Aviation Transport Security (Incident Reporting) Instrument 2026

Administered by Department of Home Affairs

Legislation au F2026L00385 In force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Issued by authority of the Secretary of the Department of Home Affairs

 

Aviation Transport Security Act 2004

 

Aviation Transport Security (Incident Reporting) Instrument 2026

 

Legislative authority

 

The Aviation Transport Security Act 2004 (the Act) establishes a regulatory framework to safeguard against unlawful interference with aviation transport in Australia. The Act gives effect to Australia’s obligations under Annex 17 to the Convention on International Civil Aviation and establishes minimum security requirements for aviation transport in Australia by imposing obligations on persons engaged in aviation-related activities. These obligations include the reporting of any aviation security incidents or cyber security incidents to the Department of Home Affairs and the Australian Signals Directorate (ASD).

 

The Act is the legislative authority for reporting incidents. Specifically, Part 6 of the Act establishes the requirement to report aviation security incidents, including cyber security incidents). Within Part 6, subsection 107(1) of the Act provides that the Secretary may, by legislative instrument, specify the information that must be included in a report required by Part 6 of the Act and the way in which the report must be made.

 

Subsection 33(3) of the Acts Interpretation Act 1901 provides that, where an Act confers a power to make, grant or issue any instrument of a legislative or administrative character (including rules, regulations or by-laws), the power shall be construed as including a power exercisable in the like manner and subject to the like conditions (if any) to repeal, rescind, revoke, amend or vary any such instrument.

 

Background

 

Part 6 of the Act establishes the requirement to report aviation security incidents and cyber security incidents.

 

Section 99 defines an aviation security incident as both a threat of unlawful interference with aviation and an unlawful interference with aviation.

 

Section 9B defines a cyber security incident to mean one or more acts, events or circumstances involving unauthorised access to, or modification of computer data or a computer program, or unauthorised impairment of electronic communication to or from a computer, or unauthorised impairment of the availability, reliability, security or operation of a computer, computer data or a computer program.

Reporting obligations for airport operators

 

Subsection 100(4) provides that airport operators must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of an aviation asset to the Secretary of the Department of Home Affairs (the Secretary) and the ASD within 12 hours after becoming aware of the incident.

 

Subsection 100(5) provides that airport operators must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of an aviation asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.

 

Subsection 104(1) provides that airport operators must report aviation security incidents, other than a cyber security incident, in accordance with section 104. In particular, paragraph 104(4)(a) provides that an aviation security incident that relates to the airport of the airport operator must be reported to the Secretary.

 

Reporting obligations for aircraft operators

 

Subsection 101(4) provides that aircraft operators must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of an aviation asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.

 

Subsection 101(5) provides that aircraft operators must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of an aviation asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.

 

Subsection 105(1) provides that aircraft operators must report aviation security

incidents, other than a cyber security incident in accordance with section 105. Paragraph 105(4)(a) provides that an aviation security incident that relates to an aircraft of the aircraft operator must be reported to the Secretary.

 

Reporting obligations for other persons with incident reporting obligations

 

Subsection 102(3A) provides that other persons with incident reporting responsibilities must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of an aviation asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.

 

Subsection 102(3B) provides that other persons with incident reporting responsibilities must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of an aviation asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.

 

Subsection 106(2) provides that other persons with incident reporting responsibilities

(identified in subsection 102(4)) must also report aviation security incidents, other than cyber security incidents to the Secretary.

 

Form and information requirements of security incident and cyber security incident reports

 

Section 107 outlines how reports are to be made. Subsection 107(1) provides that the Secretary may, by legislative instrument, specify the information that must be included in a report required by Part 6 of the Act and the way in which the report must be made.

 

Subsection 107(3) provides that if a report is made under Part 6 of the Act and the report does not comply with the requirements of the legislative instrument made under subsection 107(1), then that report is taken not to have been made.

