NDLFRS hosting agreement
13 NDLFRS hosting agreement
The NDLFRS hosting agreement is a written agreement that:
is between the Department (representing the Commonwealth) and each authority that:
is an authority of a State or Territory; and
meets the requirement in subsection (2); and
supplies or proposes to supply identification information to the Department for inclusion in a database in the NDLFRS; and
deals with the NDLFRS and the collection, use and disclosure of identification information in a database in the NDLFRS; and
meets the requirements in subsections (3), (4) and (5).
State and Territory parties must be subject to privacy obligations
Each authority of a State or Territory that is party to the agreement must:
be subject to a privacy law that:
is a law of the State or Territory; and
is prescribed by the rules for the purposes of this subparagraph; or
be one of the following to which the Privacy Act 1988 applies (with or without modifications) as if it were an organisation:
a State or Territory authority (as defined in that Act);
an instrumentality of a State or Territory; or
agree in the agreement to comply with the Australian Privacy Principles, with any modifications of subclauses 7.8 and 12.2 of those principles (about laws of the Commonwealth) specified in the agreement, as if the party were an APP entity.
The Department, which is the other party to the agreement, is subject to the Privacy Act 1988.
Requirements on each State or Territory party
The agreement must provide for each party that is an authority of a State or Territory:
to take reasonable steps to inform each individual whose identification information is, or is to be, included in a database in the NDLFRS of that inclusion; and
to provide each individual whose identification information is included in a database in the NDLFRS with means of:
finding out what that information is; and
having any errors in that information corrected in the database; and
to inform each such individual and the Department of any data breaches that:
involve identification information that relates to the individual and the NDLFRS; and
are reasonably likely to result in serious harm to the individual; and
to provide means for dealing with complaints by individuals relating to the NDLFRS and identification information that relates to them that is included in a database in the NDLFRS; and
to report annually to the Department on the party’s compliance with the agreement.
Requirements on the Department
The agreement must provide for the Department:
to maintain the security of identification information included in a database in the NDLFRS, including by encrypting the information; and
to inform the other parties to the agreement of any data breaches involving that information and the NDLFRS; and
to inform the Information Commissioner of any data breaches that:
involve that information and the NDLFRS; and
are reasonably likely to result in serious harm to an individual to whom that information relates.
For paragraph (4)(a), see also paragraph 25(a).
Requirement relating to compliance
The agreement must provide for suspension or termination of the ability of a party to the agreement to request identity verification services involving the NDLFRS if the party does not comply with the agreement.
Timing and nature of agreement
To avoid doubt:
an agreement may be the NDLFRS hosting agreement whether it was made before, on or after the commencement of this section; and
paragraph (1)(c) and subsections (3), (4) and (5) do not limit the matters the agreement may deal with.
This Act’s bill:Explanatory memorandumSecond reading speech
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.