Skip to main content
Rules Mate

Data Availability and Transparency Act 2022

Commonwealth data sharing regime — accredited users + entities.

mediumcurrentongoing

Who must comply

Commonwealth government bodies that hold public sector data (as Data Custodians), and Commonwealth, state and territory bodies and Australian universities accredited as users or data service providers, together with their staff and contractors who handle scheme data. Private companies cannot be accredited, although they may use scheme data under an approved contract with an accredited entity.

What triggers it

Receiving a data sharing request from an Accredited User, applying for accreditation, or entering a data sharing agreement under the scheme.

When due

Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.

Evidence required

Register of data sharing requests received and the reasons for agreeing or refusing; registered data sharing agreements (prohibiting offshore storage or access where personal information is shared, and re-identification of de-identified data); accreditation decisions and conditions; change-of-circumstance notices; records of staff and contractor access to scheme data.

Max penalty

Civil penalty of 300 penalty units ($109,200) for unauthorised sharing, collection or use of scheme data, rising to 600 penalty units ($218,400) for a serious contravention by an accredited entity (Data Availability and Transparency Act 2022 ss 14-14A); 300 penalty units for breaching accreditation conditions or failing to notify relevant changes (ss 30-31). Criminal offences also apply to unauthorised sharing.

Summary

The Data Availability and Transparency Act 2022 creates the DATA Scheme, administered by the Office of the National Data Commissioner, which authorises Commonwealth bodies to share public sector data with accredited users for permitted purposes, overriding other Commonwealth, state or territory secrecy laws where the scheme's safeguards are met; it does not override the Privacy Act 1988. There are three participant types: Data Custodians (Commonwealth bodies that control public sector data, automatically in the scheme), Accredited Users and Accredited Data Service Providers (Commonwealth, state and territory government bodies and Australian universities, which must apply). Sharing happens under a registered data sharing agreement, usually managed in Dataplace; projects involving complex data integration must use an accredited data service provider. Foreign entities cannot access scheme data, and under s 143 the Act sunsets five years after commencement.

Source legislation

Topics

data-governanceprivacypublic-sector

Related

Frequently asked questions

Who must comply with Data Availability and Transparency Act 2022?
Commonwealth government bodies that hold public sector data (as Data Custodians), and Commonwealth, state and territory bodies and Australian universities accredited as users or data service providers, together with their staff and contractors who handle scheme data. Private companies cannot be accredited, although they may use scheme data under an approved contract with an accredited entity.
What triggers Data Availability and Transparency Act 2022?
Receiving a data sharing request from an Accredited User, applying for accreditation, or entering a data sharing agreement under the scheme.
When is Data Availability and Transparency Act 2022 due?
Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.
What is the maximum penalty for Data Availability and Transparency Act 2022?
Civil penalty of 300 penalty units ($109,200) for unauthorised sharing, collection or use of scheme data, rising to 600 penalty units ($218,400) for a serious contravention by an accredited entity (Data Availability and Transparency Act 2022 ss 14-14A); 300 penalty units for breaching accreditation conditions or failing to notify relevant changes (ss 30-31). Criminal offences also apply to unauthorised sharing.
What evidence is required for Data Availability and Transparency Act 2022?
Register of data sharing requests received and the reasons for agreeing or refusing; registered data sharing agreements (prohibiting offshore storage or access where personal information is shared, and re-identification of de-identified data); accreditation decisions and conditions; change-of-circumstance notices; records of staff and contractor access to scheme data.

Source: https://www.datacommissioner.gov.au/data-scheme/how-scheme-operates. Rules Mate is not a law firm. Always verify against the live regulator source before acting.