 

Purpose and effect

 

The Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025 (the TSA Act) commenced on 28 March 2025. The TSA Act introduced the requirement for certain persons engaged in aviation-related activities to report cyber security incidents that have had, are having, or are likely to have a significant or relevant impact on an aviation asset. Industry participants are required to submit reports to the Department of Home Affairs and the ASD within specific timeframes from when they become aware of the incident.

 

The purpose of the Aviation Transport Security (Incident Reporting) Instrument 2026 (the Instrument) is to introduce new requirements and methods of incident reporting for cyber security incidents, while substantially replicating the existing requirements and methods of incident reporting for other aviation security incidents.

 

The updated incident reporting requirements clarify the processes by which industry participants must submit aviation security incident reports and cyber security incident reports. The Instrument prescribes the information that must be included in reports to enable industry participants to comply effectively with the obligations imposed by the Act. The Instrument also ensures that the government receives reports in a form that is suitable for the intended purpose of gaining visibility of relevant incidents that have impacted the security or reliable operations of the transport sector. The reports assist the government in gaining greater insight into the threat landscape faced by the transport sector.

 

The Instrument repeals and replaces the Aviation Transport Security (Incident Reporting) Instrument 2018. The instrument was made by a delegate of the Secretary of the Department of Home Affairs.

 

Consultation

 

The Department has consulted with industry on cyber security incident reporting since 2024. Industry has been generally supportive and noted the benefit of reducing duplication of legislative requirements and reporting processes. Between May and July 2024, the Department of Home Affairs consulted industry regarding the reforms in the TSA Act. Most industry participants supported the proposal to incorporate cyber security incidents within the definition of unlawful interference and provided input into how the new reporting requirements could work in practice.

 

The Parliamentary Joint Committee on Intelligence and Security’s report on the TSA Act recommended that the Department identify and address any duplication of reporting requirements and facilitate coordinated and efficient reporting. To reduce legislative duplication and minimise administrative burden, the Department will establish processes to allow industry to satisfy its regulatory obligation to report to the ASD across multiple frameworks by making one cyber incident report to ASD. Following further consultation with industry in March 2026 on exposure drafts of the Instrument, industry remains supportive.

 

At the time of writing, the Australian Government is also developing a Single Reporting Portal for cyber security incidents, which once in operation, should allow for greater sharing of information made through a single report.

 

Details and operations

 

Details of the Instrument are set out in Attachment A.

 

The Instrument is a Disallowable Legislative Instrument under section 42 of the Legislation Act 2003.

 

The Instrument commences on 27 March 2026.

 

Other matters

 

A Statement of Compatibility with Human Rights has been prepared in relation to the Instrument and is at Attachment B.

Attachment A

 

Details of the Aviation Transport Security (Incident Reporting) Instrument 2026

 

Section 1  Name

 

Section 1 provides that the name of the instrument is the Aviation Transport Security (Incident Reporting) Instrument 2026 (the Instrument).

 

Section 2  Commencement

 

Section 2 provides that the Instrument commences on the later of the day after it is registered, and commencement of Part 1 of Schedule 1 to the Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025.  The effect of this is where that Part commences at a later time, the Instrument commences immediately after the commencement of that Part.

 

Section 3  Authority

 

Section 3 provides that the authority to make the Instrument is subsection 107(1) of the Aviation Transport Security Act 2004 (the Act).

 

Section 4  Definitions

 

Section 4 provides the meaning for defined terms used in the Instrument.

 

The note at the start of section 4 provides that certain definitions used in the Instrument, being the definitions of ‘aircraft’, ‘aviation industry participant’, ‘aviation security incident’, ‘cyber security incident’, ‘in flight’, ‘relevant impact’, ‘significant impact’, and ‘unlawful interference with aviation’ are defined in the Act.

 

The term Act means the Aviation Transport Security Act 2004.

 

The term cyber security incident report means a report required to be made to the Secretary under Part 6 of the Act for a cyber security incident.

 

The term Department means the Department of Home Affairs.

 

The term industry participant means an aviation industry participant.

 

The term relevant cyber security incident means a cyber security incident that has a relevant impact.

 

The term security incident means an aviation security incident.

