Explanatory Statement
Issued by authority of the Attorney-General
Telecommunications (Interception and Access) Act 1979
Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2024
- The Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2024 (the Declaration) is made under paragraphs 176A(3)(a) and (b) of the Telecommunications (Interception and Access) Act 1979 (the TIA Act).
- The TIA Act protects the privacy of telecommunications and creates a legal framework for intelligence and law enforcement agencies to access information held by telecommunications providers for law enforcement and national security purposes.
Enforcement agencies
- Section 176A of the TIA Act defines an enforcement agency for the purposes of being able to access historic telecommunications data as follows:
- the agencies that also fall under the definition of ‘criminal law-enforcement agency’ under section 110A of the TIA Act, including all state and territory police agencies, the Department of Home Affairs (for limited purposes), the Australian Competition and Consumer Commission, the Australian Securities and Investments Commission, the Australian Criminal Intelligence Commission, and various integrity and corruptions Commissions, and
- an authority or body for which a declaration under subsection 176A(3) is in force.
Telecommunications data
- Telecommunications data is information about a communication, such as time, date and duration of a communication, or the service from which a communication was sent. Telecommunications data does not include the content of a communication, such as the subject line of an email or the contents of an SMS.
- Division 4 of Part 4-1 of Chapter 4 of the TIA Act provides that officers of an enforcement agency may authorise disclosure of existing or prospective telecommunications data if satisfied that it is reasonably necessary based on relevant criteria.
Purpose of the Declaration
- The purpose of the Declaration is to declare Corrective Services NSW to be an enforcement agency under subsection 176A(3) of the TIA Act to allow it to access telecommunications data. Corrective Services NSW, as a part of the NSW Department of Communities and Justice, was previously declared to be a criminal law-enforcement agency pursuant to the Telecommunications (Interception and Access) (Enforcement Agency—NSW Department of Communities and Justice) Declaration 2024. That declaration expired on 18 November 2024, 40 sitting days after its commencement, in accordance with subsection 176A(10) of the TIA Act.
Legislative scheme
- Subsections 178(1) and 179(1) of the TIA Act provide that sections 276, 277 and 278 of the Telecommunications Act 1997 (Telecommunications Act) do not prevent a disclosure of telecommunications data from a service provider should an appropriate authorisation under subsections 178(2) and 179(2) respectively be in place.
- Subsections 178(2) and 179(2) of the TIA Act allow for an authorised officer of an enforcement agency to authorise the disclosure of specified information or documents that came into existence before the time the person from whom the disclosure is sought receives notification of the authorisation.
- Paragraphs 176A(3)(a) and (b) of the TIA Act provide that the Attorney-General may, by legislative instrument, declare that an authority or body is an enforcement agency, and, that persons or kinds of persons specified in a declaration are officers of the enforcement agency, for the purposes of the Act.
- Subsection 176A(6) of the TIA Act provides that the declaration may be subject to conditions.
Considerations
- Section 176A of the TIA Act sets out the considerations for the Attorney‑General to make a declaration.
Functions of the agency
- Under subsection 176A(3B) of the TIA Act, the Attorney-General must not make a make a declaration under subsection 176A(3) of the TIA Act, unless satisfied on reasonable grounds that the functions of the authority or body include:
- enforcement of the criminal law; or
- administering a law imposing a pecuniary penalty; or
- administering a law relating to the protection of the public revenue.
- The Attorney-General is satisfied that the functions of Corrective Services NSW include the enforcement of the criminal law. Corrective Services NSW administers the Crimes (Administration of Sentences) Act 1999 (NSW) which includes criminal penalties under Part 13A for offences such as the trafficking of prohibited goods and the possession of mobile phones in correctional facilities. Corrective Services NSW also plays a critical role in the detection, investigation and prosecution of offences under the Crimes Act 1900 (NSW) including offences relating to escaping from lawful custody and threatening witnesses, as well as terrorism offences under the Terrorism (High Risk Offenders) Act 2017 (NSW) and the Criminal Code Act 1995 (Cth).
