Skip to content
Legislation
Esc
navigateopen⌘Jpreview

Legislation · public publication pilot

Cross-references

Cyber Security Act 2024 · Version 2024-11-29

Recorded references and their resolved targets. Relationships may extend outside the selected reading scope; this is not an exhaustive legal dependency analysis.

284 records · Page 4 of 12 · No records are omitted from this paginated view.

subsection (4)

Read 26-application-of-this-part.md Read 26-application-of-this-part.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (4)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/26-application-of-this-part.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/26-application-of-this-part.md",
  "sourceHeadingText": "26 Application of this Part",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "26 Application of this Part"
  ],
  "sourceLineNumber": 31,
  "sourceLineText": "- (5) However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:",
  "sourceMatchText": "subsection (4)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "26-application-of-this-part"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/26-application-of-this-part.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/26-application-of-this-part.md",
  "targetHeadingText": "26 Application of this Part",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "26 Application of this Part"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (4)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "26",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "26-application-of-this-part"
  ],
  "targetSubordinatePath": [
    "(4)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 8

Read 27-obligation-to-report-following-a-ransomware-payment.md Read 8-definitions.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 8",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "sourceHeadingText": "27 Obligation to report following a ransomware payment",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "27 Obligation to report following a ransomware payment"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "Note: For the definition of ***designated Commonwealth body***: see section 8.",
  "sourceMatchText": "section 8",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "27-obligation-to-report-following-a-ransomware-payment"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-1-preliminary/8-definitions.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-1-preliminary/8-definitions.md",
  "targetHeadingText": "8 Definitions",
  "targetHeadingTrail": [
    "Part 1—Preliminary",
    "8 Definitions"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 8",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "8",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-1-preliminary",
    "8-definitions"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 27-obligation-to-report-following-a-ransomware-payment.md Read 27-obligation-to-report-following-a-ransomware-payment.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "sourceHeadingText": "27 Obligation to report following a ransomware payment",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "27 Obligation to report following a ransomware payment"
  ],
  "sourceLineNumber": 18,
  "sourceLineText": "- (5) An entity is liable to a civil penalty if the entity contravenes subsection (1).",
  "sourceMatchText": "subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "27-obligation-to-report-following-a-ransomware-payment"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetHeadingText": "27 Obligation to report following a ransomware payment",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "27 Obligation to report following a ransomware payment"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "27",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "27-obligation-to-report-following-a-ransomware-payment"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 27

Read 28-liability.md Read 27-obligation-to-report-following-a-ransomware-payment.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 27",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceHeadingText": "28 Liability",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "28 Liability"
  ],
  "sourceLineNumber": 3,
  "sourceLineText": "- (1) An entity is not liable to an action or other proceeding for damages for or in relation to an act done or omitted in good faith in compliance with section 27.",
  "sourceMatchText": "section 27",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "28-liability"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetHeadingText": "27 Obligation to report following a ransomware payment",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "27 Obligation to report following a ransomware payment"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 27",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "27",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "27-obligation-to-report-following-a-ransomware-payment"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 28-liability.md Read 28-liability.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceHeadingText": "28 Liability",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "28 Liability"
  ],
  "sourceLineNumber": 4,
  "sourceLineText": "- (2) An officer, employee or agent of an entity is not liable to an action for damages for or in relation to an act done or omitted in good faith in connection with an act done or omitted by the entity as mentioned in subsection (1).",
  "sourceMatchText": "subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "28-liability"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "targetHeadingText": "28 Liability",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "28 Liability"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "28",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "28-liability"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 28-liability.md Read 28-liability.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "sourceHeadingText": "28 Liability",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "28 Liability"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "- (3) An entity that wishes to rely on subsection (1) in relation to an action or other proceeding bears an evidential burden (within the meaning of the Regulatory Powers Act) in relation to that matter.",
  "sourceMatchText": "subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "28-liability"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/28-liability.md",
  "targetHeadingText": "28 Liability",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "28 Liability"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "28",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "28-liability"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

Part 6

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Related container or target: cyber-security-act-2024/part-6-regulatory-powers