 

The term security incident report means a report required to be made to the Secretary under Part 6 of the Act for a security incident.

 

The term significant cyber security incident means a cyber security incident that has a significant impact.

 

The term unlawful interference means unlawful interference with aviation.

Section 5  Schedules

 

Section 5 provides that each instrument that is specified in a Schedule to the Instrument is amended or repealed as set out in the applicable items in the Schedule concerned and that any other item in a Schedule to the Instrument has effect according to its terms.

 

Section 6  Information that must be included in a security incident report

 

Section 6 sets out the way a security incident report is to be made. In doing so, it substantially replicates section 6 of the Aviation Transport Security (Incident Reporting) Instrument 2018 (the Previous Instrument).

 

Subsection 6(1) provides that this section specifies, for the purposes of paragraph 107(1)(a) of the Act, the information that must be included in a security incident report.

 

Subsection 6(2) prescribes the information that must be included in every security incident report. This includes:

  • the name, contact number, and email address of the person making the report;
  • the title or position held by the person making the report;
  • the name of the employer of the person making the report (where applicable);
  • the date of the report;
  • the date and time the security incident commenced;
  • the date and time the security incident ceased;
  • the location of the security incident (including, where applicable, the name and address of the location where the security incident occurred);
  • the industry participant or participants to whom the security incident relates;
  • the industry participant or participants who are affected as a result of the security incident;
  • whether the report is a result of a routine security inspection;
  • a detailed description of the security incident, including an indication as to whether the incident was a threat of unlawful interference or an unlawful interference;
  • the steps the industry participant has taken, or is in the process of taking, to ensure the security incident does not occur again; and
  • information set out in subsections (3), (4), (5), (6), (7) or (8), where those subsections apply.

 

The note clarifies the compliance position where an industry participant does not have the required information at the time of reporting under subsection 6(2). It draws the attention of the reader to subsection 7(2), which sets out requirements in relation to providing further information.

 

Subsection 6(3) prescribes the information that must be included in a report if the security incident was a threat of unlawful interference. This includes:

  • the name and contact details of the person who received the threat;
  •  the details of the threat;
  •  whether the threat is assessed as genuine or as a hoax and how that assessment was made; and
  •  whether the person who made the threat attempted, is in the process of committing, completed, or failed in the act of unlawful interference.

 

Subsection 6(4) prescribes the information that must be included if the security incident involves or involved an aircraft. This includes:

  • the aircraft type;
  •  the flight number;
  •  whether or not the aircraft was in flight at the time of the security incident; and
  • the type of cargo on board if applicable.

 

Subsection 6(5) prescribes the information that must be included if the security incident involved a building or other infrastructure.  This information includes a building number or other identifier that could sufficiently identify the building or other infrastructure.

 

Subsection 6(6) prescribes the information that must be provided where the security incident has previously been reported to the Secretary. This includes the approximate time and date of the earlier report, and the name or position of the person, or the name of the area within the Department, to whom the incident was reported.

 

Subsection 6(7) prescribes the information that must be included if the security incident has been previously reported to the police, an industry participant, or any other body. This includes the approximate time and date of the report, and the name and contact information of the person the incident was reported to or a relevant engagement identifier such as a case number, incident report number or other relevant identifier.

 

Subsection 6(8) prescribes the information that must be included if the security incident has been brought to the attention of an industry participant by a third party. This includes a statement indicating that the report is being made because of a notification from a third party, and the name of that third party, as well as the name of their employer where applicable.

 

The purpose of section 6 of the Instrument is to ensure the information contained in any security incident reports assists the Department of Home Affairs (the Department) to capture and efficiently monitor security incidents.

 

The security incident reports also provide information to enable the Australian Government to comply with its international obligations to report aviation security incidents to the International Civil Aviation Organization.

 

Section 7  Way in which a security incident report is to be made

 

Section 7 substantially replicates section 7 of the Previous Instrument and sets out the manner in which a security incident report is to be made.

