EXPLANATORY STATEMENT
Telecommunications Act 1997
Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2017
Issued by the Authority of the Minister for Communications
The Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2017 (the Instrument) sets out the conditions upon which authorisations for access to information contained in the Integrated Public Number Database (IPND) may be granted by the Australian Communications and Media Authority (ACMA) under the Integrated Public Number Database Scheme 2017 (the IPND Scheme).
The Instrument repeals and replaces the Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2007 (No. 1) (the 2007 Instrument) which is due to sunset on 1 October 2017, under Part 6 of the Legislation Act 2003 (the Legislation Act). Following review, it was determined that the provisions contained within the 2007 Instrument were operating effectively and efficiently, and continued to form a necessary and useful part of the regulatory framework.
Context and purposes of the Instrument
The IPND is an industry-wide database of all public telephone numbers (both listed and unlisted) in use and associated customer information including name and address information. It also includes information such as whether the number or address is to be listed in a public number directory and whether the number is used for residential, business, government or charitable purposes.
The IPND is established and maintained by Telstra Corporation Limited (Telstra) as a condition of its carrier licence. All carriage service providers which supply carriage services to customers who have public numbers are obliged to provide customer information to Telstra for inclusion in the IPND.
Information in the IPND can be accessed by persons to publish public number directories and for certain authorised research purposes.
Section 295A of the Telecommunications Act 1997 (the Telecommunications Act), requires the ACMA to establish an IPND Scheme for the granting of authorisations that will permit certain persons to use and disclose IPND information.
Following a review by the ACMA in 2016, the IPND Scheme was amended to enable the ACMA to grant research authorisations on an ongoing basis, and authorise a research body to disclose de-identified IPND data (i.e. excluding customer names) to its members for permitted research purposes provided certain requirements are met.
The IPND Scheme is established in a legislative instrument, the Telecommunications Integrated Public Number Database Scheme 2017. The IPND Scheme requires persons seeking access to information in the IPND for the purposes of publishing and maintaining a public number directory or conducting research the Minister considers to be in the public interest, to apply to the ACMA for an authorisation before access to IPND information may be granted.
Section 295P of the Telecommunications Act also permits the Minister to place mandatory conditions on authorisations granted under the IPND Scheme. This instrument making power enables the Minister to specify conditions that will further protect the privacy of information contained in the IPND.
Breach of a condition of authorisation is a criminal offence under section 295R of the Telecommunications Act. The ACMA is able to issue formal warnings in relation to breaches of conditions, and written directions to comply with a condition of authorisation. Failure to comply with a written direction is a breach of a civil penalty provision for which Part 31 of the Telecommunications Act provides pecuniary penalties.
Regulation Impact Statement
The Office of Best Practice Regulation has advised that a Regulation Impact Statement (RIS) is not required on the basis that the Instrument replaces an instrument that is sunsetting, that is, the 2007 Instrument.
Statement of compatibility with human rights
A statement of compatibility is set out at Attachment A.
Consultation
The Instrument has been updated in consultation with the ACMA and current users of the IPND. The then Department of Communications completed a review of the IPND in 2015 which identified the need to retain the current IPND. The review involved public consultation, and the report is available on the department’s website.
Legislative basis
The Instrument is made under section 295P of the Telecommunications Act.
Subsection 295P(1) provides that the Minister may, by legislative instrument, do either or both of the following:
- determine that all authorisations under the IPND Scheme are granted subject to specified conditions;
- determine that a specified kind of authorisation under the IPND Scheme is granted subject to specified conditions.
Subsection 295P(2) provides that an authorisation under the IPND Scheme is granted subject to any condition specified in an instrument under section 295P that is applicable to that authorisation.
The Instrument is a legislative instrument for the purposes of the Legislation Act (see section 8 of that Act).
NOTES ON CLAUSES
Section 1 - Name
Section 1 provides that the name of the Determination is the Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2017.
Section 2 – Commencement
Section 2 provides that the Determination commences on the day after the Instrument is registered.
Section 3 – Authority
Section 3 provides that the Determination is made under section 295P of the Telecommunications Act 1997 (the Telecommunications Act) which provides that the Minister may determine that authorisations are granted subject to conditions.
