Privacy safeguard 12—security of CDR data, and destruction or de‑identification of redundant CDR data
56EO Privacy safeguard 12—security of CDR data, and destruction or de‑identification of redundant CDR data
Each person (a CDR entity) who is:
an accredited data recipient of CDR data; or
a designated gateway for CDR data;
must take the steps specified in the consumer data rules to protect the CDR data from:
misuse, interference and loss; and
unauthorised access, modification or disclosure.
This subsection is a civil penalty provision (see section 56EU).
If:
the CDR entity no longer needs any of that CDR data for either of the following purposes (the redundant data):
a purpose permitted under the consumer data rules;
a purpose for which the person is able to use or disclose it in accordance with this Division; and
the CDR entity is not required to retain the redundant data by or under an Australian law or a court/tribunal order; and
the redundant data does not relate to any current or anticipated:
legal proceedings; or
dispute resolution proceedings;
to which the CDR entity is a party;
the CDR entity must take the steps specified in the consumer data rules to destroy the redundant data or to ensure that the redundant data is de‑identified.
This subsection is a civil penalty provision (see section 56EU).
Australian Privacy Principle 11 will not apply for paragraph (b) (see paragraph 56EC(4)(a) or (d)).
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.