Explanatory Statement
Issued by authority of the Minister for Home Affairs
Telecommunications (Interception and Access) Act 1979
Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026
- The Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026 (the Declaration) is made by the Minister for Home Affairs (the Minister) under paragraphs 176A(3)(a) and (b) of the Telecommunications (Interception and Access) Act 1979 (the TIA Act).
- The TIA Act protects the privacy of telecommunications and creates a legal framework for intelligence and law enforcement agencies to access information held by telecommunications providers for law enforcement and national security purposes.
Enforcement agencies
- Section 176A of the TIA Act defines an enforcement agency for the purposes of being able to access historic telecommunications data as follows:
- the agencies that also fall under the definition of ‘criminal law-enforcement agency’ under section 110A of the TIA Act, including all state and territory police agencies, the Department of Home Affairs (for limited purposes), the Australian Competition and Consumer Commission, the Australian Securities and Investments Commission, the Australian Criminal Intelligence Commission, and various integrity and corruptions Commissions, and
- an authority or body for which a declaration under subsection 176A(3) is in force.
Telecommunications data
- Telecommunications data is information about a communication, such as time, date and duration of a communication, or the service from which a communication was sent. Telecommunications data does not include the content or substance of a communication, such as the subject line of an email or the contents of an SMS.
- Division 4 of Part 4-1 of Chapter 4 of the TIA Act provides that officers of an enforcement agency may authorise disclosure of existing or prospective telecommunications data if satisfied that it is reasonably necessary based on relevant criteria.
Purpose of the Declaration
- The purpose of the Declaration is to declare Corrective Services NSW to be an enforcement agency under subsection 176A(3) of the TIA Act to allow it to access telecommunications data. The Declaration also declares staff members of Corrective Services NSW to be officers of Corrective Services NSW in its capacity as an enforcement agency. Corrective Services NSW was previously declared to be an enforcement agency pursuant to the Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2025. That declaration expired on 1 July 2026, 40 sitting days after its commencement, in accordance with subsection 176A(10) of the TIA Act.
Legislative scheme
- Subsections 178(1) and 179(1) of the TIA Act provide that sections 276, 277 and 278 of the Telecommunications Act 1997 (Telecommunications Act) do not prevent a disclosure of telecommunications data from a service provider should an appropriate authorisation under subsections 178(2) and 179(2) respectively be in place.
- Subsections 178(2) and 179(2) of the TIA Act allow for an authorised officer of an enforcement agency to authorise the disclosure of specified information or documents that came into existence before the time the person from whom the disclosure is sought receives notification of the authorisation.
- Paragraphs 176A(3)(a) and (b) of the TIA Act provide that the Minister may, by legislative instrument, declare that an authority or body is an enforcement agency, and, that persons or kinds of persons specified in a declaration are officers of the enforcement agency, for the purposes of the Act.
- Subsection 176A(6) of the TIA Act provides that the declaration may be subject to conditions.
Considerations
- Section 176A of the TIA Act sets out the considerations for the Minister to make a declaration.
Functions of the agency
- Under subsection 176A(3B) of the TIA Act, the Minister must not make a make a declaration under subsection 176A(3) of the TIA Act, unless satisfied on reasonable grounds that the functions of the authority or body include:
- enforcement of the criminal law; or
- administering a law imposing a pecuniary penalty; or
- administering a law relating to the protection of the public revenue.
- The Minister is satisfied that the functions of Corrective Services NSW include the enforcement of the criminal law. Corrective Services NSW administers the Crimes (Administration of Sentences) Act 1999 (NSW) which includes criminal penalties under Part 13A for offences such as the trafficking of prohibited goods and the possession of mobile phones in correctional facilities. Corrective Services NSW also plays a critical role in the detection, investigation and prosecution of offences under the Crimes Act 1900 (NSW) including offences relating to escaping from lawful custody and threatening witnesses, as well as terrorism offences under the Terrorism (High Risk Offenders) Act 2017 (NSW) and the Criminal Code Act 1995 (Cth).
- Paragraph 176A(4)(b) of the TIA Act requires the Minister to have regard to whether having access to telecommunications data would be reasonably likely to assist Corrective Services NSW perform its functions of enforcing the criminal law.
- Illicit mobile telephones pose a particular threat within correctional facilities. They are used to organise escape attempts, threaten the safety of victims and witnesses, organise trafficking of contraband, and facilitate behaviour contrary to national security interests.
