AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
These standards provide that an entity’s board is ulti - mately responsible for information security and that the board must ensure that its entity maintains infor- mation security in a manner that is commensurate with the size and vulnerability of that entity’s informa - tion assets. APRA-regulated entities are required to externally audit their organisation’s compliance with CPS 234 and report to APRA in a timely manner. If organisations are non-compliant, they may be required to issue breach notices and create rectification plans. If organisations are unable to comply with the standards following this process, APRA may undertake a more formal enforcement process which may include enforceable undertakings or court proceedings. The Cyber Security Act In addition to the reporting obligations under the CPS 234, certain responsible entities concerning “critical financial market infrastructure asset” ( 2.1 Scope of Critical Infrastructure Cybersecurity Regulation ) also have ransomware reporting obligations under the Cyber Security Act (see 2.3 Incident Response and Notification Obligations ). 3.4 Operational Resilience Enforcement There has been no enforcement action against “data processing or storage” providers or other ICT ser - vices. In fact, there has been no enforcement action reported in relation to the SOCI Act. According to CISC’s Compliance and Enforcement Strategy published in April 2022, the CISC prioritises industry partnership and pursues a co-operative, edu - cative, and overall voluntary approach. Although it has a range of regulatory options available, it is yet to use any penalising enforcement action. Depending on the breach, action against ICTs may also come from other regulators such as the OAIC. 3.5 International Data Transfers Government Transfers Although there are limits on the use of the cybersecu - rity information provided by reporting business entities under the Cyber Security Act and Intelligence Services
Act 2001 (Cth), these limitations are unlikely to pre - vent the ASD, National Cyber Security Coordinator (the “NCS Coordinator”), or CIRB from disclosing the information to foreign authorities or joint partnerships for particular purposes. For example, if information is voluntarily provided in relation to a significant cybersecurity incident, the NCS Coordinator may disclose this information for the purpose of “coordinating the whole of Government response” or to inform Commonwealth ministers. Those ministers may then disclose the same infor - mation for a “permitted cyber security purpose”, such as mitigating material risks that could prejudice Aus - tralia’s social/economic stability, defence, or national security. This onward disclosure may include sharing and international transfers of information to foreign authorities or co-ordinated partnerships. The principal legislation governing data transfers is the Privacy Act. International (cross-border) disclosures of personal information are addressed primarily by Chap - ter 8 of the Australian Privacy Principles (APP 8). These principles require APP entities to “take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles”. What is “reasona - ble” depends on one’s specific circumstances but will usually involve a contract incorporating the APP 8 and the Australian entities monitoring or at least assessing the overseas entity’s systems. Importantly, APP 8 is not limited to where there is an active transfer of data but rather extends to wherever data is accessible to an overseas entity (eg, stored on servers in Australia, but accessible by overseas entities). Market Transfers The Privacy Act Since November 2024, the government has been able to add countries to a “white list”, a binding scheme that recognised countries as being on par to and therefore an exception to the APP 8 requirements. To date, no white list has been announced. The CDR regime In respect of data transfers more generally, Part IVD of the Consumer Act regulates the handling (includ -
20 CHAMBERS.COM
Powered by FlippingBook