 

Subsection 7(1) specifies that once a security incident is identified, a security incident report must be made to the Secretary no later than 24 hours after the industry participant first becomes aware of the incident.

 

Subsection 7(2) specifies that if an industry participant does not have any or part of the information required by section 6 for the making of a security incident report, but later attains it, this information must be passed on to the Secretary , and this must be done no later than 24 hours after obtaining the information.

 

The purpose of subsection 7(2) is to ensure that the Secretary cannot penalise an industry participant for failing to include information in a security incident report that was not known to them at the time of the initial report. The provision also recognises the need for that information be provided to the Secretary promptly once that information becomes available.

 

Subsection 7(3) specifies that a security incident report can be made either orally via the phone on 1300 791 581, online via the Department’s security incident reporting form at https://www.homeaffairs.gov.au/about/transport-security/security-incident-reporting/aviation-security-incident-report-form or by email to transport.security@homeaffairs.gov.au.

 

Subsection 7(4) specifies that if a security incident report is made orally, the report must also be made in writing through the online form in paragraph 3(b) or by email in paragraph 3(c) within 24 hours after the security incident report is made orally, and must contain the information required under section 6.

 

Section 8  Notification of a cyber security incident report

 

Subsection 8(1) specifies, for the purposes of paragraph 107(1) of the Act, the requirements that a cyber security incident report must satisfy.

 

Subsection 8(2) sets out the information that must be included in a cyber security incident report:

  • the name, contact number, and email address of the person making the report;
  • the name of the employer of the person making the report;
  • the state or territory and postcode of the employer of the person making the report;
  • the date and time the incident was identified;
  • whether the incident is ongoing;
  • the nature or type of cyber security incident that is occurring or has occurred; and
  • a detailed description of the cyber security incident that is occurring or has occurred.

 

The note clarifies the compliance position where an industry participant does not have the required information at the time of reporting under subsection 8(2). It draws the reader’s attention to subsection 9(4), which sets out requirements in relation to providing further information in the way specified under that subsection.

 

Section 9 Way in which a cyber security incident report is made

 

Subsection 9(1) provides that a cyber security incident report must be submitted online via the Australian Cyber Security Centre’s portal at https://www.cyber.gov.au/report-and-recover/report.

 

Subsection 9(2) provides that where a cyber security incident report is made using the method set out in subsection (1), and consent is not given to share the report with the Secretary, the information must be submitted to the Secretary online via the Department’s form available at https://www.homeaffairs.gov.au/about/transport-security/security-incident-reporting/aviation-security-incident-report-form.

 

Subsection 9(3) provides that where information is submitted to the Secretary using the method in subsection (2), it must be provided as soon as possible and, in any event, within 12 hours of the industry participant becoming aware of a significant cyber security incident, or within 72 hours of becoming aware of a relevant cyber security incident, as prescribed by the Act.

 

Subsection 9(4) provides that if, at the time of making a cyber security incident report, the industry participant does not possess some or all of the information required under section 8 but subsequently obtains that information, the industry participant must provide it using the method set out in subsection (1) as soon as possible, and no later than 24 hours after obtaining it.

 

Subsection 9(5) provides that if information is given for the purposes of subsection (4) and consent is not given to share that information with the Secretary, the information must be submitted to the Secretary using the method in subsection (2) as soon as possible, and no later than 24 hours after it is obtained.

 

10  Reporting requirements—application

 

Section 10 provides that the Instrument applies to reports made in accordance with Division 4 of Part 6 of the Act on or after its commencement. It also applies to any additional information that must be provided to the Secretary in relation to a Division 4 report made before the Instrument commences.

 

The effect of this provision is that industry participants who reported a security incident (including cyber security incidents) according to the Previous Instrument will be able to provide further information in relation to that incident using the new general reporting procedures outlined in this Instrument. This preserves continuity and negates any need for industry participants to make new reports according to the Instrument for an incident that has already been reported on - for example, where the incident was a cyber security incident.

