AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
assistance to Australian organisations and the pub - lic on cyberthreats and it collaborates with business, government, and the community to increase cyber- resilience across Australia. The ACSC also runs the Computer Emergency Response Team (CERT), which provides advice and support to industry on cybersecurity issues affecting Australia’s critical infrastructure and other systems of national significance. Other key government bodies At this juncture, the following bodies should also be noted: • the Attorney-General’s Department (AGD) advises government on cybersecurity policies and law, including in relation to human rights, privacy, pro - tective security, international law, administration of criminal justice, and oversight of intelligence, security, and law enforcement agencies; • the Department of Defence (DoD) contributes to Australia’s whole-of-government cybersecurity pol - icy and operations and houses ASD; it also houses the Information Warfare Division, which develops information warfare capabilities for the Australian Defence Force (ADF); and • the Department of Foreign Affairs and Trade (DFAT) advances Australia’s international cyber-affairs agenda, which includes digital trade, cybersecurity, cybercrime, international security, internet govern - ance and co-operation, human rights and democ - racy online, and technology for development. Data Protection and Privacy The OAIC is the federal privacy and information regu - lator with a range of functions and powers to investi - gate and resolve privacy complaints, enforce privacy compliance, make determinations, and provide rem - edies for breaches under the notifiable data breach (NDB) scheme. The OAIC operates by reference to the Privacy Act, the My Health Records Act, the Tel - ecommunications Act, the TIA Act, and recently the Digital ID Act. The remedies range from enforceable undertakings to civil penalties of 2,000 penalty units (approximate - ly AUD660,000); but may also involve imprisonment.
Since December 2022, serious and repeated interfer - ences with privacy may attract a penalty of up to: • for entities, not body corporates – AUD2.5 million; or • for body corporates – the greater of AUD50 million, three times the value of the benefit attributable to the conduct, or 30% of the adjusted turnover for the relevant period. There are also state and territory privacy commission - ers which administer state and territory-based privacy and health information laws. These include: • the NSW Information and Privacy Commission, who administers, inter alia, the Privacy and Per - sonal Information Protection Act 1998 (NSW) and Health Records and Information Privacy Act 2002 (NSW); and • the Office of the Victorian Information Commis - sioner, who administers the Privacy and Data Protection Act 2014 (Vic) and the Victorian Health Complaints Commissioner, who handles breaches The CIC is part of the DoHA and is the federal regu - lator of the SOCI Act and certain provisions of the Telecommunications Act with powers to investigate, audit, and enforce on compliance matters. The CIC also has the ability to make recommendations to DoHA and the Home Affairs Minister on whether their information-gathering powers and directions powers should be exercised. The CIC additionally has enforcement powers which allows it to issue penal - ties for non-compliance that range from performance injunctions, enforceable undertakings, civil penalties of up to 120 penalty units (AUD39,600), or seek two years’ imprisonment. Telecommunications, Broadcasting and Marketing Cybersecurity The ACMA is Australia’s regulator for broadcasting, telecommunication, and certain online content and provides licensing to industry providers. ACMA has specific regulatory powers under the Telecommunica - tions Act, the TIA Act, the Spam Act, and the DNCR of the Health Records Act 2001 (Vic). Critical Infrastructure Cybersecurity
13 CHAMBERS.COM
Powered by FlippingBook