- Paragraph 176A(4)(b) of the TIA Act requires the Attorney-General to have regard to whether having access to telecommunications data would be reasonably likely to assist Corrective Services NSW perform its functions of enforcing the criminal law.
- Illicit mobile telephones pose a particular threat within correctional facilities. They are used to organise escape attempts, threaten the safety of victims and witnesses, organise trafficking of contraband, and facilitate behaviour contrary to national security interests. Telecommunications data is particularly vital in establishing the ownership or location of mobile phones used to commit offences within correctional facilities and would assist Corrective Services NSW in the performance of its functions.
- Acknowledging this, the Comprehensive Review of the Legal Framework of the National Intelligence Community (Comprehensive Review) recommended that corrective services agencies have access to telecommunications data if their respective state or territory government considered it necessary.
Privacy considerations
- Paragraph 176A(4)(c) of the TIA Act requires the Attorney-General to have regard to protection of personal information by the authority or body.
- Subparagraph 176A(4)(c)(i) of the TIA Act requires consideration of whether the agency is required to comply with the Australian Privacy Principles. As a NSW Government entity, Corrective Services NSW is not required to comply with the Australian Privacy Principles. However, Corrective Services NSW is required to comply with the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act) and the Crimes (Administration of Sentences) Act 1999 (NSW) provisions on protection of personal information.
- The NSW Information Protection Principles, under the PPIP Act, are broadly comparable to the Australian Privacy Principles in providing safeguards for the collection, use, disclosure and security of personal information. Although there are differences, Corrective Services NSW has agreed, in line with subparagraph 176A(4)(c)(iii) of the TIA Act, to a scheme that reflects the requirements outlined in subsection 176A(4A).
- The scope of personal information under the PPIP Act is limited and does not explicitly include telecommunications data. This has been addressed as Corrective Services NSW, through the Privacy Impact Assessment conducted by the NSW Department of Communities and Justice in May 2020, has accepted that telecommunications data is personal information and has undertaken to treat it as such under all relevant legislation.
- Under the Mandatory Notification of Data Breach Scheme, public sector agencies bound by the PPIP Act are required to notify the Privacy Commissioner and affected individuals of data breaches involving personal or health information likely to result in serious harm. Agencies also have to make reasonable attempts to mitigate the harm done by a data breach, maintain an internal data breach incident register, and have a publicly accessible data breach policy.
- As set out in its Privacy Management Plan, Corrective Services NSW must report all data breaches or allegations of a breach to the Open Government, Information and Privacy Unit, which determines whether a breach should be reported to the Privacy Commissioner.
- As a law enforcement agency for the purposes of the PPIP Act, Corrective Services NSW is exempt from a number of the NSW Information Protection Principles. Further, Corrective Services NSW is not required to, and does not, comply with other of the Principles due to the nature of its role and the information it will be collecting. However, these exemptions or areas of non-compliance are commensurate with exemptions under the Australian Privacy Principles for enforcement agencies.
- For the purposes of paragraph 176A(4A)(b) of the TIA Act, Corrective Services NSW will voluntarily report on the collection and use of telecommunications data to the NSW Privacy Commissioner and the NSW Minister for Corrections. This is in addition to the oversight of the use of telecommunications data by the Commonwealth Ombudsman as set out in Chapter 4A of the TIA Act.
- For the purposes of paragraph 176A(4A)(c) of the TIA Act, sections 45 and 53 of the PPIP Act provide a mechanism for an individual to make a complaint to the NSW Privacy Commissioner about an alleged breach of privacy by a public sector agency or may seek internal review by the agency. This process is overseen by the NSW Civil and Administrative Tribunal.
Compliance with TIA Act obligations
- Paragraph 176A(4)(d) of the TIA Act requires the Attorney-General to have regard to whether Corrective Services NSW proposes to adopt processes and practices to ensure it complies with its obligations under Chapter 4 of the TIA Act.
