<?xml version='1.0' encoding='UTF-8'?>
<akomaNtoso xmlns="http://docs.oasis-open.org/legaldocml/ns/akn/3.0">
  <act name="act">
    <meta>
      <identification source="#lex-au">
        <FRBRWork>
          <FRBRthis value="/akn/au/act/2017/12/!main"/>
          <FRBRuri value="/akn/au/act/2017/12"/>
          <FRBRdate date="2017-01-01" name="Generation"/>
          <FRBRauthor href="#parliament"/>
          <FRBRcountry value="au"/>
          <FRBRsubtype value="act"/>
          <FRBRnumber value="12"/>
          <FRBRname value="privacy-amendment-(notifiable-data-breaches)-act-2017"/>
          <FRBRprescriptive value="true"/>
          <FRBRauthoritative value="true"/>
        </FRBRWork>
        <FRBRExpression>
          <FRBRthis value="/akn/au/act/2017/12/eng@2017-02-22/!main"/>
          <FRBRuri value="/akn/au/act/2017/12/eng@2017-02-22"/>
          <FRBRdate date="2017-02-22" name="Generation"/>
          <FRBRauthor href="#parliament"/>
          <FRBRlanguage language="eng"/>
        </FRBRExpression>
        <FRBRManifestation>
          <FRBRthis value="/akn/au/act/2017/12/eng@2017-02-22/!main.akn"/>
          <FRBRuri value="/akn/au/act/2017/12/eng@2017-02-22/!main.akn"/>
          <FRBRdate date="2026-07-14" name="Generation"/>
          <FRBRauthor href="#lex-au"/>
        </FRBRManifestation>
      </identification>
      <references source="#lex-au">
        <TLCOrganization eId="parliament" href="/ontology/organization/au/parliament" showAs="Parliament of Australia"/>
        <TLCOrganization eId="lex-au" href="https://github.com/cchew/lex-au" showAs="lex-au"/>
        <TLCConcept eId="deadline" href="/ontology/concept/au/deadline" showAs="deadline"/>
        <TLCRole eId="commissioner" href="/ontology/roles/au/commissioner" showAs="the Commissioner"/>
      </references>
    </meta>
    <preface>
      <p>Privacy Amendment (Notifiable Data Breaches) Act 2017</p>
      <p>No. 12, 2017</p>
      <p>An Act to amend the <i>Privacy Act 1988</i>, and for related purposes</p>
      <p>Contents</p>
      <p>1	Short title	1</p>
      <p>2	Commencement	2</p>
      <p>3	Schedules	2</p>
      <p>Schedule 1—Amendments	3</p>
      <p>Privacy Act 1988	3</p>
      <p>Privacy Amendment (Notifiable Data Breaches) Act 2017</p>
      <p>No. 12, 2017</p>
      <p>An Act to amend the <i>Privacy Act 1988</i>, and for related purposes</p>
      <p>[<i>Assented to 22 February 2017</i>]</p>
      <formula name="enacting">
        <p>The Parliament of Australia enacts:</p>
      </formula>
    </preface>
    <body>
      <section eId="sec-1">
        <num>1</num>
        <heading>Short title</heading>
        <content>
          <p>		This Act is the <i>Privacy Amendment (</i><i>Notifiable</i> <i>Data Breaches)</i> <i>Act </i><i>2017</i>.</p>
        </content>
      </section>
      <section eId="sec-2">
        <num>2</num>
        <heading>Commencement</heading>
        <subsection eId="sec-2__subsec-1">
          <num>1</num>
          <content>
            <p>Each provision of this Act specified in column 1 of the table commences, or is taken to have commenced, in accordance with column 2 of the table. Any other statement in column 2 has effect according to its terms.</p>
          </content>
          <table>
            <tr>
              <th>Commencement information</th>
              <th>Commencement information</th>
              <th>Commencement information</th>
            </tr>
            <tr>
              <td>Column 1</td>
              <td>Column 2</td>
              <td>Column 3</td>
            </tr>
            <tr>
              <td>Provisions</td>
              <td>Commencement</td>
              <td>Date/Details</td>
            </tr>
            <tr>
              <td>1.  Sections 1 to 3 and anything in this Act not elsewhere covered by this table</td>
              <td>The day this Act receives the Royal Assent.</td>
              <td>22 February 2017</td>
            </tr>
            <tr>
              <td>2.  Schedule 1</td>
              <td>A single day to be fixed by Proclamation.
