Schedule 1 Amendments 26WM Exception—eligible data breaches of other entities If: (a) an entity complies with sections 26WK and 26WL in relation to an eligible data breach of the entity; and (b) the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities; those sections do not apply in relation to those eligible data breaches of those other entities. 26WN Exception—enforcement related activities If: (a) an entity is an enforcement body; and (b) the chief executive officer of the enforcement body believes on reasonable grounds that there has been an eligible data breach of the entity; and (c) the chief executive officer of the enforcement body believes on reasonable grounds that compliance with section 26WL in relation to the eligible data breach would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, the enforcement body; paragraph 26WK(3)(d) and section 26WL do not apply in relation to: (d) the eligible data breach of the entity; and (e) if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities. 26WP Exception—inconsistency with secrecy provisions Secrecy provisions (1) For the purposes of this section, secrecy provision means a provision that: (a) is a provision of a law of the Commonwealth (other than this Act); and (b) prohibits or regulates the use or disclosure of information. 14 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 No. 12, 2017

Select target paragraph3