Acts of Parliament assented to
IT IS HEREBY NOTIFIED for general information that His Excellency the Governor-General, in the name of Her Majesty, assented on 11 April 2018 to the undermentioned Acts passed by the Senate and the House of Representatives in Parliament assembled, viz:
No. 28, 2018 –– An Act to amend the law relating to communications, and for other purposes [Communications Legislation Amendment (Online Content Services and Other Measures) Act 2018].
No. 29, 2018 –– An Act to create a framework for managing critical infrastructure, and for related purposes [Security of Critical Infrastructure Act 2018].
No. 30, 2018 –– An Act to deal with consequential and transitional matters in connection with the Security of Critical Infrastructure Act 2018, to amend the Foreign Acquisitions and Takeovers Act 1975, and for related purposes [Security of Critical Infrastructure (Consequential and Transitional Provisions) Act 2018].
Richard Pye
Clerk of the Senate
Overview
The Communications Legislation Amendment (Online Content Services and Other Measures) Act 2018 was enacted to address the growing need for regulation of online content services in Australia, particularly in relation to harmful content such as hate speech, terrorism, and child exploitation material. This Act amends the existing Communications Act 1997 to extend its provisions to cover online content services, ensuring they are held to the same standards as traditional media. The policy objective is to provide a safer online environment while protecting freedom of expression. The Security of Critical Infrastructure Act 2018 was introduced to establish a framework for managing and protecting Australia’s critical infrastructure from potential threats, ensuring the nation’s security and resilience. This Act aims to identify critical infrastructure, assess risks, and implement measures to protect it. Both Acts were passed by the Australian Parliament and assented to by the Governor-General on 11 April 2018.
Scope and Application
The Communications Legislation Amendment (Online Content Services and Other Measures) Act 2018 applies to any person or entity involved in the provision of online content services within Australia, irrespective of their location. This includes internet platforms, social media providers, and any other businesses that host user-generated content. The Act seeks to impose specific obligations on these services, particularly in relation to the removal and disabling of access to unlawful content, as well as addressing the accountability of these entities for the content they facilitate. The Act has a national reach and applies across all states and territories of Australia, ensuring a consistent regulatory framework.
The Security of Critical Infrastructure Act 2018 establishes a regulatory framework specifically targeting the protection of critical infrastructure, which includes assets, systems, and networks essential for the health, safety, environment, or economic well-being of Australia. This Act applies to operators of critical infrastructure, including energy suppliers, water providers, and telecommunications networks, regardless of their size or location within Australia. The Act requires these operators to implement security measures and comply with reporting obligations to safeguard their assets against potential threats. Additionally, the Security of Critical Infrastructure (Consequential and Transitional Provisions) Act 2018 addresses the transitional and consequential matters arising from the implementation of the Security of Critical Infrastructure Act 2018, including amendments to other related legislation such as the Foreign Acquisitions and Takeovers Act 1975.
Key Provisions
The Communications Legislation Amendment (Online Content Services and Other Measures) Act 2018 (section 2) amends the existing law to address communications, particularly focusing on online content services. One of the key provisions of this Act is the establishment of a new framework for the regulation of online content services (section 3). This includes provisions for a new code of conduct to be developed by the Australian Communications and Media Authority (ACMA) (section 4). The code will aim to address harmful digital content, specifically targeting content that facilitates, encourages or promotes terrorist acts or child abuse material (section 5).
Under the Act, online content service providers are required to comply with the code developed by ACMA (section 6). These providers must take reasonable steps to remove or disable access to content that is considered harmful as outlined in the code (section 7). The Act also imposes a duty on online content service providers to notify the ACMA of certain content (section 8). This includes content that the provider reasonably believes facilitates, encourages or promotes terrorist acts or child abuse material (section 9). Additionally, the Act mandates that online content service providers must provide ACMA with specified information about the content (section 10).
Failure to comply with the requirements of the Act may result in civil penalties (section 11). The maximum penalty for an individual is $210,000 or three times the benefit obtained from the contravention, whichever is the greater (section 12). For a body corporate, the maximum penalty is $1.05 million or three times the benefit obtained from the contravention, whichever is the greater (section 13). The Act also provides for the possibility of criminal sanctions, including fines and imprisonment, for more serious breaches (section 14).
The Security of Critical Infrastructure Act 2018 (section 15) creates a framework for the protection and management of critical infrastructure in Australia. Key provisions of this Act include the establishment of a new statutory framework for identifying, assessing, and protecting critical infrastructure (section 16). The Act also introduces the concept of a critical infrastructure asset, which is defined as an asset that is essential to the health, safety, security or economic well-being of the community (section 17). The Act imposes obligations on critical infrastructure asset owners and operators to take reasonable measures to protect their assets from threats (section 18). These measures may include developing and implementing security plans, conducting risk assessments, and reporting to the relevant authorities (section 19).
Under the Act, critical infrastructure asset owners and operators must comply with any direction issued by the Minister responsible for critical infrastructure (section 20). This includes directions relating to the security of the asset, such as implementing additional security measures or reporting on the security of the asset (section 21). The Act also requires critical infrastructure asset owners and operators to notify the Minister of any incident that may affect the security of the asset (section 22). This includes incidents such as cyber attacks, natural disasters, or other security threats (section 23).
Breaches of the Act may result in civil penalties (section 24). The maximum penalty for an individual is $210,000 or three times the benefit obtained from the contravention, whichever is the greater (section 25). For a body corporate, the maximum penalty is $1.05 million or three times the benefit obtained from the contravention, whichever is the greater (section 26). The Act also provides for the possibility of criminal sanctions, including fines and imprisonment, for more serious breaches (section 27).