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "Part 6",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 7,
  "sourceLineText": "- (b) performing functions or exercising powers under this Part or Part 6 as it applies to this Part;",
  "sourceMatchText": "Part 6",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "structural-container",
  "targetArtifactRelativePath": "part-6-regulatory-powers",
  "targetCanonicalPath": "cyber-security-act-2024/part-6-regulatory-powers",
  "targetHeadingText": "Part 6—Regulatory powers",
  "targetHeadingTrail": [
    "Part 6—Regulatory powers"
  ],
  "targetKind": "part",
  "targetLocatorText": "Part 6",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "6",
  "targetRootKind": "part",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-6-regulatory-powers"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

Part 4

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Related container or target: cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "Part 4",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 12,
  "sourceLineText": "- (g) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to a cyber security incident;",
  "sourceMatchText": "Part 4",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "structural-container",
  "targetArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents",
  "targetCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents",
  "targetHeadingText": "Part 4—Coordination of significant cyber security incidents",
  "targetHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents"
  ],
  "targetKind": "part",
  "targetLocatorText": "Part 4",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "4",
  "targetRootKind": "part",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 11

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Read 11-disclosure-to-state-body.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 11",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 16,
  "sourceLineText": "Note: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.",
  "sourceMatchText": "section 11",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-1-preliminary/11-disclosure-to-state-body.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-1-preliminary/11-disclosure-to-state-body.md",
  "targetHeadingText": "11 Disclosure to State body",
  "targetHeadingTrail": [
    "Part 1—Preliminary",
    "11 Disclosure to State body"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 11",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "11",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-1-preliminary",
    "11-disclosure-to-state-body"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 32

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Read 32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 32",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 24,
  "sourceLineText": "Note: See also section 32 in relation to admissibility of the information in proceedings against the reporting business entity.",
  "sourceMatchText": "section 32",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "targetHeadingText": "32 Admissibility of information in ransomware payment report against reporting business entity",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "32 Admissibility of information in ransomware payment report against reporting business entity"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 32",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "32",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 28,
  "sourceLineText": "- (3) Subsection (1) does not authorise the designated Commonwealth body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the *Privacy Act 1988*.",
  "sourceMatchText": "Subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "29",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "sourceHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "sourceLineNumber": 32,
  "sourceLineText": "- (4) Subsection (1) does not prohibit the recording, use or disclosure of the following information:",
  "sourceMatchText": "Subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "29",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection 29(1)

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection 29(1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "- (b) has been obtained by another entity, Commonwealth body or State body under subsection 29(1) or this section; and",
  "sourceMatchText": "subsection 29(1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection 29(1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "29",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

Part 6

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Related container or target: cyber-security-act-2024/part-6-regulatory-powers

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "Part 6",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 14,
  "sourceLineText": "- (b) performing functions or exercising powers under this Part or Part 6 as it applies to this Part;",
  "sourceMatchText": "Part 6",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "structural-container",
  "targetArtifactRelativePath": "part-6-regulatory-powers",
  "targetCanonicalPath": "cyber-security-act-2024/part-6-regulatory-powers",
  "targetHeadingText": "Part 6—Regulatory powers",
  "targetHeadingTrail": [
    "Part 6—Regulatory powers"
  ],
  "targetKind": "part",
  "targetLocatorText": "Part 6",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "6",
  "targetRootKind": "part",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-6-regulatory-powers"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

Part 4

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Related container or target: cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "Part 4",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 19,
  "sourceLineText": "- (g) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to a cyber security incident;",
  "sourceMatchText": "Part 4",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "structural-container",
  "targetArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents",
  "targetCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents",
  "targetHeadingText": "Part 4—Coordination of significant cyber security incidents",
  "targetHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents"
  ],
  "targetKind": "part",
  "targetLocatorText": "Part 4",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "4",
  "targetRootKind": "part",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (2)

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (2)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 31,
  "sourceLineText": "- (4) Subsection (2) does not authorise the other entity, Commonwealth body or State body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the *Privacy Act 1988*.",
  "sourceMatchText": "Subsection (2)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (2)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "30",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "targetSubordinatePath": [
    "(2)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (2)

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (2)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 35,
  "sourceLineText": "- (5) Subsection (2) does not prohibit:",
  "sourceMatchText": "Subsection (2)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (2)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "30",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "targetSubordinatePath": [
    "(2)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection 29(4)

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection 29(4)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 36,
  "sourceLineText": "- (a) recording, use or disclosure of information referred to in subsection 29(4); or",
  "sourceMatchText": "subsection 29(4)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection 29(4)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "29",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "targetSubordinatePath": [
    "(4)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (2)

Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (2)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "sourceHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "sourceLineNumber": 44,
  "sourceLineText": "- (a) the entity contravenes subsection (2); and",
  "sourceMatchText": "subsection (2)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (2)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "30",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "targetSubordinatePath": [
    "(2)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection (1)

Read 31-legal-professional-privilege.md Read 31-legal-professional-privilege.md

Record fields
{
  "confidence": "contextual",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection (1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/31-legal-professional-privilege.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/31-legal-professional-privilege.md",
  "sourceHeadingText": "31 Legal professional privilege",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "31 Legal professional privilege"
  ],
  "sourceLineNumber": 6,
  "sourceLineText": "- (2) Despite subsection (1), this section does not apply to the following:",
  "sourceMatchText": "subsection (1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "31-legal-professional-privilege"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/31-legal-professional-privilege.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/31-legal-professional-privilege.md",
  "targetHeadingText": "31 Legal professional privilege",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "31 Legal professional privilege"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection (1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "31",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "31-legal-professional-privilege"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 27

Read 32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md Read 27-obligation-to-report-following-a-ransomware-payment.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 27",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceHeadingText": "32 Admissibility of information in ransomware payment report against reporting business entity",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "32 Admissibility of information in ransomware payment report against reporting business entity"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "- (b) has been obtained by a Commonwealth body or State body under section 27, subsection 29(1) or section 30; and",
  "sourceMatchText": "section 27",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-2-reporting-obligations/27-obligation-to-report-following-a-ransomware-payment.md",
  "targetHeadingText": "27 Obligation to report following a ransomware payment",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 2—Reporting obligations",
    "27 Obligation to report following a ransomware payment"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 27",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "27",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-2-reporting-obligations",
    "27-obligation-to-report-following-a-ransomware-payment"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

subsection 29(1)

Read 32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md Read 29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "subsection 29(1)",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceHeadingText": "32 Admissibility of information in ransomware payment report against reporting business entity",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "32 Admissibility of information in ransomware payment report against reporting business entity"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "- (b) has been obtained by a Commonwealth body or State body under section 27, subsection 29(1) or section 30; and",
  "sourceMatchText": "subsection 29(1)",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes.md",
  "targetHeadingText": "29 Ransomware payment reports may only be used or disclosed for permitted purposes",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "29 Ransomware payment reports may only be used or disclosed for permitted purposes"
  ],
  "targetKind": "subsection",
  "targetLocatorText": "subsection 29(1)",
  "targetResolutionKind": "intra-artifact",
  "targetRootIdentifier": "29",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "29-ransomware-payment-reports-may-only-be-used-or-disclosed-for-permitted-purposes"
  ],
  "targetSubordinatePath": [
    "(1)"
  ],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 30

Read 32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md Read 30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 30",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity.md",
  "sourceHeadingText": "32 Admissibility of information in ransomware payment report against reporting business entity",
  "sourceHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "32 Admissibility of information in ransomware payment report against reporting business entity"
  ],
  "sourceLineNumber": 5,
  "sourceLineText": "- (b) has been obtained by a Commonwealth body or State body under section 27, subsection 29(1) or section 30; and",
  "sourceMatchText": "section 30",
  "sourceStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "32-admissibility-of-information-in-ransomware-payment-report-against-reporting-business-entity"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-3-ransomware-reporting-obligations/division-3-protection-of-information/30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports.md",
  "targetHeadingText": "30 Limitations on secondary use and disclosure of information in ransomware payment reports",
  "targetHeadingTrail": [
    "Part 3—Ransomware reporting obligations",
    "Division 3—Protection of information",
    "30 Limitations on secondary use and disclosure of information in ransomware payment reports"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 30",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "30",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-3-ransomware-reporting-obligations",
    "division-3-protection-of-information",
    "30-limitations-on-secondary-use-and-disclosure-of-information-in-ransomware-payment-reports"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 36