However, if the provisions do not commence within the period of 12 months beginning on the day this Act receives the Royal Assent, they commence on the day after the end of that period.</td>
              <td>22 February 2018</td>
            </tr>
          </table>
          <authorialNote placement="end" eId="note-1" marker="1">
            <content>
              <p>Note: 	This table relates only to the provisions of this Act as originally enacted. It will not be amended to deal with any later amendments of this Act.</p>
            </content>
          </authorialNote>
        </subsection>
        <subsection eId="sec-2__subsec-2">
          <num>2</num>
          <content>
            <p>Any information in column 3 of the table is not part of this Act. Information may be inserted in this column, or information in it may be edited, in any published version of this Act.</p>
          </content>
        </subsection>
      </section>
      <section eId="sec-3">
        <num>3</num>
        <heading>Schedules</heading>
        <content>
          <p>Legislation that is specified in a Schedule to this Act is amended or repealed as set out in the applicable items in the Schedule concerned, and any other item in a Schedule to this Act has effect according to its terms.</p>
        </content>
      </section>
    </body>
    <attachments>
      <attachment>
        <hcontainer name="schedule" eId="schedule-1">
          <heading>Amendments</heading>
          <content>
            <p>Privacy Act 1988</p>
          </content>
          <hcontainer name="clause" eId="schedule-1__clause-1">
            <num>1</num>
            <heading>Subsection 6(1)</heading>
            <content>
              <p>Insert:</p>
              <p><b><i>at risk </i></b>from an eligible data breach<b><i> </i></b>has the meaning given by section 26WE.</p>
              <p><b><i>eligible</i></b><b><i> data breach</i></b> has the meaning given by Division 2 of Part IIIC.</p>
            </content>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-2">
            <num>2</num>
            <heading>After subsection 13(4)</heading>
            <content>
              <p>Insert:</p>
              <p>Notification of eligible data breaches etc.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-2__subclause-4A">
              <num>4A</num>
              <content>
                <p>	(4A)	If an entity (within the meaning of <b><i>interference with the privacy of an individual</i></b>.<ref href="#part-IIIC">Part IIIC</ref>) contravenes subsection 26WH(2), 26WK(2), 26WL(3) or 26WR(10), the contravention is taken to be an act that is an </p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-3">
            <num>3</num>
            <heading>After Part IIIB</heading>
            <content>
              <p>Insert:</p>
            </content>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WA">
            <num>26WA</num>
            <heading>Simplified outline of this Part</heading>
            <content>
              <p>•	This Part sets up a scheme for notification of eligible data breaches.</p>
              <p>•	An eligible data breach happens if:</p>
              <p>•	An entity must give a notification if:</p>
            </content>
            <paragraph eId="schedule-1__clause-26WA__para-a">
              <num>a</num>
              <content>
                <p>there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WA__para-b">
              <num>b</num>
              <content>
                <p>the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates.</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WA__para-a">
              <num>a</num>
              <content>
                <p>it has reasonable grounds to believe that an eligible data breach has happened; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WA__para-b">
              <num>b</num>
              <content>
                <p>it is directed to do so by <role refersTo="#commissioner">the Commissioner</role>.</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WB">
            <num>26WB</num>
            <heading>Entity</heading>
            <content>
              <p>		For the purposes of this Part, <b><i>entity</i></b> includes a person who is a file number recipient.</p>
            </content>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WC">
            <num>26WC</num>
            <heading>Deemed holding of information</heading>
            <content>
              <p>Overseas recipients</p>
              <p>this Part has effect as if:</p>
              <p>Bodies or persons with no Australian link</p>
              <p>this Part has effect as if:</p>
              <p>Note:	See <ref href="#sec-21N">section 21N</ref>A.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WC__subclause-1">
              <num>1</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WC__para-a">
              <num>a</num>
              <content>
                <p>an APP entity has disclosed personal information about one or more individuals to an overseas recipient; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-b">
              <num>b</num>
              <content>
                <p>Australian Privacy Principle 8.1 applied to the disclosure of the personal information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-c">
              <num>c</num>
              <content>
                <p>the overseas recipient holds the personal information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-d">
              <num>d</num>
              <content>
                <p>the personal information were held by the APP entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-e">
              <num>e</num>
              <content>
                <p>the APP entity were required under <ref href="#sec-15">section 15</ref> not to do an act, or engage in a practice, that breaches Australian Privacy Principle 11.1 in relation to the personal information.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WC__subclause-2">
              <num>2</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WC__para-a">
              <num>a</num>
              <content>
                <p>either:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-i">
              <num>i</num>
              <content>
                <p>a credit provider has disclosed, under paragraph 21G(3)(b) or (c), credit eligibility information about one or more individuals to a related body corporate, or person, that does not have an Australian link; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-ii">
              <num>ii</num>
              <content>
                <p>a credit provider has disclosed, under subsection 21M(1), credit eligibility information about one or more individuals to a body or person that does not have an Australian link; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-b">
              <num>b</num>
              <content>
                <p>the related body corporate, body or person holds the credit eligibility information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-c">
              <num>c</num>
              <content>
                <p>the credit eligibility information were held by the credit provider; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WC__para-d">
              <num>d</num>
              <content>
                <p>the credit provider were required to comply with subsection 21S(1) in relation to the credit eligibility information.</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WD">
            <num>26WD</num>
            <heading>Exception—notification under the My Health Records Act 2012</heading>
            <content>
              <p>If:</p>
              <p>has been, or is required to be, notified under <i>My Health Records Act 201</i><i>2</i>, this Part does not apply in relation to the access, disclosure or loss.<ref href="#sec-75">section 75</ref> of the </p>
            </content>
            <paragraph eId="schedule-1__clause-26WD__para-a">
              <num>a</num>
              <content>
                <p>an unauthorised access to information; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WD__para-b">
              <num>b</num>
              <content>
                <p>an unauthorised disclosure of information; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WD__para-c">
              <num>c</num>
              <content>
                <p>a loss of information;</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WE">
            <num>26WE</num>
            <heading>Eligible data breach</heading>
            <content>
              <p>Scope</p>
              <p>Eligible data breach</p>
              <p>then:</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WE__subclause-1">
              <num>1</num>
              <content>
