VPDSS — Victorian Protective Data Security Standards

Victoria's mandatory protective data security standards, administered by OVIC. Twelve standards covering governance, information, personnel, ICT and physical security.

Office of the Victorian Information Commissioner (OVIC), under Part 4 of the Privacy and Data Protection Act 2014 (Vic).

What it is

The Victorian Protective Data Security Standards are the mandatory information security standards for the Victorian public sector. They are issued by the Office of the Victorian Information Commissioner under Part 4 of the Privacy and Data Protection Act 2014 (Vic), and the current edition is VPDSS V2.0.

The Standards sit inside the broader Victorian Protective Data Security Framework, which OVIC administers. There are 12 standards, each supported by a set of elements, spanning five security domains: governance, information security, personnel security, ICT security and physical security. Their stated purpose is to give Victorian government organisations a consistent, risk-based way of managing the security of public sector information.

Compliance runs on a cycle built around three artefacts:

  • An Information Asset Register — what public sector information the organisation holds and what it is worth protecting.
  • A Security Risk Profile Assessment (SRPA) — a risk assessment process across the security domains, not a document you fill in once.
  • A Protective Data Security Plan (PDSP) — submitted to OVIC every two years, signed by the public sector body Head.

This is not a certification scheme. There is no VPDSS certificate and no accredited certification body. It is a regulatory obligation assessed by OVIC, which is a materially different thing from an ISO standard and is worth understanding before anyone sells you a certificate against it.

Who it's for

Victorian public sector agencies and bodies

Organisations subject to Part 4 of the PDP Act must adhere to the Standards, undertake an SRPA, and develop, implement and maintain a PDSP. This covers departments, agencies, statutory authorities, Victoria Police, councils and a wide range of public bodies. For these organisations the obligation is legislative, not commercial.

Contracted service providers to Victorian government

This is the larger and less well understood group. The PDP Act requires an agency or body to ensure that its contracted service providers do not act in a way that contravenes a protective data security standard in respect of public sector information. In practice the obligation flows down through your contract.

If you are a software vendor, managed service provider, healthtech supplier, consultancy or any business handling Victorian public sector information, VPDSS reaches you — usually through a clause, and usually with an assurance request attached. Losing the contract for failing it is a live commercial risk.

What triggers the work

Most engagements start from one of three places: a PDSP submission deadline approaching, a significant change requiring an out-of-cycle submission, or an agency client asking a supplier to demonstrate alignment.

Why implement it

  • For agencies, it is the law. Adherence is a statutory obligation under the PDP Act, not a matter of judgement, and PDSP submission windows are firm — OVIC states it is unable to offer extensions.
  • For suppliers, it protects the contract. Where security obligations flow down from an agency client, failing to evidence them puts the engagement at risk. This is the most common commercial driver we see.
  • It opens Victorian government work. Demonstrable VPDSS alignment is a practical prerequisite for competing for departmental and agency contracts that involve public sector information.
  • It builds the asset register you needed anyway. Most organisations cannot produce a defensible list of what information they hold and what it is worth. The Information Asset Register forces that, and it pays off well beyond the Standards.
  • It reduces incident exposure. OVIC operates an incident notification scheme, and organisations must notify incidents at business impact level 2 (limited) or higher. Knowing your holdings and your risks in advance is what makes that manageable.

How implementation works

The VPDSS cycle is built around three artefacts — the Information Asset Register, the Security Risk Profile Assessment and the Protective Data Security Plan — and each depends on the one before it.

1. Build the Information Asset Register

Identify the public sector information the organisation creates, holds and manages, and assign each holding a security value based on the consequence of compromise. Everything downstream rests on this, and a register built carelessly produces a risk assessment nobody can defend.

2. Conduct the Security Risk Profile Assessment

The SRPA is a process, not a document you buy. It assesses security risks across the four domains — information, personnel, ICT and physical — against the organisation's internal and external context and the security value of its information. OVIC is explicit that this should be approached as risk management rather than as a compliance tick.

3. Implement the Standards and their elements

Close the gaps the SRPA identifies, proportionate to the organisation's size, resources and risk. Organisations operating Industrial Automation and Control Systems have additional elements to address.

4. Develop and submit the Protective Data Security Plan

The PDSP summarises capability and progress against the Standards. It is signed by the public sector body Head and submitted to OVIC on the biennial cycle. OVIC does not grant extensions, so the date is the date.

5. Attest in the intervening years

Each year that is not a submission year, organisations attest to the continuation of the security activities set out in their last PDSP.

6. Maintain, and watch for significant change

Section 89(4) of the PDP Act requires an out-of-cycle PDSP where the organisation has undergone, or expects to undergo, a significant change to its operating environment or security risks. Machinery-of-government changes and major restructures are the usual triggers.

How Soveriq helps

Soveriq delivers the full VPDSS workflow — Information Asset Register, SRPA across all four security domains, and a PDSP prepared to OVIC submission standard — with a prioritised remediation roadmap against the gaps found.

For contracted service providers, we work the other direction: establishing exactly which obligations flow to you under your agency contract, and building the evidence that satisfies them without over-building against standards that were never yours to meet.

Where an organisation holds or is pursuing ISO 27001, we map the existing ISMS across to the Standards rather than starting again, which is usually the cheapest path to a defensible PDSP.

On internal audit. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. What we provide is readiness validation, labelled as such. Where genuinely independent assessment is required after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.

What we will not do. Soveriq does not approve PDSPs, does not speak for OVIC, and does not promise an assessment outcome.

What the engagement looks like

VPDSS work maps onto Soveriq's five modules.

  • Module 01 — Gap analysis. Assessment against the 12 standards and their elements, producing a current-state picture and a prioritised roadmap.
  • Module 02 — Build. Information Asset Register, SRPA, security policies and the remediation work, constructed inside your own environment.
  • Module 03 — Internal audit. Independent assessment of implementation, subject to the impartiality position below.
  • Module 04 — Representation where OVIC or an assessor engages directly.
  • Module 05 — Continuous compliance. Register upkeep, annual Attestation support and preparation for the next PDSP cycle.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

A note on our current position. Soveriq is not yet a DISP member. For Victorian public sector bodies, our present route is advisory and readiness work; for contracted service providers, we work directly on the obligations flowing to you from your agency client. We would rather state that plainly than let you discover it during procurement.

Common questions

Does VPDSS apply to us as a contractor, or only to the agency?

It reaches you. The PDP Act requires the agency to ensure its contracted service providers do not act in a way that contravenes the Standards. The agency discharges that through your contract, so your obligations are real even though your name is not on the legislation.

How often do we submit a PDSP?

Every two years. The most recent VPS submission window ran from 1 July to 31 August 2026, with the next cycle falling in 2028. In the intervening years you submit an Attestation confirming that the security activities in your last PDSP continue. An out-of-cycle PDSP is required if you undergo a significant change to your operating environment or security risks.

We are certified to ISO 27001. Does that cover VPDSS?

Not automatically, but it does a great deal of the work. The governance, risk and control expectations overlap heavily, so a functioning ISMS typically satisfies a large share of the Standards. What it does not do is produce the specific VPDSS artefacts — the Information Asset Register, the SRPA and the PDSP itself — which have their own form and expectations.

When do we have to notify OVIC of an incident?

Where an incident has an adverse impact on the confidentiality, integrity or availability of public sector information with a business impact level of 2 (limited) or higher. This is separate from, and additional to, any obligation under the Commonwealth Notifiable Data Breaches scheme.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope