What counts as a source
We cite primary and official sources only: the legislation registers (legislation.gov.au, legislation.govt.nz), the regulators (the OAIC and the Office of the Privacy Commissioner, Home Affairs, the Cyber and Infrastructure Security Centre, DPMC, the GCSB and the NCSC), and the standards and framework bodies (the ACSC, ISO/IEC, Standards Australia and Standards New Zealand). Law-firm articles, vendor pages and news are useful for orientation but are never the source a date or an obligation rests on.
VERIFIED and INFERRED
Every claim carries one of two labels, and we show it:
- VERIFIED — the statement is directly supported by the official source cited, in its own words. 1,335 of 1,629 claims are verified.
- INFERRED — the statement is a reasonable reading of sourced material, but the source does not state it in exactly those terms, or the timing is imprecise. 294 claims are inferred. We label these so you can weigh them, not hide them.
The same discipline applies to the 83 tracked regulatory changes: 82 are verified against a primary source, and where an exact date could not be confirmed on an official source we leave it out rather than estimate it.
How a fact gets onto the site
- Research against the official sources for that topic and jurisdiction.
- Re-check — each date and claim is opened again on the source it came from and confirmed before it is published.
- Independent re-check — the regulatory change data has additionally been re-checked against the primary and official sources by a separate review, with corrections applied (see the audit trail below).
- Correct in the open — when a source says something different, we change the record and note it here. Unverifiable items are dropped, not guessed.
Reviewed, versus changed
These are two different dates and we keep them apart. Reviewed is when we last checked a guide against its sources. Source last amended is when the underlying law or framework itself last moved. On every law and framework guide you will also find a What's changing timeline: the dated history of that instrument and any officially-scheduled next change, each entry linked to its official source. Where nothing is officially scheduled, we say so, rather than imply a change is coming.
Audit trail
A dated record of what has been researched, checked and corrected. Guides were reviewed between 2026-07-12 and 2026-07-13.
- 12 July 2026
Guide corpus researched and published
The 44 guides (22 Australian, 22 New Zealand) were built from 1,629 individually sourced claims across 440 questions. Every claim was labelled VERIFIED or INFERRED and linked to a source.
- 15 July 2026
Regulatory change tracking added
For every law and framework guide, dated change events (amendments, commencements, guidance updates and officially-scheduled future changes) were researched from official sources and each date re-checked against the source it came from before being included. 71 events across 17 guides.
- 15 July 2026
Independent source re-check of the change events
The change events were independently re-checked against the primary and official sources. The majority were confirmed as recorded; a number were corrected — mostly reclassifying a registration or compilation date to the date the law actually changed — and further sourced events were added. The change set now stands at 83 events across 18 guides, 82 verified against a primary source.
- 16 July 2026
Glossary published
64 security, privacy and compliance terms used across the guides defined in plain English — tagged Australia, New Zealand or both, with statutory terms linked to their official source and each term cross-linked to the guides that use it. Guide pages also link terms inline — dotted-underlined, first occurrence only — with a hover definition and a jump to the glossary.
- 16 July 2026
Articles section launched
Three launch articles published, every date and obligation drawn from the verified change events and cited to its official source: the two 10 December 2026 Privacy Act deadlines (AU), the Biometric Code transition ending 3 August 2026 (NZ), and the Cyber Security Act 2024 obligations now in force (AU).
This is a sourcing and verification process for educational guides and editable templates. It is not legal advice, it is not a professional or accredited compliance audit, and it is not a guarantee that any template makes you compliant. Your obligations depend on your industry, your contracts and your data. Have a qualified adviser review anything high stakes. See the full disclaimer.