Ransomware payment reports may only be used or disclosed for permitted purposes
29 Ransomware payment reports may only be used or disclosed for permitted purposes
Permitted use and disclosure
A designated Commonwealth body may make a record of, use or disclose information provided in a ransomware payment report by a reporting business entity, but only for the purposes of one or more of the following:
assisting the reporting business entity, and other entities acting on behalf of the reporting business entity, to respond to, mitigate or resolve the cyber security incident;
performing functions or exercising powers under this Part or Part 6 as it applies to this Part;
proceedings under, or arising out of, section 137.1 or 137.2 of the Criminal Code (false and misleading information and documents) that relate to this Act;
proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to a cyber security incident;
informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
the performance of the functions of an intelligence agency.
Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.
Restriction on use and disclosure for civil or regulatory action
However, the designated Commonwealth body must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the reporting business entity of a Commonwealth, State or Territory law other than:
a contravention by the reporting business entity of this Part; or
a contravention by the reporting business entity of a law that imposes a penalty or sanction for a criminal offence.
See also section 32 in relation to admissibility of the information in proceedings against the reporting business entity.
Interaction with the Privacy Act 1988
Subsection (1) does not authorise the designated Commonwealth body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.
Information not covered by the prohibitions in this section
Subsection (1) does not prohibit the recording, use or disclosure of the following information:
information that has been provided to the designated Commonwealth body by, or on behalf of, the entity to the Commonwealth to comply with:
a requirement in Part 2B of the Security of Critical Infrastructure Act 2018; or
a requirement under the Telecommunications Act 1997; or
a requirement under a law prescribed by the rules;
information that has already been lawfully made available to the public.
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.