Who must comply with Data Availability and Transparency Act 2022?
The applicability test for Data Availability and Transparency Act 2022, computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Specialised
Applies to Commonwealth data custodians and accredited users only. The Rules Mate questionnaire does not treat this as an obligation for an ordinary business.
What the obligation is
Commonwealth data sharing regime — accredited users + entities.
The Data Availability and Transparency Act 2022 creates the DATA Scheme, administered by the Office of the National Data Commissioner, which authorises Commonwealth bodies to share public sector data with accredited users for permitted purposes, overriding other Commonwealth, state or territory secrecy laws where the scheme's safeguards are met; it does not override the Privacy Act 1988. There are three participant types: Data Custodians (Commonwealth bodies that control public sector data, automatically in the scheme), Accredited Users and Accredited Data Service Providers (Commonwealth, state and territory government bodies and Australian universities, which must apply). Sharing happens under a registered data sharing agreement, usually managed in Dataplace; projects involving complex data integration must use an accredited data service provider. Foreign entities cannot access scheme data, and under s 143 the Act sunsets five years after commencement.
The applicability test
Applies to Commonwealth data custodians and accredited users only. The Rules Mate questionnaire does not treat this as an obligation for an ordinary business.
How the regulator frames it: Commonwealth government bodies that hold public sector data (as Data Custodians), and Commonwealth, state and territory bodies and Australian universities accredited as users or data service providers, together with their staff and contractors who handle scheme data. Private companies cannot be accredited, although they may use scheme data under an approved contract with an accredited entity.
What triggers it: Receiving a data sharing request from an Accredited User, applying for accreditation, or entering a data sharing agreement under the scheme.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Applies to Commonwealth data custodians and accredited users only.
What you must do, and when
- When due
- Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.
- Frequency
- Ongoing
- Evidence to keep
- Register of data sharing requests received and the reasons for agreeing or refusing; registered data sharing agreements (prohibiting offshore storage or access where personal information is shared, and re-identification of de-identified data); accreditation decisions and conditions; change-of-circumstance notices; records of staff and contractor access to scheme data.
- Status
- Current
- Priority
- Medium
Penalty for not complying
Maximum penalty: Civil penalty of 300 penalty units ($109,200) for unauthorised sharing, collection or use of scheme data, rising to 600 penalty units ($218,400) for a serious contravention by an accredited entity (Data Availability and Transparency Act 2022 ss 14-14A); 300 penalty units for breaching accreditation conditions or failing to notify relevant changes (ss 30-31). Criminal offences also apply to unauthorised sharing.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Where it sits in the corpus
Rules Mate tracks 2 published obligations tagged "data governance", 0 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated medium priority, and is an ongoing duty.
Regulator, legislation and tools
Data Availability and Transparency Act 2022: Commonwealth data sharing regime — accredited users + entities + Data Code requirements.
Free tools that help with this obligation:
Questions
- Who must comply with Data Availability and Transparency Act 2022?
- Applies to Commonwealth data custodians and accredited users only. The Rules Mate questionnaire does not treat this as an obligation for an ordinary business.
- Does Data Availability and Transparency Act 2022 apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does Data Availability and Transparency Act 2022 apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "Data Availability and Transparency Act 2022" due?
- Data Custodians must consider and respond to every request received; accredited entities must comply with their accreditation conditions continuously and notify the Commissioner in writing of relevant events or changes in circumstance; reporting to the Commissioner supports the annual report.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.