- To meet its obligations, Corrective Services NSW has:
- a purpose‑built electronic data storage system for intelligence-related and other protected and sensitive information, accessible only by authorised staff and which keeps sufficient records for oversight purposes
- a clear hierarchy of approval before consent is given to make an authorisation under the TIA Act
- clearly defined processes to record authorisation requests, outcomes, and use of information obtained, and
- training on data retention laws, including authorised officer considerations.
- Corrective Services NSW systems will report on its use of telecommunications data to the Commonwealth Attorney-General, the NSW Attorney General, the NSW Minister for Corrections, the Office of the Commonwealth Ombudsman (OCO) and the NSW Privacy Commissioner, as required by the TIA Act and NSW legislation.
- Further, the OCO has assessed Corrective Services NSW’s systems, policies and processes to ensure Corrective Services NSW can appropriately deal with and protect telecommunications data as required by the TIA Act.
Public interest
- Paragraph 176A(4)(e) of the TIA Act requires the Attorney-General to have regard to whether the declaration would be in the public interest. The importance of telecommunications data to the functions of Corrective Services NSW, the crucial role that Corrective Services NSW plays in enforcing the criminal law and protecting public safety and the privacy and other protections that Corrective Services NSW has in place mean that providing Corrective Services NSW access to telecommunications data is in the public interest.
Consultation
- The Office of Impact Analysis (the OIA) has advised that an Impact Analysis is not required. The OIA consultation reference number is OBPR23-03901.
- The Declaration is an instrument subject to disallowance under section 42 of the Legislation Act 2003 and therefore a Statement of Compatibility with Human Rights has been provided at Attachment A.
- The Attorney-General’s Department consulted Corrective Services NSW, the Office of the Australian Information Commissioner and the OCO on this Declaration.
Details of the Telecommunications (Interception and Access) (Enforcement Agency –Corrective Services NSW) Declaration 2024
- The Attorney-General’s Declaration is made under the authority of paragraphs 176A(3)(a) and (b) of the TIA Act.
- Section 1 sets out the name of the Declaration.
- Section 2 provides for the commencement of the Declaration, being the day after registration on the Federal Register of Legislation.
- The note following section 2 refers to paragraph 176A(10)(b) of the TIA Act which provides that the declaration will cease to be in force at the end of the period of 40 sitting days of a House of the Parliament after the Declaration comes into force. This reflects the temporary nature of these declarations.
- In subsection 3(1) of the Declaration, the Attorney-General declares Corrective Services NSW to be an enforcement agency under paragraph 176A(3)(a) of the TIA Act.
- In subsection 3(2) of the Declaration, the Attorney-General declares each staff member of Corrective Services NSW to be officers of Corrective Services NSW for the purposes of the TIA Act under paragraph 176A(3)(b) of the Act.
- The declaration in section 3 is subject to one condition which is set out in section 4 of the instrument.
- Subsection 176A(6) of the TIA Act provides that the declaration of an enforcement agency may be subject to conditions. Subsection 176A(7) of the TIA Act provides that a condition may provide that the authority or body is not to exercise a power conferred on an enforcement agency by or under a specified provision in Chapter 4. The authority or body is taken not to be an enforcement agency for the purposes of that provision.
- Paragraph 4(1)(a) of the Declaration provides that Corrective Services NSW is not to exercise the power under section 180Q of the TIA Act (that is, apply for journalist information warrants). The note following paragraph 4(1)(a) clarifies that Corrective Services NSW is taken not to be an enforcement agency for the purposes of section 180Q of the TIA Act.
- Corrective Services NSW has not been provided the ability to exercise the power under section 180Q of the TIA Act because telecommunications data obtained through the use of a journalist information warrant may not be protected by the NSW Information Protection Principles. Corrective Services NSW has agreed that access to this information is not necessary for the performance of its functions and has agreed to this condition.
