Criteria for accreditation
77 Criteria for accreditation
The criteria for accreditation are the following:
the entity has appropriate data management and governance policies and practices and an appropriately qualified individual in a position that has responsibility for data management and data governance for the entity;
the entity is able to minimise the risk of unauthorised access, sharing or loss of data;
the entity has the necessary skills and capability to ensure the privacy, protection and appropriate use of data, including the ability to manage risks in relation to those matters;
any additional criteria prescribed under subsection (2).
In addition to the criteria set out in subsection (1), it is a criterion for accreditation as an ADSP that the entity has the necessary policies, practices, skills and capability to perform the following data services:
de‑identification data services;
secure access data services;
complex data integration services.
The rules may provide for additional criteria for accreditation covering any other matters the Minister considers appropriate.
This Act’s bill:Explanatory memorandumSecond reading speech
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.