                <p>This section applies if:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WE__para-a">
              <num>a</num>
              <content>
                <p>both:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>an APP entity holds personal information relating to one or more individuals; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>the APP entity is required under <ref href="#sec-15">section 15</ref> not to do an act, or engage in a practice, that breaches Australian Privacy Principle 11.1 in relation to the personal information; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-b">
              <num>b</num>
              <content>
                <p>both:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>a credit reporting body holds credit reporting information relating to one or more individuals; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>the credit reporting body is required to comply with <ref href="#sec-20Q">section 20Q</ref> in relation to the credit reporting information; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-c">
              <num>c</num>
              <content>
                <p>both:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>a credit provider holds credit eligibility information relating to one or more individuals; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>the credit provider is required to comply with subsection 21S(1) in relation to the credit eligibility information; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-d">
              <num>d</num>
              <content>
                <p>both:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>a file number recipient holds tax file number information relating to one or more individuals; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>the file number recipient is required under <ref href="#sec-18">section 18</ref> not to do an act, or engage in a practice, that breaches a <ref href="#sec-17">section 17</ref> rule that relates to the tax file number information.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WE__subclause-2">
              <num>2</num>
              <content>
                <p>For the purposes of this Act, if:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WE__para-a">
              <num>a</num>
              <content>
                <p>both of the following conditions are satisfied:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>there is unauthorised access to, or unauthorised disclosure of, the information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-b">
              <num>b</num>
              <content>
                <p>the information is lost in circumstances where:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-i">
              <num>i</num>
              <content>
                <p>unauthorised access to, or unauthorised disclosure of, the information is likely to occur; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-ii">
              <num>ii</num>
              <content>
                <p>assuming that unauthorised access to, or unauthorised disclosure of, the information were to occur, a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-c">
              <num>c</num>
              <content>
                <p>	(c)	the access or disclosure covered by paragraph (a), or the loss covered by paragraph (b), is an <b><i>eligible</i></b><b><i> data breach</i></b> of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WE__para-d">
              <num>d</num>
              <content>
                <p>	(d)	an individual covered by subparagraph (a)(ii) or (b)(ii) is <b><i>at risk</i></b><b><i> </i></b>from the eligible data breach.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WE__subclause-3">
              <num>3</num>
              <content>
                <p>Subsection (2) has effect subject to <ref href="#sec-26W">section 26W</ref>F.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WF">
            <num>26WF</num>
            <heading>Exception—remedial action</heading>
            <content>
              <p>Access to, or disclosure of, information</p>
              <p>the access or disclosure is not, and is taken never to have been:</p>
              <p>this Part does not require:</p>
              <p>to take steps to notify the individual of the contents of a statement that relates to the access or disclosure.</p>
              <p>Loss of information</p>
              <p>the loss is not, and is taken never to have been:</p>
              <p>the loss is not, and is taken never to have been:</p>
              <p>this Part does not require:</p>
              <p>to take steps to notify the individual of the contents of a statement that relates to the loss.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WF__subclause-1">
              <num>1</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WF__para-a">
              <num>a</num>
              <content>
                <p>an access to, or disclosure of, information is covered by paragraph 26WE(2)(a); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-b">
              <num>b</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the access or disclosure; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-c">
              <num>c</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so before the access or disclosure results in serious harm to any of the individuals to whom the information relates; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-d">
              <num>d</num>
              <content>
                <p>as a result of the action, a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-e">
              <num>e</num>
              <content>
                <p>	(e)	an <b><i>eligible data breach</i></b> of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-f">
              <num>f</num>
              <content>
                <p>	(f)	an <b><i>eligible data breach </i></b>of any other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WF__subclause-2">
              <num>2</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WF__para-a">
              <num>a</num>
              <content>
                <p>an access to, or disclosure of, information is covered by paragraph 26WE(2)(a); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-b">
              <num>b</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the access or disclosure; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-c">
              <num>c</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so before the access or disclosure results in serious harm to a particular individual to whom the information relates; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-d">
              <num>d</num>
              <content>
                <p>as a result of the action, a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to the individual;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-e">
              <num>e</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-f">
              <num>f</num>
              <content>
                <p>any other entity;</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WF__subclause-3">
              <num>3</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WF__para-a">
              <num>a</num>
              <content>
                <p>a loss of information is covered by paragraph 26WE(2)(b); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-b">
              <num>b</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the loss; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-c">
              <num>c</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so before there is unauthorised access to, or unauthorised disclosure of, the information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-d">
              <num>d</num>
              <content>
                <p>as a result of the action, there is no unauthorised access to, or unauthorised disclosure of, the information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-e">
              <num>e</num>
              <content>
                <p>	(e)	an <b><i>eligible data breach</i></b> of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-f">
              <num>f</num>
              <content>
                <p>	(f)	an <b><i>eligible data breach </i></b>of any other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WF__subclause-4">
              <num>4</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WF__para-a">
              <num>a</num>
              <content>
                <p>a loss of information is covered by paragraph 26WE(2)(b); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-b">
              <num>b</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the loss; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-c">
              <num>c</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-i">