- Telecommunications data is particularly vital in establishing the ownership or location of mobile phones used to commit offences within correctional facilities and has proven invaluable to Corrective Services NSW in supporting investigations into suspected criminal activity in the correctional system, the prosecution of serious crime under State and Commonwealth legislation, and the detection and disruption of terrorist activity. Corrective Services NSW made 10 authorisations in 2023/24 and 12 authorisations in 2024/25 for access to existing information or documents to enforce the criminal law under section 178 of the TIA Act.
- The Comprehensive Review of the Legal Framework of the National Intelligence Community (Comprehensive Review) recommended that corrective services agencies have access to telecommunications data if their respective state or territory government considered it necessary.
Privacy considerations
- Paragraph 176A(4)(c) of the TIA Act requires the Minister to have regard to the requirements for protection of personal information by the authority or body.
- Subparagraph 176A(4)(c)(i) of the TIA Act requires consideration of whether the agency is required to comply with the Australian Privacy Principles in Schedule 1 to the Privacy Act 1988 (Cth). As a NSW Government entity, Corrective Services NSW is not required to comply with the Australian Privacy Principles. However, Corrective Services NSW is required to comply with the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act) and the Crimes (Administration of Sentences) Act 1999 (NSW) provisions on protection of personal information.
- The NSW Information Protection Principles (NSW IPPs), under the PPIP Act, are broadly comparable to the Australian Privacy Principles in providing safeguards for the collection, use, disclosure and security of personal information. Although there are differences between the frameworks, Corrective Services NSW has agreed in writing, in line with subparagraph 176A(4)(c)(iii) of the TIA Act, to a scheme that reflects the requirements outlined in subsection 176A(4A).
- The scope of personal information under the PPIP Act is limited and does not explicitly include telecommunications data. This issue has been addressed as Corrective Services NSW, through the Privacy Impact Assessment (PIA) conducted by the NSW Department of Communities and Justice in 2021, has accepted that telecommunications data is personal information and has undertaken to treat it as such under all relevant legislation. This approach has been confirmed in the current PIA. The PIA was updated in 2025 in response to NSW and Commonwealth privacy law amendments, the establishment of Corrective Services NSW as a stand-alone agency and the passage of time since the last PIA in 2021.
- Overall, the PIA assessed that Corrective Services NSW is well equipped to manage telecommunications data securely and sensitively, that privacy risks associated with Corrective Services NSW’s declaration were limited and were mitigated by a robust legislative framework, policies and training, and the agency’s highly secure information management practices.
- The 2025 PIA confirmed the ongoing relevance of 3 recommendations made in the 2021 PIA – that Corrective Services NSW continue to manage personal information in accordance with legislative requirements and information protection processes outlined in the PIA, that the agency share this PIA with the Minister for Home Affairs, and that the agency continue providing up-to-date training for relevant staff.
- The updated 2025 PIA also made two additional recommendations: that internal auditing be overseen by a second authorised officer, and that annual environmental scans be conducted to proactively identify privacy risks. Corrective Services NSW has advised that it is currently updating its operating procedures to enable a second authorised officer to verify audits and that it will conduct annual privacy environment scans from September 2026 onwards.
- Under the Mandatory Notification of Data Breach Scheme (introduced in NSW in 2023), public sector agencies bound by the PPIP Act are required to notify the Privacy Commissioner and affected individuals of data breaches involving personal or health information likely to result in serious harm. Agencies also must immediately take all reasonable steps to contain a suspected data breach and mitigate any resulting harm from that breach, maintain an internal data breach incident register, and have a publicly accessible data breach policy.
- As set out in its Privacy Management Plan, Corrective Services NSW must report all eligible data breaches (as defined in section 59D of the PPIP Act) or allegations of a breach to the Open Government, Information and Privacy Unit, which determines whether a breach should be reported to the Privacy Commissioner.
- As a law enforcement agency for the purposes of the PPIP Act, Corrective Services NSW is exempt from a number of the NSW IPPs. Further, Corrective Services NSW is not required to, and does not, comply with other of the NSW IPPs due to the nature of its role and the information it will be collecting. However, these exemptions or areas of non-compliance are commensurate with exemptions under the Australian Privacy Principles for enforcement agencies.
- For the purposes of paragraph 176A(4A)(b) of the TIA Act, Corrective Services NSW voluntarily reports on the collection and use of telecommunications data to the NSW Privacy Commissioner and the NSW Minister for Corrections. This is in addition to the oversight of the use of telecommunications data by the Commonwealth Ombudsman as set out in Chapter 4A of the TIA Act.
