Part 4—Coordination of significant cyber security incidents
Read this container onlyDivision 3—Protection of information
Read this container only38 Information provided in relation to a significant cyber security incident—use and disclosure by National Cyber Security Coordinator
Permitted use and disclosure
- (1) The National Cyber Security Coordinator may make a record of, use or disclose information provided under subsection 35(2) by, or on behalf of, an entity (the impacted entity) in relation to a cyber security incident but only for the purposes of one or more of the following:
- (a) assisting the impacted entity, and other entities acting on behalf of the impacted entity, to respond to, mitigate or resolve the cyber security incident;
- (b) a permitted cyber security purpose for a cyber security incident.
Note 1: For permitted cyber security purpose for a cyber security incident: see section 10. This includes the functions of the National Cyber Security Coordinator under this Part.
Note 2: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.
Restriction on use and disclosure for civil or regulatory action
- (2) However, the National Cyber Security Coordinator must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the impacted entity of a Commonwealth, State or Territory law other than:
- (a) a contravention by the impacted entity of this Part; or
- (b) a contravention by the impacted entity of a law that imposes a penalty or sanction for a criminal offence.
Note: See also section 42 in relation to admissibility of the information in proceedings against the impacted entity.
Interaction with the Privacy Act 1988
- (3) Subsection (1) does not authorise the National Cyber Security Coordinator to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.
Information not covered by the prohibitions in this section
- (4) Subsection (1) does not prohibit the recording, use or disclosure of the following information:
- (a) information that has been provided by, or on behalf of, the impacted entity to the Commonwealth about the cyber security incident to comply with:
- (i) a requirement in Part 3 of this Act; or
- (ii) a requirement in Part 2B of the Security of Critical Infrastructure Act 2018; or
- (iii) a requirement under the Telecommunications Act 1997; or
- (iv) a requirement under a law prescribed by the rules;
- (b) information that has been provided voluntarily to the National Cyber Security Coordinator by, or on behalf of, the impacted entity, other than under this Part;
- (c) information that has already been lawfully made available to the public.
39 Information provided in relation to other incidents—use and disclosure by National Cyber Security Coordinator
- (1) This section applies if:
- (a) an incident has occurred, is occurring or is imminent; and
- (b) an entity (the impacted entity) provides information to the National Cyber Security Coordinator in relation to the incident; and
- (c) the incident either:
- (i) is not a cyber security incident; or
- (ii) is a cyber security incident but is not a significant cyber security incident.
Permitted use and disclosure
- (2) The National Cyber Security Coordinator may make a record of, use or disclose the information provided by the impacted entity but only for the purposes of one or more of the following:
- (a) directing the impacted entity to other services that may assist the entity to respond to, mitigate, or resolve the incident;
- (b) if the incident is a cyber security incident—coordinating the whole of Government response to the cyber security incident where the National Cyber Security Coordinator considers such a response is necessary;
- (c) if the incident is a cyber security incident—informing and advising the Minister, and other Ministers of the Commonwealth, about the cyber security incident.
Restriction on use and disclosure for civil or regulatory action
- (3) However, the National Cyber Security Coordinator must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the impacted entity of a Commonwealth, State or Territory law other than:
- (a) a contravention by the impacted entity of this Part; or
- (b) a contravention by the impacted entity of a law that imposes a penalty or sanction for a criminal offence.
Note: See also section 42 in relation to admissibility of the information in proceedings against the impacted entity.
Interaction with the Privacy Act 1988
- (4) Subsection (2) does not authorise the National Cyber Security Coordinator to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.
Information not covered by the prohibitions in this section
- (5) Subsection (2) does not prohibit the recording, use or disclosure of the following information:
- (a) information that has been provided by, or on behalf of, the impacted entity to the Commonwealth about the cyber security incident to comply with:
- (i) a requirement in Part 3 of this Act; or
- (ii) a requirement in Part 2B of the Security of Critical Infrastructure Act 2018; or
- (iii) a requirement under the Telecommunications Act 1997; or
- (iv) a requirement under a law prescribed by the rules;
- (b) information that has been provided voluntarily to the National Cyber Security Coordinator by, or on behalf of, the impacted entity, other than under this Part;
- (c) information that has already been lawfully made available to the public.
40 Limitations on secondary use and disclosure
- (1) This section applies to information that:
- (a) has been provided by, or on behalf of, an entity (the impacted entity) under subsection 35(2) or as referred to in subsection 39(1); and
- (b) has been obtained by another entity, a Commonwealth body (other than ASD) or a State body under subsection 38(1) or 39(2) or this section; and
- (c) is held by the other entity, Commonwealth body or State body.
Note 1: This section does not apply to the information to the extent that it has been otherwise obtained by the other entity, Commonwealth body or State body.
Note 2: For ASD, see Division 1A of Part 6 of the Intelligence Services Act 2001.
Permitted use and disclosure
- (2) The other entity, Commonwealth body or State body may make a record of, use or disclose the information but only for the purposes of one or more of the following:
- (a) assisting the impacted entity, and other entities acting on behalf of the impacted entity, to respond to, mitigate or resolve the cyber security incident;
- (b) a permitted cyber security purpose for a cyber security incident.
Note: For permitted cyber security purpose for a cyber security incident: see section 10.
