Part 4 Gathering and using information Division 3 Use and disclosure of protected information Section 43 (vii) defence; (viii) the regulation or oversight of the relevant industry for the critical infrastructure asset to which the protected information relates; (b) a Minister of a State, the Australian Capital Territory, or the Northern Territory, who has responsibility for the regulation or oversight of the relevant industry for the critical infrastructure asset to which the protected information relates; (c) a person employed as a member of staff of a Minister mentioned in paragraph (a) or (b); (d) the head of an agency (including a Department) administered by a Minister mentioned in paragraph (a) or (b), or an officer or employee of that agency. 43 Authorised disclosure relating to law enforcement The Secretary may disclose protected information to an enforcement body (within the meaning of the Privacy Act 1988) for the purposes of one or more enforcement related activities (within the meaning of that Act) conducted by or on behalf of the enforcement body. Note: This section is an authorisation for the purposes of other laws, including the Australian Privacy Principles. 44 Secondary use and disclosure of protected information An entity may make a record of, use or disclose protected information if: (a) the entity obtains the information under this Subdivision (including this section); and (b) the entity makes the record, or uses or discloses the information, for the purposes for which the information was disclosed to the entity. Note: 40 This section is an authorisation for the purposes of other laws, including the Australian Privacy Principles. Security of Critical Infrastructure Act 2018 Authorised Version C2018A00029 No. 29, 2018

Select target paragraph3