Read 35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md Read 36-voluntary-provision-of-information-in-relation-to-other-incidents-or-cyber-security-incidents.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 36",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md",
  "sourceHeadingText": "35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident",
  "sourceHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents",
    "Division 2—Voluntary information sharing with the National Cyber Security Coordinator",
    "35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident"
  ],
  "sourceLineNumber": 14,
  "sourceLineText": "Note 1: For information provided in relation to other kinds of cyber security incidents: see sections 36 and 39.",
  "sourceMatchText": "sections 36 and 39",
  "sourceStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents",
    "division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator",
    "35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/36-voluntary-provision-of-information-in-relation-to-other-incidents-or-cyber-security-incidents.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/36-voluntary-provision-of-information-in-relation-to-other-incidents-or-cyber-security-incidents.md",
  "targetHeadingText": "36 Voluntary provision of information in relation to other incidents or cyber security incidents",
  "targetHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents",
    "Division 2—Voluntary information sharing with the National Cyber Security Coordinator",
    "36 Voluntary provision of information in relation to other incidents or cyber security incidents"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 36",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "36",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents",
    "division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator",
    "36-voluntary-provision-of-information-in-relation-to-other-incidents-or-cyber-security-incidents"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

section 39

Read 35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md Read 39-information-provided-in-relation-to-other-incidents-use-and-disclosure-by-national-cyber-security-coordinator.md

Record fields
{
  "confidence": "exact",
  "name": "Cyber Security Act 2024",
  "referenceText": "section 39",
  "schemaVersion": "1.0.0",
  "slug": "cyber-security-act-2024",
  "sourceArtifactKind": "file",
  "sourceArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md",
  "sourceCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents/division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator/35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident.md",
  "sourceHeadingText": "35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident",
  "sourceHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents",
    "Division 2—Voluntary information sharing with the National Cyber Security Coordinator",
    "35 Impacted entity may voluntarily provide information to National Cyber Security Coordinator in relation to a significant cyber security incident"
  ],
  "sourceLineNumber": 14,
  "sourceLineText": "Note 1: For information provided in relation to other kinds of cyber security incidents: see sections 36 and 39.",
  "sourceMatchText": "sections 36 and 39",
  "sourceStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents",
    "division-2-voluntary-information-sharing-with-the-national-cyber-security-coordinator",
    "35-impacted-entity-may-voluntarily-provide-information-to-national-cyber-security-coordinator-in-relation-to-a-significant-cyber-security-incident"
  ],
  "sourceTextUrl": "https://www.legislation.gov.au/C2024A00098/latest/text",
  "targetArtifactKind": "file",
  "targetArtifactRelativePath": "part-4-coordination-of-significant-cyber-security-incidents/division-3-protection-of-information/39-information-provided-in-relation-to-other-incidents-use-and-disclosure-by-national-cyber-security-coordinator.md",
  "targetCanonicalPath": "cyber-security-act-2024/part-4-coordination-of-significant-cyber-security-incidents/division-3-protection-of-information/39-information-provided-in-relation-to-other-incidents-use-and-disclosure-by-national-cyber-security-coordinator.md",
  "targetHeadingText": "39 Information provided in relation to other incidents—use and disclosure by National Cyber Security Coordinator",
  "targetHeadingTrail": [
    "Part 4—Coordination of significant cyber security incidents",
    "Division 3—Protection of information",
    "39 Information provided in relation to other incidents—use and disclosure by National Cyber Security Coordinator"
  ],
  "targetKind": "section",
  "targetLocatorText": "section 39",
  "targetResolutionKind": "artifact",
  "targetRootIdentifier": "39",
  "targetRootKind": "section",
  "targetScope": "intra-document",
  "targetStructuralPath": [
    "part-4-coordination-of-significant-cyber-security-incidents",
    "division-3-protection-of-information",
    "39-information-provided-in-relation-to-other-incidents-use-and-disclosure-by-national-cyber-security-coordinator"
  ],
  "targetSubordinatePath": [],
  "titleId": "C2024A00098",
  "versionDate": "2024-11-29"
}

a6de85cccf489b7b121dcec0cddf38c459fff4af3f64d1bc4fde69b4753ec0c5