Restriction on use and disclosure for civil or regulatory action
- (3) However, the other entity, Commonwealth body or State body must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the impacted entity of a Commonwealth, State or Territory law other than:
- (a) a contravention by the impacted entity of this Part; or
- (b) a contravention by the impacted entity of a law that imposes a penalty or sanction for a criminal offence.
Interaction with the Privacy Act 1988
- (4) Subsection (2) does not authorise the other entity, Commonwealth body or State body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.
Information not covered by the prohibitions in this section
- (5) Subsection (2) does not prohibit:
- (a) recording, use or disclosure of information referred to in subsection 38(4) or 39(5); or
- (b) if the other entity is an individual—recording, use or disclosure of personal information about the individual; or
- (c) recording, use or disclosure of the impacted entity’s own information, with the consent of the impacted entity, by another entity, a Commonwealth body or a State body; or
- (d) recording, use or disclosure for the purposes of carrying out a State’s constitutional functions, powers or duties.
Civil penalty for contravention of this section
- (6) An entity is liable to a civil penalty if:
- (a) the entity contravenes subsection (2); and
- (b) the entity is not a Commonwealth officer; and
- (c) any of the following applies:
- (i) the information is sensitive information about an individual and the individual has not consented to the record, use or disclosure of the information;
- (ii) the information is confidential or commercially sensitive;
- (iii) the record, use or disclosure of the information would, or could reasonably be expected to, cause damage to the security, defence or international relations of the Commonwealth.
Note 1: See the Criminal Code for offences for Commonwealth officers.
Note 2: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.
Civil penalty: 60 penalty units.
41 Legal professional privilege
- (1) The fact that an entity provided information to the National Cyber Security Coordinator under subsection 35(2), or as referred to in subsection 39(1), does not otherwise affect a claim of legal professional privilege that anyone may make in relation to that information in any proceedings:
- (a) under any Commonwealth, State or Territory law (including the common law); or
- (b) before a tribunal of the Commonwealth, a State or a Territory.
- (2) Despite subsection (1), this section does not apply to the following:
- (a) the proceedings of a coronial inquiry or a Royal Commission in Australia;
- (b) proceedings in a federal court exercising original jurisdiction in which a writ of mandamus or prohibition or an injunction is sought against an officer or officers of the Commonwealth.
Note: For federal court, see section 2B of the Acts Interpretation Act 1901.
- (3) This section does not limit or affect any right, privilege or immunity that the entity has, apart from this section, as a defendant in any proceedings.
42 Admissibility of information voluntarily given by impacted entity
- (1) This section applies to information that:
- (a) has been provided by, or on behalf of, an entity (the impacted entity) under subsection 35(2) or as referred to in subsection 39(1); and
- (b) has been obtained by a Commonwealth body or State body under subsection 35(2), 38(1), 39(1), 39(2) or 40(2); and
- (c) is held by the Commonwealth body or State body.
Note: This section does not apply to information held by the Commonwealth body or State body to the extent that it has been otherwise obtained.
- (2) That information is not admissible in evidence against the impacted entity in any of the following proceedings:
- (a) criminal proceedings for an offence against a Commonwealth, State or Territory law, other than:
- (i) proceedings for an offence against section 137.1 or 137.2 of the Criminal Code (which deal with false or misleading information or documents) that relates to this Act; or
- (ii) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
- (b) civil proceedings for a contravention of a civil penalty provision of a Commonwealth, State or Territory law, other than a civil penalty provision of this Part;
- (c) proceedings for a breach of any other Commonwealth, State or Territory law (including the common law);
- (d) proceedings before a tribunal of the Commonwealth, a State or a Territory.
- (3) However, this section does not apply to the following:
- (a) the proceedings of a coronial inquiry or a Royal Commission in Australia;
- (b) proceedings in a federal court exercising original jurisdiction in which a writ of mandamus or prohibition or an injunction is sought against an officer or officers of the Commonwealth.
Note: For federal court, see section 2B of the Acts Interpretation Act 1901.
- (4) This section does not limit or affect any right, privilege or immunity that the entity has, apart from this section, as a defendant in any proceedings.
43 National Cyber Security Coordinator not compellable as witness
- (1) The Secretary may issue a certificate stating that:
- (a) a specified person is, or has been:
- (i) a person referred to in paragraph (a) of the definition of National Cyber Security Coordinator in section 8; or
- (ii) a person referred to in paragraph (b) of the definition of National Cyber Security Coordinator in section 8; and
- (b) the specified person is involved, or has been involved, in a specified matter in which the National Cyber Security Coordinator is performing or has performed functions or is exercising or has exercised powers under this Part.
- (2) If, under subsection (1), the Secretary issues a certificate in relation to a person and a specified matter, the person:
- (a) is not obliged to comply with a subpoena or similar direction of a federal court or a court of a State or Territory to attend and answer questions relating to the matter; and
- (b) is not compellable to give an expert opinion in any civil or criminal proceedings in a federal court or a court of a State or Territory in relation to the matter;
but only to the extent that the matter relates to information that has been provided by, or on behalf of, an entity under subsection 35(2) or as referred to in subsection 39(1).
- (3) This section does not apply to a coronial inquiry.