Section 4 – Definitions
Section 4 defines the terms and concepts used in the Determination.
The term Act is defined to mean the Telecommunications Act 1997.
The term contractor is defined to mean a person who performs services for and on behalf of the holder of a public number directory authorisation or a research authorisation but does not include a person who performs such services in the capacity of an employee of the holder.
The term customer is defined to mean a person who is supplied with a carriage service by a carriage service provider.
Customer data is defined to have the same meaning as in the Telecommunications Integrated Public Number Database Scheme 2017. Customer data includes the public number, name, directory finding name, and the directory address of a customer or their business. It also includes information such as whether the number or address is to be listed in a public number directory and whether the number is used for residential, business, government or charitable purposes.
Directory address is defined to mean the information contained in the designated directory address fields in the integrated public number database.
Directory finding name is defined to mean the information contained in the designated finding name fields in the integrated public number database.
Integrated public number database is defined to have the meaning given by subsection 285(2) of the Act.
Integrated public number database scheme is defined to mean the scheme in force under section 295A of the Act.
IPND Manager is defined to mean the person who for the time being maintains the integrated public number database.
Australian Privacy Principles is defined to have the same meaning as in the Privacy Act 1988.
Protected information is defined to mean information or a document disclosed under subsection 285(1A) of the Act for a purpose covered by subparagraph 285(1A)(c)(ii) or subparagraph 285(1A)(c)(iv) of the Act.
Public number is defined to have the meaning given by subsection 285(2) of the Act.
Public number directory is defined to have the meaning given by subsection 285(2) of the Act.
Public number directory authorisation is defined to mean an authorisation under the integrated public number database scheme that permits the person to whom it is granted to use and disclose protected information for a purpose covered by subparagraph 285(1A)(c)(ii) of the Act.
Research authorisation is defined to mean an authorisation under the integrated public number database scheme that permits the person to whom it is granted to use and disclose protected information for a purpose covered by subparagraph 285(1A)(c)(iv) of the Act.
There is a note under subsection 4(1) providing that a number of expressions used in this Instrument are defined in section 7 of the Act.
Subsection 4(2) provides, for the purposes of the Instrument, protected information is taken to be transferred to someone who is in a foreign country when it becomes accessible to the intended recipient of the information in the foreign country.
There is a note under subsection 4(2) which provides that section 6 of the Instrument deals with transborder data flows and it is not intended to capture temporary offshoring of data such as when a document is emailed between two points within Australia but because of Internet routing it travels overseas on the way to its destination.
Section 5 – Schedules
Section 5 provides that each instrument that is specified in Schedule 1 is repealed as set out in the Schedule.
Section 6 – Cross-border disclosure of protected information
The conditions in section 6 apply to all holders of authorisations granted under the IPND Scheme.
Subsection 6(1) restricts the circumstances in which holders of authorisations may transfer IPND information to foreign countries. Subsection 6(1) provides that the only circumstances under which IPND information may be transferred to a foreign country are where:
- the holder of the authorisation reasonably believes that the recipient is subject to a law or binding scheme that has the effect of protecting the information in a way that, overall, is at least substantially similar to the Australian Privacy Principles; or
- the holder of the authorisation has made contractual arrangements with the recipient to ensure that the IPND information will not be held, used or disclosed by the recipient inconsistently with the Australian Privacy Principles.
The condition seeks to protect the privacy of personal information sourced from the IPND by preventing it from being transferred to a country that does not have the same level of privacy protection for personal information as that provided in Australia. Alternatively, if the IPND information is to be transferred to a country with lower privacy protections than those prevailing in Australia, the authorisation holder must put in place contractual arrangements with the information recipient in that country to ensure that IPND information is protected to the standard provided for in the Australian Privacy Principles.
Australian Privacy Principle 8 (APP 8) is the accepted standard in relation to restrictions on transferring personal information outside of Australia. However, APP 8 contains some very broad exemptions which would not effectively prevent the transfer of IPND information outside of Australia without appropriate protections. Subsection 6(1) in the Determination is therefore a more restrictive version of APP 8.