              <num>i</num>
              <content>
                <p>after there is unauthorised access to, or unauthorised disclosure of, the information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-ii">
              <num>ii</num>
              <content>
                <p>before the access or disclosure results in serious harm to any of the individuals to whom the information relates; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-d">
              <num>d</num>
              <content>
                <p>as a result of the action, a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-e">
              <num>e</num>
              <content>
                <p>	(e)	an <b><i>eligible data breach</i></b> of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-f">
              <num>f</num>
              <content>
                <p>	(f)	an <b><i>eligible data breach </i></b>of any other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WF__subclause-5">
              <num>5</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WF__para-a">
              <num>a</num>
              <content>
                <p>a loss of information is covered by paragraph 26WE(2)(b); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-b">
              <num>b</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the loss; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-c">
              <num>c</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-i">
              <num>i</num>
              <content>
                <p>after there is unauthorised access to, or unauthorised disclosure of, the information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-ii">
              <num>ii</num>
              <content>
                <p>before the access or disclosure results in serious harm to a particular individual to whom the information relates; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-d">
              <num>d</num>
              <content>
                <p>as a result of the action, a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to the individual;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-e">
              <num>e</num>
              <content>
                <p>the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WF__para-f">
              <num>f</num>
              <content>
                <p>any other entity;</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WG">
            <num>26WG</num>
            <heading>Whether access or disclosure would be likely, or would not be likely, to result in serious harm—relevant matters</heading>
            <content>
              <p>For the purposes of this Division, in determining whether a reasonable person would conclude that an access to, or a disclosure of, information:</p>
              <p>to result in serious harm to any of the individuals to whom the information relates, have regard to the following:</p>
              <p>the likelihood that the persons, or the kinds of persons, who:</p>
              <p>have obtained, or could obtain, information or knowledge required to circumvent the security technology or methodology;</p>
              <p>Note:	If the security technology or methodology mentioned in paragraph (h) is encryption, an encryption key is an example of information required to circumvent the security technology or methodology.</p>
              <p>Subdivision A—Suspected eligible data breaches</p>
            </content>
            <paragraph eId="schedule-1__clause-26WG__para-a">
              <num>a</num>
              <content>
                <p>would be likely; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-b">
              <num>b</num>
              <content>
                <p>would not be likely;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-c">
              <num>c</num>
              <content>
                <p>the kind or kinds of information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-d">
              <num>d</num>
              <content>
                <p>the sensitivity of the information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-e">
              <num>e</num>
              <content>
                <p>whether the information is protected by one or more security measures;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-f">
              <num>f</num>
              <content>
                <p>if the information is protected by one or more security measures—the likelihood that any of those security measures could be overcome;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-g">
              <num>g</num>
              <content>
                <p>the persons, or the kinds of persons, who have obtained, or who could obtain, the information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-h">
              <num>h</num>
              <content>
                <p>if a security technology or methodology:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-i">
              <num>i</num>
              <content>
                <p>was used in relation to the information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-ii">
              <num>ii</num>
              <content>
                <p>was designed to make the information unintelligible or meaningless to persons who are not authorised to obtain the information;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-iii">
              <num>iii</num>
              <content>
                <p>have obtained, or who could obtain, the information; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-iv">
              <num>iv</num>
              <content>
                <p>have, or are likely to have, the intention of causing harm to any of the individuals to whom the information relates;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-i">
              <num>i</num>
              <content>
                <p>the nature of the harm;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WG__para-j">
              <num>j</num>
              <content>
                <p>any other relevant matters.</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WH">
            <num>26WH</num>
            <heading>Assessment of suspected eligible data breach</heading>
            <content>
              <p>Scope</p>
              <p>Assessment</p>
              <p>Note:	Section 26WK applies if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WH__subclause-1">
              <num>1</num>
              <content>
                <p>This section applies if:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WH__para-a">
              <num>a</num>
              <content>
                <p>an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WH__para-b">
              <num>b</num>
              <content>
                <p>the entity is not aware that there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WH__subclause-2">
              <num>2</num>
              <content>
                <p>The entity must:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WH__para-a">
              <num>a</num>
              <content>
                <p>carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WH__para-b">
              <num>b</num>
              <content>
                <p>take all reasonable steps to ensure that the assessment is completed <quantity refersTo="#deadline">within 30 days</quantity> after the entity becomes aware as mentioned in paragraph (1)(a).</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WJ">
            <num>26WJ</num>
            <heading>Exception—eligible data breaches of other entities</heading>
            <content>
              <p>If:</p>
              <p>that section does not apply in relation to those eligible data breaches of those other entities.</p>
              <p>Subdivision B—General notification obligations</p>
            </content>
            <paragraph eId="schedule-1__clause-26WJ__para-a">
              <num>a</num>
              <content>
                <p>an entity complies with <ref href="#sec-26W">section 26W</ref>H in relation to an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WJ__para-b">
              <num>b</num>
              <content>
                <p>the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities;</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WK">
            <num>26WK</num>
            <heading>Statement about eligible data breach</heading>
            <content>
              <p>Scope</p>
              <p>Statement</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WK__subclause-1">
              <num>1</num>
              <content>
                <p>This section applies if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WK__subclause-2">
              <num>2</num>
              <content>
                <p>The entity must:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WK__para-a">