- For the purposes of paragraph 176A(4A)(c) of the TIA Act, sections 45 and 53 of the PPIP Act provide a mechanism for an individual to make a complaint to the NSW Privacy Commissioner about an alleged breach of privacy by a public sector agency or may seek internal review by the agency. This process is overseen by the NSW Civil and Administrative Tribunal.
Compliance with TIA Act obligations
- Paragraph 176A(4)(d) of the TIA Act requires the Minister to have regard to whether Corrective Services NSW proposes to adopt processes and practices to ensure it complies with its obligations under Chapter 4 of the TIA Act.
- To meet its obligations, Corrective Services NSW has:
- a purpose‑built electronic data storage system for intelligence-related and other protected and sensitive information, accessible only by authorised staff and which keeps sufficient records for oversight purposes
- a clear hierarchy of approval before consent is given to make an authorisation under the TIA Act
- clearly defined processes to record authorisation requests, outcomes, and use of information obtained, and
- training on data retention laws, including authorised officer considerations.
- Corrective Services NSW systems will continue to report on its use of telecommunications data to the Minister, the NSW Attorney General, the NSW Minister for Corrections, the Commonwealth Ombudsman and the NSW Privacy Commissioner, as required by the TIA Act and NSW legislation.
- Further, the Ombudsman has assessed Corrective Services NSW’s systems, policies and processes to ensure Corrective Services NSW can appropriately deal with and protect telecommunications data as required by the TIA Act. In 2022, Corrective Services NSW participated in a ‘health check’ performed by the Ombudsman, followed by inspections in 2022, 2023, 2024 and in 2026. The Ombudsman has not made any findings of serious or systemic non-compliance with the requirements of the TIA Act since the initial ‘health check’ in 2022 and has commented that it considers Corrective Services NSW’s operating procedures to be robust, detailed and fit for purpose.
Public interest
- Paragraph 176A(4)(e) of the TIA Act requires the Minister to have regard to whether the declaration would be in the public interest. The importance of telecommunications data to the functions of Corrective Services NSW, the crucial role that Corrective Services NSW plays in enforcing the criminal law and protecting public safety and the privacy and other protections that Corrective Services NSW has in place mean that providing Corrective Services NSW access to telecommunications data is in the public interest.
Consultation
- The Declaration is an instrument subject to disallowance under section 42 of the Legislation Act 2003 and therefore a Statement of Compatibility with Human Rights has been provided at Attachment A.
- The Department of Home Affairs consulted Corrective Services NSW, the Office of the Australian Information Commissioner (OAIC) and the Commonwealth Ombudsman on this Declaration. Neither the OAIC nor the Ombudsman have objected to the making of a new declaration. The Ombudsman advised that it has not made any findings of serious or systemic non-compliance or any findings of an issue or risk that would give rise to a concern that the CSNSW is unable to use these powers lawfully and as intended by the Parliament. The OAIC similarly did not identify any significant concerns with the proposal.
Details of the Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026
Section 1 Name
- This section provides for the name of the instrument to be Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026 (Declaration).
Section 2 Commencement
- Section 2 provides for the commencement of the Declaration. The Declaration commences on 2 July 2026.
- The note following section 2 draws the reader’s attention to paragraph 176A(10)(b) of the Telecommunications (Interception and Access) Act 1979 (TIA Act), which has the effect that the declaration will cease to be in force at the end of the period of 40 sitting days of a House of the Parliament after the Declaration comes into force. This reflects the temporary nature of the declarations made under section 176A.
Section 3 Authority
- This section provides that the Declaration is made under section 176A of the TIA Act.
Section 4 Definitions
- Section 4 sets out the meaning of the following terms referred to in the Declaration:
- The term “Act”, which is defined to mean the TIA Act.
- The term “enforcement agency” which is defined to have the same meaning as in section 176A of the TIA Act.
Section 5 Declaration
- Section 5 provides for the declaration made under paragraphs 176A(3)(a) and (b) of the TIA Act.
- Subsection 5(1) provides that the declaration made under section 5 are subject to the condition set out in section 6.
- Subsection 5(2) sets out the Minister’s declaration of Corrective Services NSW as an enforcement agency under paragraph 176A(3)(a) of the TIA Act.
- Subsection 5(3) sets out the Minister’s declaration that each staff member of Corrective Services NSW is an officer of Corrective Services NSW, in that agency’s capacity as an enforcement agency, for the purposes of the TIA Act. That declaration is in accordance with paragraph 176A(3)(b) of the Act.