The Determination has been drafted to ensure that temporary offshoring of IPND information, for example where a document is emailed between two points in Australia but travels overseas on the way to its destination because of Internet routing, is not captured by these provisions (see subsection 4(2) of the Determination).
The provision is not intended to prevent the viewing overseas of online public number directories published by authorised publishers of using IPND data.
Subsection 6(2) requires holders of authorisations who transfer IPND information to a foreign country to remain legally responsible for any use or disclosure of that information by the recipient that is inconsistent with the Australian Privacy Principles. This condition seeks to overcome the jurisdictional issues involved in enforcing Australian privacy law overseas. The condition will have the effect of enabling individuals to seek redress from, and the ACMA to take action against, the Australian- based holder of the authorisation should the IPND information be used or disclosed inappropriately outside of Australia.
Section 7 – Safeguarding protected information
The condition in section 7 applies to all holders of authorisations granted under the IPND Scheme.
Section 7 requires authorisation holders to take reasonable steps to protect and secure the IPND information, and any personal information related to the IPND information, that it holds from misuse or loss, and from unauthorised access, modification, use or disclosure. This condition is based on Australian Privacy Principle 11.1.
The phrase ‘personal information related to the protected information’ (i.e. IPND information) is intended to include sensitive information such as the political opinions or health information pertaining to an individual.
Section 8 – Addressing breaches of security
The condition in section 8 applies to all holders of authorisations granted under the IPND Scheme.
Section 8 requires an authorisation holder to notify the ACMA and the IPND Manager (currently Telstra) as soon as practicable after the authorisation holder becomes aware of a substantive or systemic breach of security that could reasonably be regarded as having an adverse impact on the integrity and confidentiality of IPND information. This condition also requires the authorisation holder to take reasonable steps to minimise the effects of the breach.
Section 9 – Notification of breaches by others
The condition in section 9 applies to all holders of authorisations granted under the IPND Scheme.
Section 9 requires the holder of the authorisation to notify the ACMA and the IPND Manager as soon as practicable after becoming aware that a person to whom the authorisation holder has disclosed IPND information has contravened any legal restrictions on the use or disclosure of IPND information.
Section 10 – Secure disposal of protected information after use
The condition in section 10 applies to all holders of authorisations granted under the IPND Scheme.
Section 10 requires IPND information be securely destroyed within 10 business days if the information is no longer needed or where an authorisation ceases or has been revoked. This is intended to ensure that the user of the information only has access to IPND information for as long as it is needed or for as long as the user is authorised to have access to it. Requiring the secure destruction of IPND information will also minimise the risk of unauthorised persons obtaining access to the IPND information after the holder of the authorisation no longer needs, or is no longer authorised to access, the information. This condition is based on Australian Privacy Principle 11.2.
Section 11 – Public number directory publishers
Section 11 specifies conditions of authorisations that apply only to holders of authorisations for the publication and maintenance of a public number directory.
Subsection 11(1) recognises that publishers of public number directories may contract out the preparation of the public number directory to another person, and that the conditions relating to use and disclosure of IPND information for the purpose set out in the authorisation should also apply to the other person.
Subsection 11(1) requires that, before the holder of an authorisation can disclose IPND information to a contractor, the holder of the authorisation must have contractual arrangements in place that ensure the contractor neither uses nor discloses IPND information except for the purpose of publishing and maintaining a public number directory. This condition is also intended to prevent public number directory publishers avoiding their obligations through outsourcing arrangements.
If an authorisation is granted by the ACMA under the IPND Scheme, the holder of the authorisation will, subject to entering contractual arrangements with the IPND Manager, be given access to IPND ‘customer data’.
The definition of public number directory in the subsection 285(2) of the Telecommunications Act defines a public number directory as a record containing the public number( excluding an unlisted number), name and, optionally, address of a person or body. Additional information may be included in a public number directory in relation to bodies that are qualifying entities as defined in subsection 295(2) of the Telecommunications Act, but only if the qualifying entity has consented orally or in writing to this additional information being included in the public number directory.
Subsection 11(2) makes it a condition of authorisation that the only customer data (as defined above, that is, originating from the IPND) that may be included in a public number directory that is published and maintained by the holder of the authorisation is the finding name, directory address and public number. This is on the basis that this is the only information the customer would have consented to having included in a public number directory at the time of subscribing to the telecommunications service.
