Gathering and using information Part 4 Use and disclosure of protected information Division 3 Section 41 Division 3—Use and disclosure of protected information Subdivision A—Authorised use and disclosure 41 Authorised use and disclosure—performing functions etc. An entity may make a record of, use or disclose protected information if the entity makes the record, or uses or discloses the information, for the purposes of: (a) exercising the entity’s powers, or performing the entity’s functions or duties, under this Act; or (b) otherwise ensuring compliance with a provision of this Act. Note: This section is an authorisation for the purposes of other laws, including the Australian Privacy Principles. 42 Authorised use and disclosure—other person’s functions etc. (1) The Secretary may: (a) disclose protected information to a person mentioned in subsection (2); and (b) make a record of or use protected information for the purpose of that disclosure; for the purposes of enabling or assisting the person to exercise his or her powers or perform his or her functions or duties. Note: This subsection is an authorisation for the purposes of other laws, including the Australian Privacy Principles. (2) The persons to whom the Secretary may disclose protected information are the following: (a) a Minister of the Commonwealth who has responsibility for any of the following: (i) national security; (ii) law enforcement; (iii) foreign investment in Australia; (iv) taxation policy; (v) industry policy; (vi) promoting investment in Australia; No. 29, 2018 Security of Critical Infrastructure Act 2018 Authorised Version C2018A00029 39

Select target paragraph3