              <num>a</num>
              <content>
                <p>both:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-i">
              <num>i</num>
              <content>
                <p>prepare a statement that complies with subsection (3); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-ii">
              <num>ii</num>
              <content>
                <p>give a copy of the statement to <role refersTo="#commissioner">the Commissioner</role>; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-b">
              <num>b</num>
              <content>
                <p>do so as soon as practicable after the entity becomes so aware.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WK__subclause-3">
              <num>3</num>
              <content>
                <p>The statement referred to in subparagraph (2)(a)(i) must set out:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WK__para-a">
              <num>a</num>
              <content>
                <p>the identity and contact details of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-b">
              <num>b</num>
              <content>
                <p>a description of the eligible data breach that the entity has reasonable grounds to believe has happened; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-c">
              <num>c</num>
              <content>
                <p>the kind or kinds of information concerned; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WK__para-d">
              <num>d</num>
              <content>
                <p>recommendations about the steps that individuals should take in response to the eligible data breach that the entity has reasonable grounds to believe has happened.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WK__subclause-4">
              <num>4</num>
              <content>
                <p>If the entity has reasonable grounds to believe that the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities, the statement referred to in subparagraph (2)(a)(i) may also set out the identity and contact details of those other entities.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WL">
            <num>26WL</num>
            <heading>Entity must notify eligible data breach</heading>
            <content>
              <p>Scope</p>
              <p>Notification</p>
              <p>Note:	See also subsections 26WF(2) and (5), which deal with remedial action.</p>
              <p>Method of providing a statement to an individual</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WL__subclause-1">
              <num>1</num>
              <content>
                <p>This section applies if:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WL__para-a">
              <num>a</num>
              <content>
                <p>an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-b">
              <num>b</num>
              <content>
                <p>the entity has prepared a statement that:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-i">
              <num>i</num>
              <content>
                <p>complies with subsection 26WK(3); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-ii">
              <num>ii</num>
              <content>
                <p>relates to the eligible data breach that the entity has reasonable grounds to believe has happened.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WL__subclause-2">
              <num>2</num>
              <content>
                <p>The entity must:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WL__para-a">
              <num>a</num>
              <content>
                <p>if it is practicable for the entity to notify the contents of the statement to each of the individuals to whom the relevant information relates—take such steps as are reasonable in the circumstances to notify the contents of the statement to each of the individuals to whom the relevant information relates; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-b">
              <num>b</num>
              <content>
                <p>if it is practicable for the entity to notify the contents of the statement to each of the individuals who are at risk from the eligible data breach—take such steps as are reasonable in the circumstances to notify the contents of the statement to each of the individuals who are at risk from the eligible data breach; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-c">
              <num>c</num>
              <content>
                <p>if neither paragraph (a) nor (b) applies:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-i">
              <num>i</num>
              <content>
                <p>publish a copy of the statement on the entity’s website (if any); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WL__para-ii">
              <num>ii</num>
              <content>
                <p>take reasonable steps to publicise the contents of the statement.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WL__subclause-3">
              <num>3</num>
              <content>
                <p>The entity must comply with subsection (2) as soon as practicable after the completion of the preparation of the statement.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WL__subclause-4">
              <num>4</num>
              <content>
                <p>If the entity normally communicates with a particular individual using a particular method, the notification to the individual under paragraph (2)(a) or (b) may use that method. This subsection does not limit paragraph (2)(a) or (b).</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WM">
            <num>26WM</num>
            <heading>Exception—eligible data breaches of other entities</heading>
            <content>
              <p>If:</p>
              <p>those sections do not apply in relation to those eligible data breaches of those other entities.</p>
            </content>
            <paragraph eId="schedule-1__clause-26WM__para-a">
              <num>a</num>
              <content>
                <p>an entity complies with sections 26WK and 26WL in relation to an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WM__para-b">
              <num>b</num>
              <content>
                <p>the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities;</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WN">
            <num>26WN</num>
            <heading>Exception—enforcement related activities</heading>
            <content>
              <p>If:</p>
              <p>paragraph 26WK(3)(d) and <ref href="#sec-26W">section 26W</ref>L do not apply in relation to:</p>
            </content>
            <paragraph eId="schedule-1__clause-26WN__para-a">
              <num>a</num>
              <content>
                <p>an entity is an enforcement body; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WN__para-b">
              <num>b</num>
              <content>
                <p>the chief executive officer of the enforcement body believes on reasonable grounds that there has been an eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WN__para-c">
              <num>c</num>
              <content>
                <p>the chief executive officer of the enforcement body believes on reasonable grounds that compliance with <ref href="#sec-26W">section 26W</ref>L in relation to the eligible data breach would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, the enforcement body;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WN__para-d">
              <num>d</num>
              <content>
                <p>the eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WN__para-e">
              <num>e</num>
              <content>
                <p>if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities.</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WP">
            <num>26WP</num>
            <heading>Exception—inconsistency with secrecy provisions</heading>
            <content>
              <p>Secrecy provisions</p>
              <p>Prescribed secrecy provisions</p>
              <p>are taken not to be provisions that require or authorise the use or disclosure of information.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-1">
              <num>1</num>
              <content>
                <p>	(1)	For the purposes of this section, <b><i>secrecy provision</i></b> means a provision that:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WP__para-a">
              <num>a</num>
              <content>
                <p>is a provision of a law of the Commonwealth (other than this Act); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WP__para-b">
              <num>b</num>
              <content>
                <p>prohibits or regulates the use or disclosure of information.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-2">
