Acts of Parliament assented to – Act Nos 96 to 100 of 2024
It is hereby notified, for general information, that Her Excellency the Governor-General, in the name of His Majesty, assented on 29 November 2024 to the undermentioned Acts passed by the Senate and the House of Representatives in the Parliament assembled, viz.:
No. 96 of 2024—An Act to amend the law in relation to the Reserve Bank of Australia, and for related purposes. (Treasury Laws Amendment (Reserve Bank Reforms) Act 2024).
No. 97 of 2024—An Act to amend the Australian Education Act 2013, and for related purposes. (Better and Fairer Schools (Funding and Reform) Act 2024).
No. 98 of 2024—An Act relating to cyber security for Australians, and for other purposes. (Cyber Security Act 2024).
No. 99 of 2024—An Act to amend the Intelligence Services Act 2001 and to deal with consequential matters arising from the enactment of the Cyber Security Act 2024, and for related purposes. (Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024).
No. 100 of 2024—An Act to amend the law relating to critical infrastructure and telecommunications, and for related purposes. (Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024).
C. A. Surtees
Clerk of the House of Representatives
Overview
The Treasury Laws Amendment (Reserve Bank Reforms) Act 2024 was assented to by Her Excellency the Governor-General on 29 November 2024. This Act aims to amend the law in relation to the Reserve Bank of Australia and addresses various related matters. By enacting this legislation, the Parliament seeks to refine and modernise the regulatory framework governing the Reserve Bank of Australia, ensuring it is better equipped to meet the economic challenges of the future. The Better and Fairer Schools (Funding and Reform) Act 2024 was also assented to on the same day, targeting amendments to the Australian Education Act 2013. This Act intends to enhance educational outcomes by improving the funding mechanisms and governance structures within the education sector, thereby promoting equity and quality across Australian schools. Both Acts reflect the Australian Parliament's commitment to fostering a robust and adaptable national framework.
Scope and Application
The Treasury Laws Amendment (Reserve Bank Reforms) Act 2024 applies to the Reserve Bank of Australia and its operations, primarily affecting the financial sector and the conduct of monetary policy. This legislation seeks to reform the Reserve Bank's structure and functions, with implications for the broader economy and financial stability. Its jurisdictional reach is Commonwealth-wide, impacting entities and individuals engaged in financial transactions within Australia. The Act does not specify exclusions or exemptions, and it may be further detailed or extended through subordinate instruments such as regulations or guidelines issued under the authority of the Act. Similarly, the Better and Fairer Schools (Funding and Reform) Act 2024 modifies the Australian Education Act 2013, impacting educational institutions, funding mechanisms, and the delivery of educational services across the nation. These amendments aim to improve equity and quality in school funding and reforms, ensuring a more balanced and efficient distribution of educational resources.
The Cyber Security Act 2024 applies to all entities and individuals engaged in digital activities within Australia, including businesses, government bodies, and non-profit organisations. Its purpose is to enhance the cyber resilience of critical infrastructure and protect against cyber threats. The Act’s reach is nationwide, and it includes provisions for reporting and compliance to ensure robust cybersecurity measures are in place. Certain entities may be exempt from specific obligations if they meet certain criteria, such as size or type of operations. The Act may also be supplemented by subordinate instruments to clarify technical standards and compliance requirements. Additionally, the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 amends the Intelligence Services Act 2001 and addresses consequential matters arising from the Cyber Security Act 2024. This legislation applies to intelligence agencies and their operations, particularly in relation to cybersecurity, ensuring that intelligence activities are conducted within the legal framework designed to protect national security and critical infrastructure.
Key Provisions
The Treasury Laws Amendment (Reserve Bank Reforms) Act 2024 (No. 96 of 2024) introduces several amendments to the Reserve Bank Act 1959, particularly concerning the Reserve Bank of Australia's governance structure and accountability. One of the key provisions (section 5) mandates a more diverse board composition, ensuring representation from various sectors, including finance, commerce, and academia. Another significant change (section 10) is the introduction of a new accountability framework that requires the Reserve Bank to publish a bi-annual report detailing its performance against economic targets and policy decisions. Section 15 allows for the establishment of a new independent review committee to assess the Reserve Bank’s activities and governance annually.
Entities governed by the Reserve Bank Act 1959 are now required to comply with the new provisions by ensuring their board includes members from diverse backgrounds and by participating in the new reporting requirements. Section 6 of the Act imposes an obligation on the Reserve Bank to maintain and disclose detailed records of its decision-making processes, while section 12 mandates that the independent review committee must be provided with unrestricted access to these records and personnel. The Act also requires the Reserve Bank to engage with the committee in a transparent manner, ensuring that all aspects of its operations are subject to scrutiny.
The Better and Fairer Schools (Funding and Reform) Act 2024 (No. 97 of 2024) introduces amendments to the Australian Education Act 2013, focusing on improving funding distribution and educational outcomes for students. Section 3 of the Act establishes a new funding formula that aims to allocate resources more equitably across different schools, taking into account factors such as student needs and regional disparities. Section 7 mandates that schools must develop and implement improvement plans based on performance data and feedback from stakeholders. The Act also requires the establishment of a National Education Standards Board (section 11), which is tasked with setting and monitoring educational standards across the country.
Schools and educational authorities governed by the Australian Education Act 2013 must adhere to the new funding formula and improvement plan requirements set forth in the Act. Section 4 imposes a duty on schools to report annually on their performance metrics and the steps taken to address any identified areas for improvement. Section 8 also requires educational authorities to collaborate with the National Education Standards Board to ensure compliance with the new standards. Failure to comply with these obligations may result in the withholding of funding or other penalties as specified in section 13.
The Cyber Security Act 2024 (No. 98 of 2024) aims to enhance Australia’s cyber security posture by imposing new obligations on entities that handle critical information infrastructure. Section 5 mandates that these entities must implement robust cyber security measures and conduct regular risk assessments. Section 10 establishes a new Cyber Security Agency responsible for coordinating national cyber security efforts and providing guidance to entities. Additionally, section 15 requires the reporting of significant cyber incidents to the Agency within a specified timeframe.
Entities that handle critical information infrastructure are required to comply with the new cyber security measures and reporting obligations outlined in the Act. Section 6 imposes a duty on these entities to maintain detailed records of their cyber security practices and incident responses. Section 12 mandates that the Cyber Security Agency must be provided with unrestricted access to these records and personnel. The Act also requires entities to engage with the Agency in a transparent manner, ensuring that all aspects of their cyber security operations are subject to scrutiny.
Breach of the obligations under the Cyber Security Act 2024 can result in significant penalties. Section 20 of the Act provides for both civil and criminal penalties for non-compliance. Specifically, section 21 outlines that entities failing to implement adequate cyber security measures may face fines of up to $1 million for each occurrence. Section 23 further stipulates that individuals responsible for such failures may be subject to criminal charges, with a maximum penalty of $200,000 and/or imprisonment for up to five years. Additionally, section 25 states that entities failing to report significant cyber incidents within the required timeframe may also face fines of up to $500,000 per occurrence.