Amendments Schedule 1 (ii) a credit provider has disclosed, under subsection 21M(1), credit eligibility information about one or more individuals to a body or person that does not have an Australian link; and (b) the related body corporate, body or person holds the credit eligibility information; this Part has effect as if: (c) the credit eligibility information were held by the credit provider; and (d) the credit provider were required to comply with subsection 21S(1) in relation to the credit eligibility information. Note: See section 21NA. 26WD Exception—notification under the My Health Records Act 2012 If: (a) an unauthorised access to information; or (b) an unauthorised disclosure of information; or (c) a loss of information; has been, or is required to be, notified under section 75 of the My Health Records Act 2012, this Part does not apply in relation to the access, disclosure or loss. Division 2—Eligible data breach 26WE Eligible data breach Scope (1) This section applies if: (a) both: (i) an APP entity holds personal information relating to one or more individuals; and (ii) the APP entity is required under section 15 not to do an act, or engage in a practice, that breaches Australian Privacy Principle 11.1 in relation to the personal information; or No. 12, 2017 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 5

Select target paragraph3