              <num>2</num>
              <content>
                <p>If compliance by an entity with subparagraph 26WK(2)(a)(ii) in relation to a statement would, to any extent, be inconsistent with a secrecy provision (other than a prescribed secrecy provision), subsection 26WK(2) does not apply to the entity, in relation to the statement, to the extent of the inconsistency.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-3">
              <num>3</num>
              <content>
                <p>If compliance by an entity with <ref href="#sec-26W">section 26W</ref>L in relation to a statement would, to any extent, be inconsistent with a secrecy provision (other than a prescribed secrecy provision), <ref href="#sec-26W">section 26W</ref>L does not apply to the entity, in relation to the statement, to the extent of the inconsistency.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-4">
              <num>4</num>
              <content>
                <p>	(4)	For the purposes of this section, <b><i>prescribed secrecy provision</i></b> means a secrecy provision that is specified in the regulations.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-5">
              <num>5</num>
              <content>
                <p>For the purposes of a prescribed secrecy provision:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WP__para-a">
              <num>a</num>
              <content>
                <p>subparagraph 26WK(2)(a)(ii); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WP__para-b">
              <num>b</num>
              <content>
                <p><ref href="#sec-26W">section 26W</ref>L;</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-6">
              <num>6</num>
              <content>
                <p>If compliance by an entity with subparagraph 26WK(2)(a)(ii) in relation to a statement would, to any extent, be inconsistent with a prescribed secrecy provision, subsection 26WK(2) does not apply to the entity in relation to the statement.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WP__subclause-7">
              <num>7</num>
              <content>
                <p>If compliance by an entity with <ref href="#sec-26W">section 26W</ref>L in relation to a statement would, to any extent, be inconsistent with a prescribed secrecy provision, <ref href="#sec-26W">section 26W</ref>L does not apply to the entity in relation to the statement.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WQ">
            <num>26WQ</num>
            <heading>Exception—declaration by Commissioner</heading>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-1">
              <num>1</num>
              <content>
                <p>If <role refersTo="#commissioner">the Commissioner</role>:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>is aware that there are reasonable grounds to believe that there has been an eligible data breach of an entity; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>is informed by an entity that the entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity;</p>
              </content>
            </paragraph>
            <content>
              <p><role refersTo="#commissioner">the Commissioner</role> may, by written notice given to the entity:</p>
              <p>as if that subsection required compliance with subsection 26WL(2) before the end of a period specified in the declaration.</p>
              <p>Applications</p>
              <p><role refersTo="#commissioner">the Commissioner</role> is taken not to have refused the application.</p>
              <p>until <role refersTo="#commissioner">the Commissioner</role> makes a decision in response to the application for the declaration.</p>
              <p>Extension of specified period</p>
              <p>Subdivision C—Commissioner may direct entity to notify eligible data breach</p>
            </content>
            <paragraph eId="schedule-1__clause-26WQ__para-c">
              <num>c</num>
              <content>
                <p>declare that sections 26WK and 26WL do not apply in relation to:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-i">
              <num>i</num>
              <content>
                <p>the eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-ii">
              <num>ii</num>
              <content>
                <p>if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-d">
              <num>d</num>
              <content>
                <p>declare that subsection 26WL(3) has effect in relation to:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-i">
              <num>i</num>
              <content>
                <p>the eligible data breach of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-ii">
              <num>ii</num>
              <content>
                <p>if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities;</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-2">
              <num>2</num>
              <content>
                <p><role refersTo="#commissioner">The Commissioner</role>’s power in paragraph (1)(d) may only be used to extend the time for compliance with subsection 26WL(2) to the end of a period that <role refersTo="#commissioner">the Commissioner</role> is satisfied is reasonable in the circumstances.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-3">
              <num>3</num>
              <content>
                <p><role refersTo="#commissioner">The Commissioner</role> must not make a declaration under subsection (1) unless <role refersTo="#commissioner">the Commissioner</role> is satisfied that it is reasonable in the circumstances to do so, having regard to the following:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>the public interest;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>any relevant advice given to <role refersTo="#commissioner">the Commissioner</role> by:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-i">
              <num>i</num>
              <content>
                <p>an enforcement body; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-ii">
              <num>ii</num>
              <content>
                <p>the Australian Signals Directorate of the Defence Department;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-c">
              <num>c</num>
              <content>
                <p>such other matters (if any) as <role refersTo="#commissioner">the Commissioner</role> considers relevant.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-4">
              <num>4</num>
              <content>
                <p>Paragraph (3)(b) does not limit the advice to which <role refersTo="#commissioner">the Commissioner</role> may have regard.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-5">
              <num>5</num>
              <content>
                <p><role refersTo="#commissioner">The Commissioner</role> may give a notice of a declaration to an entity under subsection (1):</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>on <role refersTo="#commissioner">the Commissioner</role>’s own initiative; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>on application made to <role refersTo="#commissioner">the Commissioner</role> by the entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-6">
              <num>6</num>
              <content>
                <p>An application by an entity under paragraph (5)(b) may be expressed to be:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>an application for a paragraph (1)(c) declaration; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>an application for a paragraph (1)(d) declaration; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-c">
              <num>c</num>
              <content>
                <p>an application for:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-i">
              <num>i</num>
              <content>
                <p>a paragraph (1)(c) declaration; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-ii">
              <num>ii</num>
              <content>
                <p>in the event that <role refersTo="#commissioner">the Commissioner</role> is not disposed to make such a declaration—a paragraph (1)(d) declaration.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-7">
              <num>7</num>
              <content>
                <p>If an entity applies to <role refersTo="#commissioner">the Commissioner</role> under paragraph (5)(b):</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p><role refersTo="#commissioner">the Commissioner</role> may refuse the application; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>if <role refersTo="#commissioner">the Commissioner</role> does so—<role refersTo="#commissioner">the Commissioner</role> must give written notice of the refusal to the entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-8">
