View full documentView full document Previous section | Next section
House of Representatives

National Security Legislation Amendment (Comprehensive Review and Other Measures No. 3) Bill 2023

Explanatory Memorandum

(Circulated by authority of the Minister for Home Affairs, the Honourable Clare O'Neil MP)

GENERAL OUTLINE

1. The National Security Legislation Amendment (Comprehensive Review and Other Measures No. 3) Bill 2023 (the Bill) would amend the Australian Security Intelligence Organisation Act 1979 (ASIO Act), the Intelligence Services Act 2001 (IS Act), the Telecommunications (Interception and Access) Act 1979 (TIA Act) and the Archives Act 1983 (Archives Act) to support intelligence agencies by:

a.
strengthening protections around the identity of their employees;
b.
improving the ability of the Australian Security Intelligence Organisation (ASIO) to communicate information, and providing additional protections for individuals through making the communication of certain information prescribed administrative action;
c.
increasing operational flexibility through updated approval processes for certain intelligence activities;
d.
clarifying provisions relating to the authorisation of certain intelligence activities; and
e.
providing for quicker processing of non-prejudicial security clearance suitability assessments.

2. The Bill would also promote increased oversight of our intelligence agencies by:

a.
promoting further oversight of the ASIO's work on security assessments and security clearance related activities under Parts IV and IVA of the ASIO Act, by requiring ASIO to notify the Inspector-General of Intelligence and Security where certain security assessments, security clearance decisions, and security clearance suitability assessments have not been made or furnished within 12 months; and
b.
making it clear that only the Attorney-General, and not junior ministers, can exercise certain powers under the TIA Act and ASIO Act.

3. The Bill would address 12 of the recommendations of the Comprehensive Review of the Legal Framework of the National Intelligence Community (Comprehensive Review) led by Dennis Richardson AC, relating to security assessments, the protection of identities and information, authorisations for intelligence activities, and oversight.

4. The Bill would also clarify the operation of existing provisions in the ASIO Act and the IS Act, and update the publication offence in the ASIO Act to take into account developments in technology and modern communications.

Security assessments

Schedule 1 of the Bill would amend the ASIO Act to:

extend the definition of prescribed administrative action to decisions relating to parole, firearms licences and security guard licences;
enable new categories of prescribed administrative action to be prescribed by the regulations;
clarify the application of the definitions in section 35 throughout Part IV;
enable ASIO to communicate information to a Commonwealth agency, a State or an authority of a State under subsection 18(3) or 19A(4), for the purposes of prescribed administrative action that is a decision relating to firearms licences and security guard licences;
clarify that a decision under the Foreign Acquisitions and Takeovers Act 1975 does not constitute prescribed administrative action;
enable ASIO to make a preliminary communication to Commonwealth agencies, States or authorities of a State on an urgent and temporary basis, where the information could be used for the purposes of certain prescribed administrative action; and
require ASIO to notify the Inspector-General of Intelligence and Security where certain security assessments are not furnished within 12 months.

Protecting identities and information

Schedule 2 of the Bill would amend the ASIO Act, the IS Act and the Archives Act to:

improve and enable cover employment arrangements and associated protections for current and former ASIO employees, ASIO affiliates and staff members of the Australian Secret Intelligence Service (ASIS), and Australian Signals Directorate (ASD);
consolidate secrecy offences relating to ASIS, ASD, the Australian Geospatial-Intelligence Organisation (AGO) and the Defence Intelligence Organisation (DIO);
make exempt under the Archives Act records that identify ASIO or ASIS employees, affiliates and agents; and
update and modernise the publication offence in the ASIO Act, which makes it an offence to make public the identity of current or former ASIO employees and affiliates, to take into account developments in technology and modern communications.

Authorisations for intelligence activities

Schedule 3 of the Bill would amend the ASIO Act, IS Act and the TIA Act to:

enable the Minister for Foreign Affairs and the Minister for Defence to authorise ASIS, ASD and AGO to undertake activities relating to an Australian person who is likely to be involved in activities that are likely to be a threat to security, before the Attorney-General gives their agreement to the authorisation. The authorisation will not take effect until the Attorney-General's agreement has been obtained;
clarify the Minister for Foreign Affairs and the Minister for Defence can authorise ASIS, ASD and AGO to undertake activities relating to an Australian person who is likely to be involved in activities that present a risk to their own safety, or are themselves involved in activities relating to a contravention of a UN sanction enforcement law;
remove the ability for a junior Minister to exercise a power under the ASIO Act or TIA Act; and
permit only the Director-General of Security to apply for an authority to conduct a special intelligence operation on behalf of ASIO.