Attachment A
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2024
The Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2024 (the Declaration) is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the legislative instrument
Section 176A of the Telecommunications (Interception and Access) Act 1979 (TIA Act) defines an enforcement agency for the purposes of being able to access historic telecommunications data as follows:
- a list of agencies that also fall under the definition of ‘criminal law-enforcement agency’ under section 110A of the TIA Act, including all state and territory police agencies, the Department of Home Affairs (for limited purposes), the Australian Competition and Consumer Commission, the Australian Securities and Investments Commission, the Australian Criminal Intelligence Commission, and various integrity and anti-corruption Commissions, and
- an authority or body for which a declaration under subsection 176A(3) is in force.
The Declaration is a legislative instrument made by the Attorney-General under subsection 176A(3) of the TIA Act, and declares Corrective Services NSW to be an enforcement agency under subsection 176A(3) of the TIA Act to allow access to telecommunications data. Additionally, the Declaration specifies each staff member of Corrective Services NSW to be officers under the TIA Act.
The Declaration is subject to one condition:
- Officers of Corrective Services NSW are not to exercise the power under section 180Q of the TIA Act to apply for journalist information warrants.
The Declaration does not change the statutory basis on which enforcement agencies are able to access telecommunications data and does not amend the existing processes for lawfully accessing telecommunications data.
Human rights implications
The Declaration engages the right to privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR) on the basis that the telecommunications data retained pursuant to subsection 187A(1) of the TIA Act will be accessible by Corrective Services NSW in accordance with the existing lawful access provisions in the Act.
Article 17 provides that no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation, and that everyone has the right to the protection of the law against such interference or attacks.
The protection against arbitrary or unlawful interference with privacy under Article 17 can be permissibly limited in order to achieve a legitimate objective and where the limitations are lawful and not arbitrary. The term unlawful in Article 17 of the ICCPR means that no interference can take place except as authorised under domestic law. Additionally, the term arbitrary in Article 17(1) of the ICCPR means that any interference with privacy must be in accordance with the provisions, aims and objectives of the ICCPR and should be reasonable in the particular circumstances.[1] The United Nations Human Rights Committee has interpreted reasonableness to mean that any limitation must be proportionate and necessary in the circumstances.
The Declaration limits the right to privacy as it allows access to telecommunications data as authorised under domestic law – namely the existing provisions in the TIA Act. However, it is reasonable in the particular circumstances as it is proportionate and necessary.
In considering the reasonableness, consideration has been given to the:
- functions of Corrective Services NSW and whether they necessitate access to telecommunications data, and
- privacy and other safeguards in place to minimise the privacy impacts on any persons to whom the data relates or is appreciably linked.
Functions of Corrective Services NSW
Corrective Services NSW performs the functions of a corrective services agency and enforces the criminal law.
Specifically, Corrective Services NSW administers the Crimes (Administration of Sentences) Act 1999 (NSW) which includes criminal penalties under Part 13A for offences such as the trafficking of prohibited goods and the possession of mobile phones in correctional facilities. Corrective Services NSW also plays a critical role in the detection, investigation and prosecution of offences under the Crimes Act 1900 (NSW) including offences relating to escaping from lawful custody and threatening witnesses as well as terrorism offences under the Terrorism (High Risk Offenders) Act 2017 (NSW) and the Criminal Code Act 1995 (Cth).
The Declaration addresses the legitimate objective of protecting public order by providing Corrective Services NSW with powers required to effectively administering sentences imposed by the courts. This includes not only securely holding offenders, and disrupting offending within correctional centres, but seeking to identify and treat inmates’ criminogenic needs in order to reduce reoffending.
Illicit mobile telephones pose a particular threat within correctional facilities. They are used to organise escape attempts, threaten the safety of victims and witnesses, organise trafficking of contraband, as well as facilitate behaviour contrary to national security interests. Telecommunications data is particularly vital in establishing the ownership or location of mobile phones used to commit offences within correctional facilities. Access to this data would assist Corrective Services NSW to better identify, investigate and prevent illicit mobile phone-related crime in correctional facilities, ensuring any criminal offences are appropriately detected and prosecuted, mitigating the risk posed to public order.