              <num>8</num>
              <content>
                <p>If:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>an application for a paragraph (1)(d) declaration nominates a period to be specified in the declaration; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p><role refersTo="#commissioner">the Commissioner</role> makes the declaration, but specifies a different period in the declaration;</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-9">
              <num>9</num>
              <content>
                <p>If an entity applies to <role refersTo="#commissioner">the Commissioner</role> under paragraph (5)(b) for a declaration that, to any extent, relates to an eligible data breach of the entity, sections 26WK and 26WL do not apply in relation to:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>the eligible data breach; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities;</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-10">
              <num>10</num>
              <content>
                <p>An entity is not entitled to make an application under paragraph (5)(b) in relation to an eligible data breach of the entity if:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WQ__para-a">
              <num>a</num>
              <content>
                <p>the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WQ__para-b">
              <num>b</num>
              <content>
                <p>one of those other entities has already made an application under paragraph (5)(b) in relation to the eligible data breach of the other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WQ__subclause-11">
              <num>11</num>
              <content>
                <p>If notice of a paragraph (1)(d) declaration has been given to an entity, <role refersTo="#commissioner">the Commissioner</role> may, by written notice given to the entity, extend the period specified in the declaration.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WR">
            <num>26WR</num>
            <heading>Commissioner may direct entity to notify eligible data breach</heading>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-1">
              <num>1</num>
              <content>
                <p>If <role refersTo="#commissioner">the Commissioner</role> is aware that there are reasonable grounds to believe that there has been an eligible data breach of an entity, <role refersTo="#commissioner">the Commissioner</role> may, by written notice given to the entity, direct the entity to:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WR__para-a">
              <num>a</num>
              <content>
                <p>prepare a statement that complies with subsection (4); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-b">
              <num>b</num>
              <content>
                <p>give a copy of the statement to <role refersTo="#commissioner">the Commissioner</role>.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-2">
              <num>2</num>
              <content>
                <p>The direction must also require the entity to:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WR__para-a">
              <num>a</num>
              <content>
                <p>if it is practicable for the entity to notify the contents of the statement to each of the individuals to whom the relevant information relates—take such steps as are reasonable in the circumstances to notify the contents of the statement to each of the individuals to whom the relevant information relates; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-b">
              <num>b</num>
              <content>
                <p>if it is practicable for the entity to notify the contents of the statement to each of the individuals who are at risk from the eligible data breach—take such steps as are reasonable in the circumstances to notify the contents of the statement to each of the individuals who are at risk from the eligible data breach; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-c">
              <num>c</num>
              <content>
                <p>if neither paragraph (a) nor (b) applies:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-i">
              <num>i</num>
              <content>
                <p>publish a copy of the statement on the entity’s website (if any); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-ii">
              <num>ii</num>
              <content>
                <p>take reasonable steps to publicise the contents of the statement.</p>
              </content>
            </paragraph>
            <content>
              <p>Note:	See also subsections 26WF(2) and (5), which deal with remedial action.</p>
              <p>Method of providing a statement to an individual</p>
              <p>Compliance with direction</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-3">
              <num>3</num>
              <content>
                <p>Before giving a direction to an entity under subsection (1), <role refersTo="#commissioner">the Commissioner</role> must invite the entity to make a submission to <role refersTo="#commissioner">the Commissioner</role> in relation to the direction within the period specified in the invitation.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-4">
              <num>4</num>
              <content>
                <p>The statement referred to in paragraph (1)(a) must set out:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WR__para-a">
              <num>a</num>
              <content>
                <p>the identity and contact details of the entity; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-b">
              <num>b</num>
              <content>
                <p>a description of the eligible data breach that <role refersTo="#commissioner">the Commissioner</role> has reasonable grounds to believe has happened; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-c">
              <num>c</num>
              <content>
                <p>the kind or kinds of information concerned; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-d">
              <num>d</num>
              <content>
                <p>recommendations about the steps that individuals should take in response to the eligible data breach that <role refersTo="#commissioner">the Commissioner</role> has reasonable grounds to believe has happened.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-5">
              <num>5</num>
              <content>
                <p>A direction under subsection (1) may also require the statement referred to in paragraph (1)(a) to set out specified information that relates to the eligible data breach that <role refersTo="#commissioner">the Commissioner</role> has reasonable grounds to believe has happened.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-6">
              <num>6</num>
              <content>
                <p>In deciding whether to give a direction to an entity under subsection (1), <role refersTo="#commissioner">the Commissioner</role> must have regard to the following:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WR__para-a">
              <num>a</num>
              <content>
                <p>any relevant advice given to <role refersTo="#commissioner">the Commissioner</role> by:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-i">
              <num>i</num>
              <content>
                <p>an enforcement body; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-ii">
              <num>ii</num>
              <content>
                <p>the Australian Signals Directorate of the Defence Department;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-b">
              <num>b</num>
              <content>
                <p>any relevant submission that was made by the entity:</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-i">
              <num>i</num>
              <content>
                <p>in response to an invitation under subsection (3); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-ii">
              <num>ii</num>
              <content>
                <p>within the period specified in the invitation;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WR__para-c">
              <num>c</num>
              <content>
                <p>such other matters (if any) as <role refersTo="#commissioner">the Commissioner</role> considers relevant.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-7">
              <num>7</num>
              <content>
                <p>Paragraph (6)(a) does not limit the advice to which <role refersTo="#commissioner">the Commissioner</role> may have regard.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-8">
              <num>8</num>
              <content>
