Data Availability and Transparency Act 2022
Commonwealth data sharing regime — accredited users + entities.
Who must comply
Commonwealth government bodies that hold public sector data (as Data Custodians), and Commonwealth, state and territory bodies and Australian universities accredited as users or data service providers, together with their staff and contractors who handle scheme data. Private companies cannot be accredited, although they may use scheme data under an approved contract with an accredited entity.
What triggers it
Receiving a data sharing request from an Accredited User, applying for accreditation, or entering a data sharing agreement under the scheme.
When due
Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.
Evidence required
Register of data sharing requests received and the reasons for agreeing or refusing; registered data sharing agreements (prohibiting offshore storage or access where personal information is shared, and re-identification of de-identified data); accreditation decisions and conditions; change-of-circumstance notices; records of staff and contractor access to scheme data.
Max penalty
Civil penalty of 300 penalty units ($109,200) for unauthorised sharing, collection or use of scheme data, rising to 600 penalty units ($218,400) for a serious contravention by an accredited entity (Data Availability and Transparency Act 2022 ss 14-14A); 300 penalty units for breaching accreditation conditions or failing to notify relevant changes (ss 30-31). Criminal offences also apply to unauthorised sharing.
Summary
The Data Availability and Transparency Act 2022 creates the DATA Scheme, administered by the Office of the National Data Commissioner, which authorises Commonwealth bodies to share public sector data with accredited users for permitted purposes, overriding other Commonwealth, state or territory secrecy laws where the scheme's safeguards are met; it does not override the Privacy Act 1988. There are three participant types: Data Custodians (Commonwealth bodies that control public sector data, automatically in the scheme), Accredited Users and Accredited Data Service Providers (Commonwealth, state and territory government bodies and Australian universities, which must apply). Sharing happens under a registered data sharing agreement, usually managed in Dataplace; projects involving complex data integration must use an accredited data service provider. Foreign entities cannot access scheme data, and under s 143 the Act sunsets five years after commencement.
Source legislation
Topics
Related
- CWLTHPrivacy Act Reform — information controllers regime (proposed Tranche 2)Tranche 2 reforms in scoping — information controllers + processors regime.
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHAPP 3 collection of sensitive informationAPP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- CWLTHAutomated decision-making transparency in your privacy policy (APP 1.7–1.9)From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
- CWLTHProtective Security Policy Framework (PSPF)Federal entities bound by PSPF — governance, information, personnel + physical security.
- CWLTHPrepare for the proposed removal of the small business exemptionRemoving the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
Frequently asked questions
- Who must comply with Data Availability and Transparency Act 2022?
- Commonwealth government bodies that hold public sector data (as Data Custodians), and Commonwealth, state and territory bodies and Australian universities accredited as users or data service providers, together with their staff and contractors who handle scheme data. Private companies cannot be accredited, although they may use scheme data under an approved contract with an accredited entity.
- What triggers Data Availability and Transparency Act 2022?
- Receiving a data sharing request from an Accredited User, applying for accreditation, or entering a data sharing agreement under the scheme.
- When is Data Availability and Transparency Act 2022 due?
- Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.
- What is the maximum penalty for Data Availability and Transparency Act 2022?
- Civil penalty of 300 penalty units ($109,200) for unauthorised sharing, collection or use of scheme data, rising to 600 penalty units ($218,400) for a serious contravention by an accredited entity (Data Availability and Transparency Act 2022 ss 14-14A); 300 penalty units for breaching accreditation conditions or failing to notify relevant changes (ss 30-31). Criminal offences also apply to unauthorised sharing.
- What evidence is required for Data Availability and Transparency Act 2022?
- Register of data sharing requests received and the reasons for agreeing or refusing; registered data sharing agreements (prohibiting offshore storage or access where personal information is shared, and re-identification of de-identified data); accreditation decisions and conditions; change-of-circumstance notices; records of staff and contractor access to scheme data.
Source: https://www.datacommissioner.gov.au/data-scheme/how-scheme-operates. Rules Mate is not a law firm. Always verify against the live regulator source before acting.