Subsection 11(3) requires authorisation holders to be the copyright holder in any public number directory produced using IPND information as result of that authorisation, whether the directory is produced by the holder of the authorisation or a contractor. Any public number directory published will also need to include the name and contact details of the directory publisher and a copyright statement concerning the holder’s copyright in the directory.
This condition is intended to act as a disincentive for the on-selling of IPND information directly to other persons who may then use the information to produce their own directory products in which they hold the copyright.
This condition also assists the ACMA in its monitoring and compliance role by easily enabling the ACMA to identify the publisher of a particular public number directory.
The condition will also enable customers to easily identify the directory publisher in the event that they wish to contact the publisher or make a complaint about the directory publisher, for example if they wish to correct their entry in the public number directory or where they have an issue with the disclosure or use of their personal information by the directory publisher.
Section 12 – Researchers
Section 12 specifies conditions of authorisation that apply only to holders of authorisations to conduct research in the public interest.
Subsection 12(1) recognises that researchers may contract out the preparation of the database of IPND information used to conduct research, or the conduct of the research itself, to another person, and that the conditions applying to the use and disclosure of IPND information for the purpose set out in the authorisation should also apply to that person.
Subsection 12(1) requires that, before the holder of an authorisation can disclose IPND information to a contractor, the holder of the authorisation must have contractual arrangements in place that ensure the contractor neither uses nor discloses IPND information except for the purpose of conducting the kind of research as specified in the Telecommunications (Integrated Public Number Database – Permitted Research Purposes) Instrument 2017. This condition is also intended to prevent researchers avoiding their obligations under the Telecommunications Act through outsourcing arrangements.
Subsection 12(2) makes it a condition of authorisation that the holder of the authorisation must not produce a database from IPND information for research purposes that is reverse-searchable. What constitutes ‘reverse-searchable’ in this condition is that the database must not enable a person who only knows someone’s public number to readily identify their name and/or address or, subject to subsection (3), a person who only knows the whole or part of someone’s address to identify their name and/or public number.
The condition in subsection 12(2) is made on the basis that there is no apparent need for researchers to produce databases that permit searching by number to find a person’s name and/or address for research purposes. There is also a clear concern among members of the public about directories and databases being reverse-searchable.
Reverse-searchability is a particularly a concern in relation to electronic public number directories that are in the public domain. A reverse-searchable public number directory can be easily used by any member of the public with malicious intent to identify and locate a person. Such uses of public number directories by the general public fall outside of the provisions of the Telecommunications Act and the Privacy Act 1988.
Reverse-searchability appears to be less of a concern when databases will be produced and used by researchers internally. It has been pointed out in public consultation in the past that researchers need to be able to search any database they produce for research purposes by postcode, to find a list of public numbers in that postcode for geographically valid sampling purposes. If this is not permitted, access to the IPND for these users will be ineffective.
As a result, subsection 12(3) creates an exception to the general prohibition on researchers producing databases that are reverse-searchable, allowing the holder of a research authorisation to produce a database that enables a person to search by postcode to find a list of public numbers, and the associated customer data, from within the postcode.
The condition in subsection 12(4) mirrors the condition placed on public number directory publishers under subsection 11(2) and is made on the same basis, that is, that this is the only information the customer would have consented to having included in a public number directory at the time of subscribing to the telecommunications service. Therefore, it would be reasonable to assume that these are the customer details by which a customer would expect to be contacted by researchers.
Subsection 12(5) prohibits the holder of an authorisation from selling or providing IPND information to any person for any purpose unless this is authorised by or under law. Authorised by or under law includes by the Telecommunications Act or legislative instruments made under that Act.
Schedule 1 – Repeals
Schedule 1 repeals the Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2007 (No. 1) which is due to sunset on 1 October 2017 so it can be replaced with this new Instrument.
Attachment A
Statement of Compatibility with Human Rights
Prepared in accordance with subsection 9(1) of the Human Rights (Parliamentary Scrutiny) Act 2011
Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2017
Overview of the Instrument
The Telecommunications (Integrated Public Number Database Scheme – Conditions for Authorisations) Determination 2017 (the Instrument) sets out the conditions upon which authorisations for access to personal information contained in the Integrated Public Number Database (IPND) may be granted by the Australian Communications and Media Authority (ACMA) under the IPND Scheme.
