Barrister AI
All legislation
COMMONWEALTHAct
In force
This is the latest official compilation.Check the official source →
s 38

Information provided in relation to a significant cyber security incident—use and disclosure by National Cyber Security Coordinator

In force
Part 4Coordination of significant cyber security incidents
Division 3Protection of information

38 Information provided in relation to a significant cyber security incident—use and disclosure by National Cyber Security Coordinator

Permitted use and disclosure

(1)

The National Cyber Security Coordinator may make a record of, use or disclose information provided under subsection 35(2) by, or on behalf of, an entity (the impacted entity) in relation to a cyber security incident but only for the purposes of one or more of the following:

(a)

assisting the impacted entity, and other entities acting on behalf of the impacted entity, to respond to, mitigate or resolve the cyber security incident;

(b)

a permitted cyber security purpose for a cyber security incident.

Note 1:

For permitted cyber security purpose for a cyber security incident: see section 10. This includes the functions of the National Cyber Security Coordinator under this Part.

Note 2:

Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.

Restriction on use and disclosure for civil or regulatory action

(2)

However, the National Cyber Security Coordinator must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the impacted entity of a Commonwealth, State or Territory law other than:

(a)

a contravention by the impacted entity of this Part; or

(b)

a contravention by the impacted entity of a law that imposes a penalty or sanction for a criminal offence.

Note:

See also section 42 in relation to admissibility of the information in proceedings against the impacted entity.

Interaction with the Privacy Act 1988

(3)

Subsection (1) does not authorise the National Cyber Security Coordinator to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.

Information not covered by the prohibitions in this section

(4)

Subsection (1) does not prohibit the recording, use or disclosure of the following information:

(a)

information that has been provided by, or on behalf of, the impacted entity to the Commonwealth about the cyber security incident to comply with:

(i)

a requirement in Part 3 of this Act; or

(ii)

a requirement in Part 2B of the Security of Critical Infrastructure Act 2018; or

(iii)

a requirement under the Telecommunications Act 1997; or

(iv)

a requirement under a law prescribed by the rules;

(b)

information that has been provided voluntarily to the National Cyber Security Coordinator by, or on behalf of, the impacted entity, other than under this Part;

(c)

information that has already been lawfully made available to the public.

Research tools for this sectionPro

The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.