 

Schedule 1  Repeals

 

Item 1 of Schedule 1 to the Instrument has the effect of repealing the Previous Instrument, Aviation Transport Security (Incident Reporting) Instrument 2018.


ATTACHMENT B

 

Statement of Compatibility with Human Rights

 

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

 

Aviation Transport Security (Incident Reporting) Instrument 2026

 

The Disallowable Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

 

Overview of the Disallowable Legislative Instrument

The Aviation Transport Security Act 2004 (the Act) establishes a legislative framework that contains obligations aimed at protecting civil aviation in Australia from threats and unlawful interference. It achieves this by imposing minimum security requirements and reporting obligations on aviation industry participants. The Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025 (the TSA Act) commenced on 28 March 2025. The TSA Act introduced into the Act the requirement for certain persons engaged in aviation-related activities to report cyber security incidents that have had, are having, or are likely to have a significant or relevant impact on an aviation asset.

Part 6, Division 5 of the Act sets out the requirements for the form, content, and manner in which security and cyber security incident reports must be made. Specifically, section 107 provides that the Secretary of the Department of Home Affairs (Home Affairs), through a legislative instrument, may specify the precise information that the aviation industry participants must include in their reports, as well as the approved methods for submitting them. This ensures that reporting obligations remain clear, consistent, and responsive to operational and security needs.

Timely and accurate reporting of security incidents is essential to maintaining the safety, resilience, and integrity of Australia’s aviation sector. Incident reporting enables the early detection of emerging threats, supports coordinated responses across government, industry, and airport operators, and ensures that lessons learned from previous incidents can be used to strengthen aviation security arrangements. In recent years, rapid technological advancements and the increasing reliance on digital and networked systems across aviation operations have created new avenues for unlawful interference and security risks. Cyber incidents in particular now pose significant risks to the continuity, safety, and operational control of critical aviation systems and infrastructure.

The Aviation Transport Security (Incident Reporting) Instrument 2026 (ATSI) repeals and replaces the Aviation Transport Security (Incident Reporting) Instrument 2018. It introduces new requirements and methods of reporting for cyber security incidents, while substantially replicating the existing requirements and methods of incident reporting for aviation security incidents. The ATSI sets out the information that must be provided when aviation industry participants report aviation security incidents and cyber security incidents under Part 6 of the Act, and specifies the approved methods for submitting those reports. The ATSI provides clarity for industry participants in meeting their reporting obligations under the Act, while also ensuring relevance in the information provided to Home Affairs.

Updating the incident reporting framework through this instrument ensures that it remains responsive to modern security environments, captures both physical and cyber threats, and continues to provide government and industry with the information needed to protect Australia’s aviation network.

Human rights implications

The ATSI may engage the right to privacy in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).

Article 17 of the ICCPR provides:

1. No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.

2. Everyone has the right to the protection of the law against such interference or attacks.

Pursuant to Article 17(1) of the ICCPR, any interference with an individual’s privacy must have a lawful basis. Interference with privacy may be permissible provided that it is authorised by law and is not arbitrary. For an interference with the right to privacy not to be arbitrary, the interference must be for a reason consistent with the provisions, aims and objectives of the ICCPR and be reasonable in the particular circumstances. The United Nations Human Rights Committee has interpreted ‘reasonableness’ in this context to mean that ‘any interference with privacy must be proportional to the end sought and be necessary in the circumstances of any given case’. The term unlawful means that no interference can take place except as authorised under domestic law.

The ATSI may engage the right to privacy as it specifies information that must be included in security incident reports and cyber security incident reports and may involve (where applicable) the collection, use and disclosure of personal information. This includes the name, contact number, and email address of the person making the report. For security incident reports, it may also include the name and contact details of a person who received a threat of unlawful interference and where applicable, the names of the person to whom an incident has been previously reported, including police officers, or third parties (including employers of third parties) who have informed the reporter of the incident.

In such instances, any limitation on the right to privacy is for the legitimate objective of protecting Australia’s national security. The measure is rationally connected to that objective because these reports will help Australia to identify and mitigate security and cyber security risks that are a threat to Australia’s national security through the disruption of operations in aviation sector. The reports also allow for the provision of technical assistance for cyber security incidents, from the Australian Government, with consent, which can contribute to containing and limiting the consequences of cyber security incidents.

