Restricted Access Systems Declaration 1999 (No. 1)

Administered by Department of Communications and the Arts

Legislation au F2007B00701 Not in force Legislative Instrument

Legislation content

 

 

Restricted Access Systems Declaration 1999 (No. 1)

 

 

 

THE AUSTRALIAN BROADCASTING AUTHORITY makes this declaration under subclause 4(1) of Schedule 5 of the Broadcasting Services Act 1992.

 

 

 

 

 

Dated  3rd December  1999

 

 

 

 

 

 

 

David E. Flint (signed)


 

 

Chairman

 

 

 

 

 

 

 

 

 

 

 

Australian Broadcasting Authority

 

 

Restricted Access Systems Declaration 1999 (No. 1)

 

made under the

 

Broadcasting Services Act 1992

 

 

1. Introduction

 

1.1.            This Declaration is the Restricted Access Systems Declaration 1999 (No. 1).

 

1.2.            This declaration commences on gazettal.

 

1.3.            This declaration sets out minimum system requirements for a 'restricted access system' pursuant to subclause 4(1) of Schedule 5 of the Broadcasting Services Act 1992 (the Act).

 

1.4.            Pursuant to subclause 4(2) of Schedule 5 of the Act, in making this declaration, the Australian Broadcasting Authority

 

 has had regard to the objective of protecting children from exposure to Internet content that is unsuitable for children; and

 has been guided by the principles contained in subsection 4(3) of the Act concerning the regulation of Internet content hosted in Australia and Internet carriage services supplied to end-users in Australia.

 

2. Functions

 

2.1. A 'restricted access system' will be required, as a minimum, to perform the following functions:

 

Number

Function

Description

1.

Registration

The system will receive applications for registration, either in hard copy or electronically.

2.

Qualification/validation

The system will verify age. Upon verification of age, the system will allocate a personal identification number (PIN) or password to the applicant.

3.

Access

To gain access to Internet content subject to the system, the applicant will need to input in full the issued PIN or password. A registered user should not encounter Internet content that is likely to be classified ‘R’ until entered PIN or password has been verified.

 

3. Registration

 

3.1 A person will apply for registration with the system electronically, for example, via a website or email; or in hard copy form, for example, by letter or fax.

 

3.2 Application forms must specify data items that are mandatory and those that are ‘optional’.

 

3.2.1. Mandatory data items for the electronic lodgement of an application are:

 

 name of applicant;

 declaration that applicant is 18 years of age or over; and either

 credit card details; or

 digital signature.

 

3.2.2. Mandatory data items for the lodgement of a hard copy application are:

 

 name of applicant;

 declaration that applicant is 18 years or over; and either

 credit card details; or

 evidence of age, for example, a copy of passport, birth certificate, driver's licence, senior's card or student card.

 

4. Qualification/validation

 

4.1. The system will 'qualify' an application for registration if all mandatory information requirements are provided.

 

4.2. The following rules will be used to invalidate an application:

 

 if applicant has not declared that he/she is at least 18 years of age; or

 if credit card details cannot be validated; or

 if digital signature cannot be authenticated in the case of an electronic application; or

 if evidence of age has not been produced in the case of a hard copy application.

4.3. Upon valid registration, a PIN or password is to be issued to the registered user. It should be a condition of use that the allocated PIN or password should not be passed on to a third person under the age of 18.

 

 

4.4. An allocated PIN or password can be changed if the user and/or system administrator suspects the integrity of the data is compromised.

 

5.      Access

 

5.1                A registered user must input allocated PIN or password to gain access to any  website subject to the system.

 

5.2 Access is to be denied if entered PIN or password does not match registered record of PIN or password.

 

6. System compliance

 

6.1. System compliance will be tested if the ABA receives a complaint about Internet content subject to the system.

 

7. Privacy and security requirements

 

7.1.            The handling of personal information should comply with the privacy standards contained in the National Principles for the Fair Handling of Personal Information issued by the Federal Privacy Commissioner.

 

7.2.            It is highly desirable that the electronic transfer of credit card information be protected with reasonable data security mechanisms.  For example, the use of Secure Sockets Layer (SSL) in online registration processes.

 

Overview

The Restricted Access Systems Declaration 1999 (No. 1) was enacted to establish minimum system requirements for a 'restricted access system' in compliance with the Broadcasting Services Act 1992. This legislative instrument was introduced by the Australian Broadcasting Authority, which was the regulatory body at the time, to address the need to protect children from exposure to unsuitable internet content. The policy objective was to ensure that children are shielded from content that is not suitable for their age, while also adhering to the principles outlined in the Act concerning the regulation of internet content hosted in Australia and internet carriage services supplied to end-users in Australia. The declaration sets out processes for registration, qualification, and access, ensuring that users must verify their age and use a personal identification number or password to access restricted content.

Scope and Application

The Restricted Access Systems Declaration 1999 (No. 1) applies to restricted access systems that are intended to protect children from exposure to unsuitable Internet content as outlined in the Broadcasting Services Act 1992. These systems are required to meet minimum standards for registration, qualification, and validation, ensuring that users who wish to access certain internet content must verify their age and obtain a personal identification number or password. This declaration applies to any individual or entity providing restricted access systems, which are specifically designed to manage access to internet content that might be inappropriate for minors. The declaration is issued under the Commonwealth jurisdiction and aims to ensure compliance with the national principles for the fair handling of personal information and data security. The application of this declaration extends to all restricted access systems used within Australia and is enforced by the Australian Broadcasting Authority. However, the declaration does not specify any particular exclusions or exemptions; it is designed to be broadly applicable to any restricted access system operating within Australia's jurisdiction.

Key Provisions

The Restricted Access Systems Declaration 1999 (No. 1) outlines the minimum system requirements for a 'restricted access system' under subclause 4(1) of Schedule 5 of the Broadcasting Services Act 1992 (the Act). This declaration, which commences on its gazettal, aims to protect children from exposure to Internet content that is unsuitable for them and is guided by the principles set out in subsection 4(3) of the Act concerning the regulation of Internet content and carriage services. The restricted access system must perform specific functions, such as receiving applications for registration, verifying the age of applicants, and allocating personal identification numbers (PINs) or passwords upon successful verification (section 2). These systems must ensure that access to restricted content is granted only when the correct PIN or password is entered (section 5). The declaration imposes several obligations on the parties involved. For instance, the system must be capable of receiving applications for registration either electronically or in hard copy, with specific mandatory data requirements for each method (sections 3.2 and 3.2.2). These mandatory data items include the applicant’s name, a declaration of being 18 years or older, and either credit card details or a digital signature for electronic applications, and credit card details or evidence of age for hard copy applications (section 3). The system must validate applications according to certain rules and issue PINs or passwords upon successful registration, ensuring these are not shared with third parties under 18 (section 4). Breaches of the system requirements or misuse of the allocated PINs or passwords may lead to various consequences. For example, if a system does not comply with the outlined requirements, it may be subject to review and corrective action if the Australian Broadcasting Authority (ABA) receives a complaint about inappropriate Internet content (section 6). Additionally, the handling of personal information must adhere to privacy standards, and the security of electronic data transfers, such as credit card information, must be ensured through mechanisms like Secure Sockets Layer (SSL) (section 7). The specific penalties or consequences for breaches are not explicitly detailed in the declaration, but non-compliance could result in regulatory action by the ABA.

Legal classification tags

Area of Law
Technology Law
Privacy Law
Instrument
Legislative Instrument
Concepts
Definitions & Interpretation
Licensing & Registration
Reporting & Disclosure Obligations
Compliance Obligations
Privacy and Security Requirements
Enforcement Powers

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.