Section 6 provides for the cross-border disclosure of protected information, section 7 provides for safeguarding of protected information, section 8 addresses breaches of security, section 9 outlines the notification requirements for security breaches, and section 10 relates to securing the disposal of protected information after use.
Sections 276 and 277 of the Telecommunications Act prohibit the disclosure or use of information obtained by carriers and carriage service providers in the course of providing their services. The prohibition extends to the disclosure and use of information held in the IPND, an industry wide database of all residential and business telephone numbers and associated subscriber information.
Section 285 of the Telecommunications Act contains an exception to the prohibition, and permits disclosure of information from the IPND by Telstra (as the IPND Manager) to a person who holds an authorisation granted by the ACMA to receive IPND information. The Telecommunications Integrated Public Number Database Scheme 2017 is the scheme under which authorisations may be granted to access information contained in the IPND for the purposes of paragraph 285(1A)(d) of the Telecommunications Act. Those purposes are the publication and maintenance of a public number directory and the conduct of research of a kind specified in a legislative instrument, by the Minister, where the Minister is satisfied that the kind of research is in the public interest.
Human rights implications
It has been assessed whether the Instrument is compatible with human rights, being the rights and freedoms recognised or declared by the international instruments listed in subsection 3(1) of the Human Rights (Parliamentary Scrutiny) Act 2011 as they apply to Australia.
Having considered the likely impact of the Instrument and the nature of the applicable rights and freedoms, it has been determined that the Instrument engages the right to privacy in Article 17 of the International Covenant on Civil and Political Rights (the ICCPR).
Right to privacy
Article 17 of the ICCPR provides:
1. No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.
2. Everyone has the right to the protection of the law against such interference or attacks.
Collecting, using, storing, disclosing or publishing personal information amounts to an interference with privacy. In order for the interference with privacy not to be ‘arbitrary’, any interference with privacy must be in accordance with the provisions, aims and objectives of the ICCPR and should be reasonable in the particular circumstances. Reasonableness, in this context, incorporates notions of proportionality, appropriateness and necessity.
Subsection 6(1) provides that an authorisation under the IPND Scheme is subject to the prohibition of transferring protected information to someone who is in a foreign country (recipient), unless the authorisation holder believes the recipient is subject to a law or scheme that would protect that information in line with the Australian Privacy Principles, or a contractual arrangement has been made with the recipient to ensure that the information will not be held, used or disclosed in a manner inconsistent with the Australian Privacy Principles. The authorisation holder remains legally responsible for any use of disclosure of protected information by the recipient.
Section 7 requires the authorisation holder to ensure reasonable steps are taken to protect and secure protected information and any personal information related to the protected information from misuse or loss, and unauthorised access, modification, use or disclosure. Where these safeguards are breached, section 8 requires the authorisation holder to notify the ACMA and the IPND Manager of the breach as soon as practicable after the holder becomes aware of the breach. An authorisation holder is also obliged to notify the ACMA and the IPND Manager once it becomes aware that a person to whom the holder has disclosed protected information has contravened any legal restrictions governing the use or disclosure of protected information under section 9.
Section 10 requires an authorisation holder to securely destroy protected information within 10 business days of the protected information no longer being required for the purpose for which it was disclosed to the holder, or the authorisation ceasing or being revoked.
Research authorisations are also subject to conditions requiring contractual arrangements to be made between the authorisation holder and any contractor to ensure contractors to whom the holder discloses protected information neither use nor disclose the information except for the purposes outlined in subparagraph 285(1A)(c)(iv) of the Telecommunications Act.
All the conditions are designed to promote the protection of personal information and the right to privacy. These protections provide that IPND information is used only for strictly prescribed purposes and in defined circumstances. To the extent that the measures in the Instrument engage the right to privacy, they are lawful and non-arbitrary.
Conclusion
The Instrument is compatible with human rights. To the extent that it limits any human rights, those impacts are reasonable, necessary and proportionate.