As an agency responsible for ensuring effect sentence administration, it is important that Corrective Services NSW is vested with the powers and capabilities it requires to effectively discharge its functions, and is not dependent on other agencies—and in particular, on agencies within its jurisdiction—to exercise such powers. While there will be cases where it is appropriate for Corrective Services NSW to partner with other law enforcement agencies when conducting investigations, such as NSW Police, the ability to exercise powers under the TIA Act independently is important to:
- ensure that Corrective Services NSW can determine, and exercise powers, in accordance with its own investigative priorities, and
- ensure that the functions of Corrective Services NSW are not constrained by the capacity of other law enforcement agencies to assist its investigations.
Other privacy safeguards
Corrective Services NSW is subject to NSW privacy laws including the Privacy and Personal Information Protection Act 1998 (NSW), and secrecy provisions including in the Crimes (Administration of Sentences) Act 1999 (NSW). Importantly, the privacy protections under NSW legislation are similar to those set out in the Privacy Act 1988 (Cth). These protections are complemented by the strict requirements of the TIA Act for the collection, use and disclosure of information obtained by law enforcement agencies.
Oversight and reporting requirements under the TIA Act also provide accountability on the use of telecommunications data by Corrective Services NSW. Corrective Services NSW will be subject to independent oversight by the Commonwealth Ombudsman, who will inspect the records of Corrective Services NSW to determine the extent of its (and its officers’) compliance with Chapter 4 of the TIA Act and the Ombudsman will also report annually to the Attorney-General about the results of those inspections. The Attorney-General also reports to Parliament on the operation of the data retention scheme each year as required by section 187P of the TIA Act.
Consistent with the approach taken in section 176A for all enforcement agencies, the Declaration provides that all staff members of Corrective Services NSW will be officers for the purpose of the TIA Act. The declaration of staff members as being ‘officers’ for the purposes of the TIA Act is mechanical in nature, and reflects that the various Commonwealth, state and territory agencies that operate under the TIA Act have different employment arrangements that must be accounted for by defining the range of ‘officers’ of each agency. The declaration of staff members as ‘officers’ for the purposes of the TIA Act does not in and of itself permit those staff members to authorise access to telecommunications data. Only ‘authorised officers’ holding a management position or office, authorised in writing under section 5AB of the TIA Act may exercise powers under Chapter 4 of the Act to authorise access to telecommunications data.
In practice, access to the powers is managed via internal governance structures and procedures, is limited to relevant officers of the agency and is subject to external oversight. The TIA Act requires, and Corrective Services NSW has demonstrated, that it has processes and systems in place that ensure telecommunications data will only be accessed when required and will be appropriately protected. Corrective Services NSW systems also allow it to report on its use of telecommunications data to the Commonwealth Attorney-General, the NSW Attorney General, the NSW Minister for Corrections and the NSW Privacy Commissioner as required by the TIA Act and NSW legislation.
The framework for the authorisation of powers under the TIA Act, and the independent oversight of the use of those powers, ensures that any interference with privacy is necessary and proportionate. Authorised officers of Corrective Services NSW will only be permitted to authorise access to telecommunications data if they are satisfied that access is reasonably necessary for an investigative purpose, and are satisfied on reasonable grounds that any interference with privacy is justifiable and proportionate having regard to:
- the gravity of the conduct in relation to which the authorisation is sought
- the likely relevance and usefulness of the information, and
- the reason why the disclosure is proposed to be authorised.
As is the case with other criminal law-enforcement agencies that are authorised to exercise covert powers under Chapters 3 and 4 of the TIA Act, the Commonwealth Ombudsman would oversee Corrective Services NSW’s use of powers. Oversight by the Commonwealth Ombudsman would provide further assurance that the exercise of powers that limit the right to privacy are reasonable, necessary and proportionate.
Conclusion
This Declaration is made for the legitimate purpose of protecting national security, public order and the rights of others. The Declaration is compatible with human rights as set out above, and to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate.
[1] Toonen v Australia, Communication No. 488/1992, U.N. Doc CCPR/C/50/D/488/1992 (1994) at 8.3.