Exemption—compromise to cybersecurity
60 Exemption—compromise to cybersecurity
An agency need not comply with section 53 in relation to an eligible data breach if compliance is likely to—
compromise or worsen the agency’s cybersecurity; or
lead to further data breaches of the agency.
The exemption applies only for the period during which a matter mentioned in subsection (1)(a) or (b) continues to apply for the agency in relation to the eligible data breach.
If an agency relies on this section, the agency must give a written notice to the information commissioner stating—
the agency is exempt from complying with division 2 under this section; and
when the agency expects the exemption will stop applying; and
how the agency will review the application of the exemption.
The agency must—
review the application of the exemption each month for the period during which the exemption is relied on; and
give the commissioner a summary of the review as soon as practicable after it is completed.
This Act’s bill:Explanatory memorandumSecond reading speech
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.