falls short: Tolerance breach detected late so the 24 hour clock is missed
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P59 APRA Notification of Service Agreements and OffshoringThe entity must notify APRA as soon as possible and no more than 20 business days after entering into or materially changing an agreement for a service it relies on to undertake a critical operation, and must notify APRA before entering into any material offshoring arrangement or when a significant change to such an arrangement is proposed, including where data or personnel rel...
Where it usually falls short: Offshoring notified after signature instead of before
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 234 para 16 Assessment of Related Party and Third Party CapabilityWhere a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.
Where it usually falls short: Assessment limited to outsourced material business activities
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 27 Internal Audit Assessment of Third Party Control AssuranceInternal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.
Where it usually falls short: Third party assurance accepted without assessment
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 HoursAPRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 P22 Evaluation of Third Party Control DesignWhere a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.
Where it usually falls short: Reliance on a certificate with no design evaluation
APRA CPS 234 Information Security in The Art of Service standards library
ISO 27001 A.5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27701 A.2.2.2 Customer agreementWhere relevant, the contract to process personal data must address the organization's role in assisting the customer with the customer's own obligations, taking account of the nature of processing and the information available to it, covering as relevant privacy by design and by default, achieving security of processing, notifying breaches to a supervisory authority and to cust...
Where it usually falls short: Assistance promised in contract with no operational capability behind it, discovered only when the customer first asks
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.4.3 Return, transfer or disposal of PIIThe organization must provide the ability to return, transfer or dispose of personal data securely and must make its policy available to the customer, managing the capability securely whether the outcome is return to the customer, transfer to another organization or controller, deletion, destruction, de-identification or archiving, providing the assurance the customer needs tha...
Where it usually falls short: Erasure certified for primary systems while backups retain the data for the full backup cycle, which the customer is not told
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.7 Disclosure of subcontractors used to process PIIThe organization must disclose to the customer any use of subcontractors to process personal data before that use, with provisions included in the customer contract, disclosing that subcontracting is used and the names of the relevant subcontractors, the countries and international organizations to which they can transfer data, and the means by which they are obliged to meet or...
Where it usually falls short: Subcontractors disclosed only on request, with customers never told the information exists
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.8 Engagement of a subcontractor to process PIIThe organization must engage a subcontractor to process personal data only according to the customer contract, obtaining written authorization from the customer before the subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement, holding a written contract with every such subcontractor that addresses implemen...
Where it usually falls short: Subcontractor engaged on the strength of a general authorization that does not in fact cover it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.9 Change of subcontractor to process PIIWhere it holds a general written authorization, the organization must inform the customer of any intended change involving the addition or replacement of a subcontractor that processes personal data, giving the customer the opportunity to object, and where it changes the subcontractor carrying out some or all of the processing, written authorization from the customer is require...
Where it usually falls short: Notification given at the point of change or after, so the objection right is theoretical
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.10 Addressing information security within supplier agreementsAgreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII...
Where it usually falls short: Supplier contracts silent on PII while the supplier processes it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidentsFor a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notif...
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library
Read your customers in Australia
Paste the list; every agreement with a customer here is read against these regimes by its sector and its kind. Eight agreements free, no account.
Check my contract list