Insights · Compliance

Data governance in Melbourne.

Melbourne organisations sit under two data regimes, not one. Most governance frameworks are written for the federal layer and quietly miss the Victorian one.

What data governance means in Melbourne.

Data governance in Melbourne is the practice of assigning accountable ownership, quality standards and access controls to an organisation's data under two overlapping legal regimes rather than one. Federal law applies to most private-sector organisations through the Privacy Act 1988 (Cth), its Australian Privacy Principles and the Notifiable Data Breaches scheme, regulated by the Office of the Australian Information Commissioner. Victorian law adds a second layer: the Privacy and Data Protection Act 2014 (Vic), regulated by the Office of the Victorian Information Commissioner (OVIC), and the Victorian Protective Data Security Standards (VPDSS) that OVIC issues under it. Health information held in Victoria is governed separately again, under the Health Records Act 2001 (Vic).

That is the whole distinction, and it is why a governance model lifted from a generic framework tends not to survive contact with a Melbourne organisation. It maps to the layer everyone knows about and leaves the state layer as an appendix.

The Victorian layer, and who it actually reaches.

The VPDSS bind the Victorian public sector directly. Departments, agencies, statutory bodies, universities and councils are in scope by law. Private organisations are not, and a lot of Melbourne businesses stop reading there.

They should not. The Victorian layer reaches the private sector contractually. If your organisation handles Victorian public sector information as a supplier, contracted service provider or subcontractor, the contract typically passes the obligation down to you. For a Melbourne consultancy, health provider, education supplier, infrastructure contractor or SaaS vendor selling into state government, this is not a theoretical exposure. It is a clause you have already signed, or one you will be asked to sign at the next tender.

The practical consequence is that "we comply with the Privacy Act" is not a sufficient answer to a Victorian government procurement question. The question being asked is whether you can evidence controls aligned to a specific state standard, on specific information, held in specific systems, with named owners. Most organisations can produce the policy. Far fewer can produce the evidence.

Financial services adds a third regime.

Melbourne's banking, insurance and superannuation sector carries a further layer again. APRA's CPS 234 sets information security requirements, and CPS 230 extends the expectation into operational risk management and service provider oversight, with tolerance levels for disruption to critical operations. Both are supervisory standards rather than privacy law, and both change what "evidence" means: not a control description but a demonstrable, continuous signal that the control operates.

We have written about that shift in detail in asserted vs observed compliance, and about the consultant market it has created in CPS 230 and AI: which consultant do you actually need. The short version is that a governance model built to satisfy an auditor once a year does not satisfy a supervisor asking what your position was last Tuesday.

Why AI raises the stakes on all three.

Ungoverned data has always been expensive. AI makes it expensive faster. A model trained on data with no owner, no lineage and no quality standard inherits every defect in that data and scales it across every decision the model touches. Worse, it launders the defect: the output arrives with the confidence of a system, and the provenance that would let someone challenge it has been dissolved into weights.

This is the single most common failure pattern we see in Melbourne engagements. The organisation has an AI ambition, a capable engineering team and a data estate nobody owns. The pilot works. The production system cannot be defended to a regulator, a board, or a customer who asks why a decision went the way it did. Governance is not the brake on that programme. It is the thing that lets it leave the lab.

A governance operating model that holds.

The framework-first approach fails predictably: twelve months of policy writing, a committee, a data catalogue nobody populates, and no change to how anyone works. The domain-first approach works because it produces evidence early.

01

Pick one domain

One critical data domain — customer, claims, student, patient, asset. Not the enterprise. One.

02

Map it end to end

Source systems, pipelines, datasets, consumers. Where it lives, where it moves, who touches it.

03

Name the owner

A person, not a committee. Accountable for quality and access decisions in that domain.

04

Map the jurisdiction

Which regime applies to this domain: federal, Victorian, health, prudential, or several at once.

05

Instrument it

Turn the rules into monitored checks so compliance emits a live signal instead of an annual assertion.

Step five is the one most programmes skip, and it is the one that changes the conversation with a board or a supervisor. A governed domain that produces a timestamped signal history is an artefact. A governance framework is a document. Only one of them answers the question actually being asked.

What good looks like after ninety days.

A realistic ninety-day outcome for a mid-size Melbourne organisation is not an enterprise data governance capability. It is one domain with a named owner, a documented lineage, an agreed quality standard, an access model that matches the applicable regime, and monitoring that fires when any of those slip. That is a small footprint and a complete pattern, and the pattern is what scales to the next domain.

This is the model behind our data governance consulting and AI and data governance work, and it is how our Data Foundation engagement is structured. If the driver is regulatory rather than analytical, the regulatory compliance and observed compliance pages are the better starting point. The Melbourne AI consulting page has the local detail.

Common questions.

Do private Melbourne businesses have to comply with the VPDSS?

Not directly — the standards bind Victorian public sector organisations. But if you handle Victorian public sector information under contract, your agreement will generally require equivalent controls, and you will be asked to evidence them at tender.

Who regulates data governance in Victoria?

OVIC for Victorian public sector privacy and data security, the OAIC for the federal Privacy Act, the Health Complaints Commissioner for Victorian health privacy, and APRA for prudentially regulated financial services.

How is data governance different from data management?

Management is the work of moving and serving data. Governance is the accountability structure that decides who may do that work, to what standard, and who answers when the standard is missed. Governance without management is a policy library. Management without governance is a platform nobody trusts.

TL;DR: data governance in Melbourne answers to federal privacy law, the Victorian regime administered by OVIC, and — in financial services — APRA's prudential standards. Frameworks written for the federal layer alone leave the state layer as an appendix, and that appendix is what Victorian government procurement asks about. Start with one domain, name an owner, map the applicable regime, and instrument the rules so compliance produces a live signal.

If you want a fast read on where your organisation sits before committing to any of this, the free AI readiness check takes a few minutes and covers the data foundation questions first.

General information only, not legal or regulatory advice. Current as at August 2026.