The reporting requirements in the ATSI are lawful, as they are authorised by subsection 107(1) of the Act. Any limitation on the right to privacy by the ATSI is also not arbitrary, as to the extent that personal information may be included in security or cyber security incident reports it is rationally connected to the objective of protecting Australia’s national security and is subject to the below safeguards.

The requirements in the ATSI ensure that any limitation on the right to privacy is no more restrictive than necessary. The use and disclosure of information recorded, made or used under the ATSI will be restricted to purposes authorised under the Act and the Australian Border Force Act 2015 (ABF Act). It is a criminal offence to use or disclose protected information other than as authorised under Part 6 of the ABF Act.

Reports are required to be made to Home Affairs and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) within specific timeframes from when the industry participant (IP) becomes aware of the incident. Cyber security incident reports are to be made online through the ACSC’s reporting portal. If the IP reporting the incident does not consent to sharing the cyber security incident report with Home Affairs, a separate report must be submitted to Home Affairs online within the specified timeframe. Non-cyber security incidents must be reported to Home Affairs orally via telephone, online via the Home Affairs website or by email.

All information collected on ASD’s ACSC’s portal is subject to limited use provisions in the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024. The limited use obligation intends to provide additional assurance that cyber security information voluntarily shared with ASD’s ACSC, or that is acquired or prepared by ASD’s ACSC with the consent of an impacted entity, is protected. Information protected by the limited use obligation cannot be used for regulatory action or admitted as evidence in civil or criminal proceedings against the impacted entity, except in certain circumstances. It is automatically applied and encourages proactive, timely and voluntary information sharing relating to cyber security incidents with the Australian Government.

The Australian Government is developing a Single Reporting Portal for cyber security incidents, which once in operation, should allow for greater sharing of information made through a single report.

Any limitation on the right to privacy that may arise through this measure is proportionate, as the information collected is subject to safeguards including through the ABF Act (that it may only be used to pursue the prevention, or minimisation, of the consequences of unlawful interference with aviation operations) and the Privacy Act 1998 (Privacy Act), and is the least restrictive option available to allow the government to assist an affected IP with its response and recovery.

Specific safeguards in the Privacy Act and the Australian Privacy Principles (APPs) contained in Schedule 1, apply when collecting personal information for a security incident report under the ATSI. Under APP3, only information reasonably necessary for aviation security functions may be collected. APP5 requires notifying individuals of the collection purpose unless an exemption such as the law‑enforcement exception applies. APP6 restricts further use or disclosure unless required by the Act’s reporting obligations in sections 102 and 103. APP 11 requires protecting security incident information from misuse, interference, loss, and unauthorised access.

Collecting personal information through a security or cyber security incident report is a necessary component of enabling government support throughout an IP’s response or recovery phase. It also contributes to the legitimate objective of preserving national security and the economic prosperity of Australia by minimising and mitigating the consequences of security and cyber security incidents on the aviation sector.

The information to be provided by an IP will be a high-level report of the incident within a specified period. Any personal information collected is consistent with the provisions, aims and objectives of the ICCPR and is reasonable in the circumstance of a security incident.

Any personal information included as part of the security incident report will only be in relation to the incident itself. This engagement is both necessary and proportionate to allow Home Affairs, or the ASD’s ACSC to appropriately understand and respond to a security incident.

Where the instrument requires the collection of personal information, such as the contact details of the person making the report or individuals involved in a threat, these requirements are reasonable, necessary, and proportionate to the legitimate objective of maintaining aviation security and managing transportrelated risks. The information required is limited to what is operationally necessary to identify, assess, and respond to incidents that may affect the aviation sector.

Conclusion

The ATSI is compatible with human rights because to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate to achieving a legitimate objective.

Matthew Pedler

Delegate of the Secretary of the Department of Home Affairs

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.