Section 6 Conditions
- Subsection 176A(6) of the TIA Act provides that the declaration of an enforcement agency may be subject to conditions. Subsection 176A(7) of the TIA Act provides that a condition may provide that the authority or body is not to exercise a power conferred on an enforcement agency by or under a specified provision in Chapter 4. The authority or body is taken not to be an enforcement agency for the purposes of that provision.
- This section has the effect that, as a condition of the declaration in section 5 of the Declaration, Corrective Services NSW is not to exercise the power under section 180Q of the TIA Act (that is, apply for journalist information warrants). The note following section 6 clarifies that Corrective Services NSW is taken not to be an enforcement agency for the purposes of section 180Q of the TIA Act.
- Corrective Services NSW has not been provided the ability to exercise the power under section 180Q of the TIA Act because telecommunications data obtained through the use of a journalist information warrant may not be protected by the NSW IPPs. Corrective Services NSW has agreed that access to this information is not necessary for the performance of its functions and has agreed to this condition.
Attachment A
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026
The Telecommunications (Interception and Access) (Enforcement Agency—Corrective Services NSW) Declaration 2026 (the Declaration) is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the legislative instrument
Section 176A of the Telecommunications (Interception and Access) Act 1979 (TIA Act) defines an enforcement agency for the purposes of being able to access historic telecommunications data as follows:
- a ‘criminal law-enforcement agency’ under the prescribed list in subsection 110A(1) of the TIA Act, which includes:
- all state and territory police agencies
- the Department of Home Affairs (for limited purposes)
- the Australian Competition and Consumer Commission
- the Australian Securities and Investments Commission
- the Australian Criminal Intelligence Commission
- various integrity and anti-corruption Commissions and
- an authority or body for which a declaration under subsection 176A(3) is in force.
The Declaration is a disallowable legislative instrument made by the Minister under subsection 176A(3) of the TIA Act and declares Corrective Services NSW to be an ‘enforcement agency’, authorising Corrective Services NSW to access telecommunications data. Additionally, the Declaration prescribes each staff member of Corrective Services NSW to be an ‘officer’ of an enforcement agency under the TIA Act.
The Declaration is subject to one condition:
- officers of Corrective Services NSW are not to exercise the power under section 180Q of the TIA Act to apply for journalist information warrants.
The Declaration does not change the statutory basis on which enforcement agencies are able to access telecommunications data and does not amend the existing processes for lawfully accessing telecommunications data.
Human rights implications
The Declaration engages the right to privacy under Article 17 of the International Covenant on Civil and Political Rights (ICCPR) on the basis that the telecommunications data retained pursuant to subsection 187A(1) of the TIA Act will be accessible by Corrective Services NSW in accordance with the existing lawful access provisions in the Act.
Article 17 of the ICCPR states:
- No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.
2. Everyone has the right to the protection of the law against such interference or attacks.
Under Article 17(1) of the ICCPR, any interference with an individual’s privacy must have a lawful basis. In addition to requiring a lawful basis for limitation on the right to privacy, Article 17 prohibits arbitrary interference with privacy. Interference which is lawful may nonetheless be arbitrary where that interference is not in accordance with the objectives of the ICCPR and is not reasonable in the circumstances.
The Declaration limits the right to privacy as it allows Corrective Services NSW to access telecommunications data as authorised under domestic law – namely the existing provisions in the TIA Act. However, it is reasonable in the circumstances as it is proportionate and necessary to the legitimate objective of protecting national security, public order and the rights of others.
In considering the reasonableness, consideration has been given to the:
- functions of Corrective Services NSW and whether they necessitate access to telecommunications data, and
- privacy and other safeguards in place to minimise the privacy impacts on any persons to whom the data relates or is appreciably linked.
Functions of Corrective Services NSW
Corrective Services NSW performs the functions of a corrective services agency and enforces criminal law.
Specifically, Corrective Services NSW administers the Crimes (Administration of Sentences) Act 1999 (NSW) which includes criminal penalties under Part 13A for offences such as the trafficking of prohibited goods and the possession of mobile phones in correctional facilities. Corrective Services NSW also plays a critical role in the detection, investigation and prosecution of offences under the Crimes Act 1900 (NSW) including offences relating to escaping from lawful custody and threatening witnesses as well as terrorism offences under the Terrorism (High Risk Offenders) Act 2017 (NSW) and the Criminal Code Act 1995 (Cth).