                <p>If <role refersTo="#commissioner">the Commissioner</role> is aware that there are reasonable grounds to believe that the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities, a direction under subsection (1) may also require the statement referred to in paragraph (1)(a) to set out the identity and contact details of those other entities.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-9">
              <num>9</num>
              <content>
                <p>If an entity normally communicates with a particular individual using a particular method, the notification to the individual mentioned in paragraph (2)(a) or (b) may use that method. This subsection does not limit paragraph (2)(a) or (b).</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WR__subclause-10">
              <num>10</num>
              <content>
                <p>An entity must comply with a direction under subsection (1) as soon as practicable after the direction is given.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WS">
            <num>26WS</num>
            <heading>Exception—enforcement related activities</heading>
            <content>
              <p>An entity is not required to comply with a direction under subsection 26WR(1) if:</p>
            </content>
            <paragraph eId="schedule-1__clause-26WS__para-a">
              <num>a</num>
              <content>
                <p>the entity is an enforcement body; and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WS__para-b">
              <num>b</num>
              <content>
                <p>the chief executive officer of the enforcement body believes on reasonable grounds that compliance with the direction would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, the enforcement body.</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-26WT">
            <num>26WT</num>
            <heading>Exception—inconsistency with secrecy provisions</heading>
            <content>
              <p>Secrecy provisions</p>
              <p>Prescribed secrecy provisions</p>
              <p>are taken not to be provisions that require or authorise the use or disclosure of information.</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-26WT__subclause-1">
              <num>1</num>
              <content>
                <p>	(1)	For the purposes of this section, <b><i>secrecy provision</i></b> means a provision that:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WT__para-a">
              <num>a</num>
              <content>
                <p>is a provision of a law of the Commonwealth (other than this Act); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WT__para-b">
              <num>b</num>
              <content>
                <p>prohibits or regulates the use or disclosure of information.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WT__subclause-2">
              <num>2</num>
              <content>
                <p>If compliance by an entity with paragraph 26WR(1)(b) or subsection 26WR(2) in relation to a statement would, to any extent, be inconsistent with a secrecy provision (other than a prescribed secrecy provision), paragraph 26WR(1)(b) or subsection 26WR(2), as the case may be, does not apply to the entity, in relation to the statement, to the extent of the inconsistency.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WT__subclause-3">
              <num>3</num>
              <content>
                <p>	(3)	For the purposes of this section, <b><i>prescribed secrecy provision</i></b> means a secrecy provision that is specified in the regulations.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-26WT__subclause-4">
              <num>4</num>
              <content>
                <p>For the purposes of a prescribed secrecy provision:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-26WT__para-a">
              <num>a</num>
              <content>
                <p>paragraph 26WR(1)(b); and</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-26WT__para-b">
              <num>b</num>
              <content>
                <p>subsection 26WR(2);</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-26WT__subclause-5">
              <num>5</num>
              <content>
                <p>If compliance by an entity with paragraph 26WR(1)(b) or subsection 26WR(2) in relation to a statement would, to any extent, be inconsistent with a prescribed secrecy provision, paragraph 26WR(1)(b) or subsection 26WR(2), as the case may be, does not apply to the entity in relation to the statement.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-4">
            <num>4</num>
            <heading>After paragraph 96(1)(b)</heading>
            <content>
              <p>Insert:</p>
            </content>
            <paragraph eId="schedule-1__clause-4__para-ba">
              <num>ba</num>
              <content>
                <p>a decision under subsection 26WQ(7) to refuse an application for a declaration;</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-4__para-bb">
              <num>bb</num>
              <content>
                <p>a decision to make a declaration under paragraph 26WQ(1)(d);</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-4__para-bc">
              <num>bc</num>
              <content>
                <p>a decision under subsection 26WR(1) to give a direction;</p>
              </content>
            </paragraph>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-5">
            <num>5</num>
            <heading>After subsection 96(2)</heading>
            <content>
              <p>Insert:</p>
            </content>
            <hcontainer name="subclause" eId="schedule-1__clause-5__subclause-2A">
              <num>2A</num>
              <content>
                <p>An application under paragraph (1)(ba) may only be made by:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-5__para-a">
              <num>a</num>
              <content>
                <p>the entity that made the application for a declaration; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-5__para-b">
              <num>b</num>
              <content>
                <p>if another entity’s compliance with subsection 26WL(2) is affected by the decision to refuse the application for a declaration—that other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-5__subclause-2B">
              <num>2B</num>
              <content>
                <p>An application under paragraph (1)(bb) may only be made by:</p>
              </content>
            </hcontainer>
            <paragraph eId="schedule-1__clause-5__para-a">
              <num>a</num>
              <content>
                <p>the entity to whom notice of the declaration was given; or</p>
              </content>
            </paragraph>
            <paragraph eId="schedule-1__clause-5__para-b">
              <num>b</num>
              <content>
                <p>if another entity’s compliance with subsection 26WL(2) is affected by the declaration—that other entity.</p>
              </content>
            </paragraph>
            <hcontainer name="subclause" eId="schedule-1__clause-5__subclause-2C">
              <num>2C</num>
              <content>
                <p>An application under paragraph (1)(bc) may only be made by the entity to whom the direction was given.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-5__subclause-2D">
              <num>2D</num>
              <content>
                <p>	(2D)	For the purposes of subsections (2A), (2B) and (2C), <b><i>entity </i></b>has the same meaning as in Part IIIC.</p>
              </content>
            </hcontainer>
          </hcontainer>
          <hcontainer name="clause" eId="schedule-1__clause-6">
            <num>6</num>
            <heading>Application of amendments—eligible data breaches</heading>
            <hcontainer name="subclause" eId="schedule-1__clause-6__subclause-1">
              <num>1</num>
              <content>
                <p>(1)	Paragraph 26WE(2)(a) of the <i>Privacy Act 1988</i> (as amended by this Schedule) applies to an access or disclosure that happens after the commencement of this item.</p>
              </content>
            </hcontainer>
            <hcontainer name="subclause" eId="schedule-1__clause-6__subclause-2">
              <num>2</num>
              <content>
                <p>(2)	Paragraph 26WE(2)(b) of the <i>Privacy Act 1988</i> (as amended by this Schedule) applies to a loss that happens after the commencement of this item.</p>
              </content>
            </hcontainer>
            <content>
              <p>[<i>Minister’s second reading speech made in—</i></p>
              <p>
                <i>House of Representatives on 19 October 2016</i>
              </p>
              <p><i>Senate on 8 February 2017</i>]</p>
              <p>(158/16)</p>
            </content>
          </hcontainer>
        </hcontainer>
      </attachment>
    </attachments>
  </act>
</akomaNtoso>
