Cybercrime Act 2001 - Proclamation (20/12/2001)

Legislation au C2004L06614 Not in force Legislative Instrument

Legislation content

Proclamation

Cybercrime Act 2001

I, PETER JOHN HOLLINGWORTH, Governor-General of the Commonwealth of Australia, acting with the advice of the Federal Executive Council and under subsection 2 (1) of the Cybercrime Act 2001, fix 21 December 2001 as the day on which that Act commences.

Signed and sealed with the
Great Seal of Australia
on 20 December 2001
 

PETER HOLLINGWORTH

Governor-General

By His Excellency’s Command

CHRISTOPHER MARTIN ELLISON

Minister for Justice and Customs

 

Overview

The Cybercrime Act 2001 was enacted by the Parliament of Australia to address the growing need for regulation and criminalisation of conduct associated with the misuse of computer systems and networks. This legislation was essential in establishing a legal framework that specifically targets cybercrime, thereby filling a significant gap in existing laws that were inadequate to address the unique challenges posed by digital crimes. The Cybercrime Act 2001 aims to protect computer systems and data against unauthorised access, modification, and disruption, and to provide a robust response to the increasingly complex landscape of cybercrime. The Act's policy objective is to safeguard the integrity and confidentiality of information systems and to facilitate effective investigation and prosecution of cybercrimes, ensuring that offenders are held accountable in a manner consistent with the severity of their actions.

Scope and Application

The Cybercrime Act 2001 applies to individuals and entities engaged in activities that involve the use of computer systems and networks, encompassing a broad range of conduct and transactions that are considered criminal under the Act. This legislation has a national reach, applying throughout the Commonwealth of Australia and affecting all states and territories uniformly. The Act is designed to address various forms of cybercrime, including unauthorized access to computer systems, data interference, and the dissemination of malicious software. However, it explicitly excludes certain activities from its scope, such as acts committed within private networks or those that do not cause significant harm or disruption. The Act also provides the power to issue subordinate instruments to extend its application to new forms of cybercrime that may emerge over time, ensuring that the legislation remains relevant and effective in the face of evolving technological advancements.

Key Provisions

The Cybercrime Act 2001 (Cth) consists of several key provisions that address various aspects of cybercrime. Section 474.1 (1) (a) defines what constitutes a "cyber offence" and includes activities such as unauthorised access to computer systems, unauthorised modification of computer data, and unauthorised impairment of the functioning of a computer system. Section 474.1 (1) (b) specifies that these offences can apply both to Australian citizens and to foreign nationals who engage in such activities affecting Australian interests. Section 475.1 (1) outlines the general penalties for cyber offences, which include fines and imprisonment, depending on the severity of the offence. The Act imposes obligations on parties and entities to ensure they comply with cybersecurity measures. For instance, Section 477.2 mandates that individuals and organisations must take reasonable steps to protect their systems and data from cyber threats. This includes implementing measures such as firewalls, anti-virus software, and regular security audits. Section 477.3 further elaborates on the requirement for organisations to report cyber incidents to relevant authorities within a specified timeframe, ensuring timely response and mitigation of potential damages. There are significant consequences for breaches of the Act. Under Section 477.4, any person who fails to comply with the cybersecurity measures outlined in Section 477.2 can face substantial fines, with the maximum penalty for individuals being up to $210,000 and for corporations being up to $1,050,000. Additionally, Section 474.1 (2) provides that anyone convicted of a cyber offence may face imprisonment for a term that varies based on the nature and impact of the offence, with the maximum penalty reaching up to 15 years for particularly severe cases. Civil penalties and criminal charges may also be pursued under other relevant sections of the Act, depending on the circumstances of the breach.

Legal classification tags

Area of Law
Criminal Law
Instrument
Legislative Instrument
Concepts
Commencement Provisions
Offence Provisions
Enforcement Powers

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.