Voluntary provision of information in relation to other incidents or cyber security incidents
36 Voluntary provision of information in relation to other incidents or cyber security incidents
This section applies if:
an incident has occurred, is occurring or is imminent; and
an entity (the impacted entity) provides information to the National Cyber Security Coordinator in relation to the incident; and
it is unclear at the time the information is provided whether the incident is a cyber security incident or a significant cyber security incident.
The National Cyber Security Coordinator may collect and use the information for the purposes of determining whether the incident is a cyber security incident or a significant cyber security incident.
This subsection constitutes an authorisation for the National Cyber Security Coordinator to collect the information (including sensitive information) for the purposes of the Privacy Act 1988.
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.