Illicit mobile telephones pose a particular threat within correctional facilities. They are used to organise escape attempts, threaten the safety of victims and witnesses, organise trafficking of contraband, as well as facilitate behaviour contrary to national security interests. Telecommunications data is particularly vital in establishing the ownership or location of mobile phones used to commit offences within correctional facilities. Access to this data assists Corrective Services NSW in identifying, investigating and preventing illicit mobile phone-related crime in correctional facilities, ensuring any criminal offences are appropriately detected and prosecuted, mitigating the risk posed to public order. Corrective Services NSW made 10 authorisations in 2023/24 and 12 authorisations in 2024/25 for access to existing information or documents to enforce the criminal law under section 178 of the TIA Act.
The Declaration addresses the legitimate objective of protecting public order by providing Corrective Services NSW with powers required to effectively administer sentences imposed by the courts. This includes not only securely holding offenders, and disrupting offending within correctional centres, but seeking to identify and treat inmates’ criminogenic needs in order to reduce reoffending.
As an agency responsible for ensuring effective sentence administration, it is important that Corrective Services NSW is vested with the powers and capabilities it requires to effectively discharge its functions and is not dependent on other agencies to exercise such powers. While there will be cases where it is appropriate for Corrective Services NSW to partner with other law enforcement agencies when conducting investigations, such as NSW Police, the ability to exercise powers under the TIA Act independently is important to:
- ensure that Corrective Services NSW can determine, and exercise powers, in accordance with its own investigative priorities, and
- ensure that the functions of Corrective Services NSW are not constrained by the capacity or operational priorities of other law enforcement agencies to assist its investigations.
Corrective Services NSW is best-placed to determine the gravity of any conduct that is the subject of an investigation, the likely relevance of data and other information associated with inmates and offenders under its management, and how data obtained under an authorisation may support a broader investigation, given its broader operational context in managing the relevant correctional centre or centres. Corrective Services NSW has a demonstrated capacity and expertise to undertake these functions.
The use of this power will correlate to illegal (or suspected) activity by staff and inmates. There may be periods where such activity is minimal and can be addressed by existing, and less intrusive, search and intelligence capacity. Conversely, there may be periods where such activity is high in volume or is of a nature that cannot be effectively detected or investigated using other capabilities and methods, and access to telecommunications data may be required.
In practice, access to telecommunications data powers within Corrective Services NSW is strictly limited. Authorisation of access to telecommunications data under the TIA Act is limited to ‘authorised officers’ of an enforcement agency, who under section 5AB are designated in writing, and must hold a management office or management position in the enforcement agency. Only four authorised officers within Corrective Services NSW can make authorisations, and only officers within the Corrections Intelligence Group (CIG) who hold Negative Vetting 1 security clearances and have undertaken specific training, are able to access the data. Once telecommunications data is received, it is held in a secure system that is only accessible by select personnel and is fully auditable. As noted above, Corrective Services NSW participated in a ‘health check’ performed by the Commonwealth Ombudsman (‘the Ombudsman’) in 2022, followed by inspections in 2022, 2023, 2024, and 2026. The Ombudsman has not made any findings of serious or systemic non-compliance with the requirements of the TIA Act since the initial ‘health check’ in 2022 and has commented that it considers Corrective Services NSW’s operating procedures to be comprehensive and fit for purpose.
Other privacy safeguards
Corrective Services NSW is subject to NSW privacy laws including the Privacy and Personal Information Protection Act 1998 (NSW), and secrecy provisions including in the Crimes (Administration of Sentences) Act 1999 (NSW). Importantly, the privacy protections under NSW legislation are similar to those set out in the Privacy Act 1988 (Cth). These protections are complemented by the strict requirements of the TIA Act for the collection, use and disclosure of information obtained by law enforcement agencies.
Oversight and reporting requirements under the TIA Act also provide accountability on the use of telecommunications data by Corrective Services NSW. Corrective Services NSW is subject to independent oversight by the Commonwealth Ombudsman, who inspects the records of Corrective Services NSW to determine the extent of its (and its officers’) compliance with Chapter 4 of the TIA Act. The Ombudsman reports annually to the Minister about the results of those inspections, who in turn table the report to Parliament within 15 sitting days after the Minister receives it, as required by section 186J of the TIA Act.
