Amendments Schedule 1 Applications (6) An application by an entity under paragraph (5)(b) may be expressed to be: (a) an application for a paragraph (1)(c) declaration; or (b) an application for a paragraph (1)(d) declaration; or (c) an application for: (i) a paragraph (1)(c) declaration; or (ii) in the event that the Commissioner is not disposed to make such a declaration—a paragraph (1)(d) declaration. (7) If an entity applies to the Commissioner under paragraph (5)(b): (a) the Commissioner may refuse the application; and (b) if the Commissioner does so—the Commissioner must give written notice of the refusal to the entity. (8) If: (a) an application for a paragraph (1)(d) declaration nominates a period to be specified in the declaration; and (b) the Commissioner makes the declaration, but specifies a different period in the declaration; the Commissioner is taken not to have refused the application. (9) If an entity applies to the Commissioner under paragraph (5)(b) for a declaration that, to any extent, relates to an eligible data breach of the entity, sections 26WK and 26WL do not apply in relation to: (a) the eligible data breach; or (b) if the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities—such an eligible data breach of those other entities; until the Commissioner makes a decision in response to the application for the declaration. (10) An entity is not entitled to make an application under paragraph (5)(b) in relation to an eligible data breach of the entity if: (a) the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities; and No. 12, 2017 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 17

Select target paragraph3