AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
• federal, state, and territory surveillance legisla - tion, which regulates video surveillance, computer and data monitoring, GPS tracking, and the use of listening devices on individuals. Further definitions and details on the Privacy Act are set out in 6.1 Cybersecurity and Data Protection . Cybersecurity Cybersecurity laws in Australia are primarily governed under sector-specific federal laws, and include the fol - lowing. • Critical infrastructure: this sector is regulated under the Security of Critical Infrastructure Act 2018 (Cth) (the “SOCI Act”), which imposes registration, reporting, and notification obligations on owners and operators of critical infrastructure and empow - ers the Australian government to gather informa - tion and issue directions where there is a risk to security. More details are contained in 2. Critical Infrastructure Cybersecurity Regulation . • Telecommunications: this sector is regulated by dual legislation, namely: (a) the Telecommunications Act 1997 (Cth) (the “Telecommunications Act”), which imposes security and notification obligations on Aus - tralian telecommunications providers and empowers the Australian government to gather information and issue directions; and (b) the Telecommunications (Interception and Access) Act 1979 (Cth) (the “TIA Act”), which prohibits the interception of communication and access to stored communication data, ex - cept for certain law enforcement and national security purposes. • Corporate: corporations generally are regulated under the Corporations Act 2001 (Cth) (the “Corpo - rations Act”), which is highly relevant to the cyber - security space. For example, the director’s duty to exercise “care and diligence” (Section 180) is equally relevant to the management of foreseeable cyber and information security risks. • Financial services: certain financial, insurance, and superannuation entities are regulated through standards, including the Prudential Standard CPS 234 on Information Security (CPS 234), issued by the Australian Prudential Regulation Authority
(APRA). Additionally, entities in the financial servic - es have specific obligations under the Corporations Act, such as adequate risk management systems to hold a financial licence (section 912A). There are additional laws that are highly relevant to the cybersecurity space that are less sector-specific, such as consumer law, specifically the Competition and Consumer Act 2010 (Cth) (the “Consumer Act”) which addresses consumer affairs, including consum - er data protection and cyberscams. Cybercrime Overlaying the above are various cybercrime offences in Australia at the federal, state, and territory levels. These offences broadly encompass two categories: • offences that are directed at computers or other devices and involve hacking-related activities; and • cyber-enabled offences where such devices are used as a key component of the offence, includ - ing online fraud, online child abuse offences, and cyberstalking. Federally, cybercrime is criminalised under Parts 10.6 and 10.7 of the Schedule to the Criminal Code Act 1995 (Cth) (the “Criminal Code”), which sets out a vari - ety of offences with maximum penalties ranging from fine-only through to life imprisonment. Organisations should note that in addition to the Crim - inal Code: • the TIA Act also makes it a federal offence for an individual to (without authorisation) intercept or access private telecommunications without the knowledge of those involved; and • state and territory laws criminalise computer offences similar to those criminalised under the Criminal Code (eg, Part 6 of the Crimes Act 1900 (NSW) provides for multiple computer offences regarding unauthorised access, modification, or impairment of restricted data and electronic com - munications). Australian states and territories also have their own criminal laws which govern cybercrime offences.
11 CHAMBERS.COM
Powered by FlippingBook