As a NSW Government entity, Corrective Services NSW is required to comply with the Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act) and the Crimes (Administration of Sentences) Act 1999 (NSW) provisions on protection of personal information. The NSW Information Protection Principles, under the PPIP Act, are broadly comparable to the Australian Privacy Principles in providing safeguards for the collection, use, disclosure and security of personal information. Although there are differences, Corrective Services NSW has agreed, in line with subparagraph 176A(4)(c)(iii) of the TIA Act, to a scheme that reflects the requirements outlined in subsection 176A(4A).
The scope of personal information under the PPIP Act is limited and does not explicitly include telecommunications data. This has been addressed as Corrective Services NSW, through the Privacy Impact Assessment (PIA) conducted by the NSW Department of Communities and Justice in May 2020, has accepted that telecommunications data is personal information and has undertaken to treat it as such under all relevant legislation. This approach has been confirmed in the current PIA. This was updated in 2025 in response to NSW and Commonwealth privacy law amendments, the establishment of Corrective Services NSW as a stand-alone agency and the passage of time since the last PIA in 2021. Overall, the PIA assessed that Corrective Services NSW is well equipped to manage telecommunications data securely and sensitively, that privacy risks associated with Corrective Services NSW’s declaration were limited and were mitigated by a robust legislative framework, policies and training, and the agency’s highly secure information management practices.
The 2025 PIA confirmed the ongoing relevance of 3 recommendations made in the 2021 PIA – that Corrective Services NSW continue to manage personal information in accordance with legislative requirements and information protection processes outlined in the PIA, that the agency share this PIA with the Minister for Home Affairs, and that the agency continue providing up-to-date training for relevant staff.
The 2025 PIA also made two additional recommendations: that internal auditing be overseen by a second authorised officer, and that annual environmental scans be conducted to proactively identify privacy risks. Corrective Services NSW has advised that it is currently updating its operating procedures to enable a second authorised officer to verify audits and that it will conduct annual privacy environment scans from September 2026 onwards.
Consistent with the approach taken in section 176A for all enforcement agencies, the Declaration provides that all staff members of Corrective Services NSW will be officers for the purpose of the TIA Act. The declaration of staff members as being ‘officers’ for the purposes of the TIA Act is mechanical in nature, and reflects that the various Commonwealth, state and territory agencies that operate under the TIA Act have different employment arrangements that must be accounted for by defining the range of ‘officers’ of each agency. The declaration of staff members as ‘officers’ of an enforcement agency for the purposes of the TIA Act does not in and of itself permit those staff members automatic access to telecommunications data. Staff members will only have access where they have been authorised by ‘authorised officers’ holding a management position or office who are authorised in writing under section 5AB of the TIA Act to authorise access to telecommunications data. The PIA notes that Corrective Services NSW has a robust governance model for managing requests for and use of telecommunications data. This includes adhering to a clear and tightly controlled chain-of-command to regulate access and use of data, and a conservative approach to using the powers, only requesting data when the authorised person is satisfied that it cannot be obtained through other means. Corrective Services NSW has, to date, made no more than 15 authorisations for telecommunications data in a financial year.
In practice, access to the powers is managed via internal governance structures and procedures, is limited to relevant officers of the agency and is subject to external oversight. The TIA Act requires, and Corrective Services NSW has demonstrated, that it has processes and systems in place that ensure telecommunications data will only be accessed when required and will be appropriately protected. Corrective Services NSW systems also allow it to report on its use of telecommunications data to the Minister, the NSW Attorney General, the NSW Minister for Corrections and the NSW Privacy Commissioner as required by the TIA Act and NSW legislation.
The framework for the authorisation of powers under the TIA Act, and the independent oversight of the use of those powers, ensures that any interference with privacy is necessary and proportionate. Authorised officers of Corrective Services NSW will only be permitted to authorise a staff member’s access to telecommunications data if they are satisfied that their access is reasonably necessary for an investigative purpose, and are satisfied on reasonable grounds that any interference with privacy is justifiable and proportionate having regard to:
- the gravity of the conduct in relation to which the authorisation is sought;
- the likely relevance and usefulness of the information; and
- the reason why the disclosure is proposed to be authorised.
As is the case with other enforcement agencies that are authorised to exercise covert powers under Chapters 4 of the TIA Act, the Commonwealth Ombudsman oversees Corrective Services NSW’s use of powers. Oversight by the Commonwealth Ombudsman provides further assurance that the exercise of powers that limit the right to privacy are reasonable, necessary and proportionate.
Conclusion
This Disallowable Legislative Instrument is made for the legitimate purpose of protecting national security, public order and the rights of others. The Declaration is compatible with human rights as set out above, and to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate.
The Hon Tony Burke MP
Minister for Home Affairs