Security vetting and security clearance related activities

Schedule 4 of the Bill would amend the ASIO Act to:

clarify the application of the definitions in section 82A throughout the Act;
support quicker processing of non-prejudicial security clearance suitability assessments by permitting the Director-General of Security to delegate their power or function to furnish non-prejudicial security clearance suitability assessments; and
require ASIO to notify the Inspector-General of Intelligence and Security where certain security clearance decisions and security clearance suitability assessments are not made or furnished within 12 months.

FINANCIAL IMPACT STATEMENT

The Bill has nil financial impacts.

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

National Security Legislation Amendment (Comprehensive Review and Other Measures No. 3) Bill 2023

This Bill is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the Bill

1. This Bill will implement the Government's response to some of the recommendations of the Comprehensive Review of the Legal Framework of the National Intelligence Community (the Comprehensive Review). The Comprehensive Review examined the effectiveness of the legislative framework governing the national intelligence community (NIC) and prepared findings and recommendations for reforms. This Bill addresses 12 of the outstanding recommendations of the Comprehensive Review, as well as a number of other measures identified as necessary in consultation with our national security agencies.

2. The measures in the Bill will support Australia's national security agencies by strengthening identity protections for their employees, increasing operational flexibility and sharing of information, clarifying some authorities to provide greater certainty, and supporting quicker processing of security clearance suitability assessments. The Bill will also promote increased oversight of our national security agencies by introducing additional safeguards to provide oversight of Australian Security Intelligence Organisation's (ASIO) work on security assessments and vetting, and limiting who can exercise certain powers.

3. The Bill will address the recommendations of the Comprehensive Review to:

Refine the framework for security assessments in the Australian Security Intelligence Organisation Act 1979 (ASIO Act) (Schedule 1 to the Bill) by:

o
Amending the definition of 'prescribed administrative action' in the ASIO Act to include the exercise of powers or functions in relation to parole, security guard licences and firearms licences (recommendation 193).
o
Inserting a regulation-making power into the definition of 'prescribed administrative action' in the ASIO Act. Such regulations must be reviewed by the Parliamentary Joint Committee on Intelligence and Security (the PJCIS), and be subject to an extended disallowance period (recommendation 194).
o
Providing that ASIO is not prevented from communicating information to States or authorities of a State in relation to the commission, or intended commission, of a serious crime or where it is required in the national interest (subsections 18(3) and 19A(4) of the ASIO Act).
o
Providing that decisions made under the Foreign Acquisitions and Takeovers Act 1975 are not 'prescribed administrative actions' under the ASIO Act (recommendation 197).
o
Amending the ASIO Act to allow ASIO to make a preliminary communication to a State or authority of the State, whether directly, or indirectly through a Commonwealth agency, where the requirements of security make it necessary and as a matter of urgency, to take action of a temporary nature pending the furnishing of a security assessment, including consequent to the amendments to the definition of 'prescribed administrative action' (recommendation 198).
o
Amending the ASIO Act to require ASIO to notify the Inspector-General of Intelligence and Security (IGIS), in accordance with a protocol, where it has taken longer than 12 months to finalise a security assessment. However, the requirement to notify will not apply for ASIO-initiated assessments or decisions, or if ASIO is notified the security assessment is no longer required (recommendation 199).
o
Clarifying the application of the definitions in section 35 in the ASIO Act.

Enhance the protection of identities of Australian Secret Intelligence Service (ASIS), Australian Signals Directorate (ASD) and ASIO staff members and the protection of intelligence information and documents (Schedule 2 to the Bill) by:

o
Amending the Intelligence Services Act 2001 (IS Act) to provide that the Director-General of ASIS and Director-General of ASD can authorise the use of a Commonwealth authority as the cover employer for staff members of ASIS and ASD, or former staff members of ASIS and ASD, including where the person became a staff member before the amendments commence or requires cover employment for a period that occurred before the amendments commence. The amendments will also provide an immunity from criminal liability for persons who facilitate, or provide support in furtherance of those cover arrangements. Section 41AC of the IS Act will provide protection from Commonwealth, State or Territory law to a person who, in the performance of the person's powers, functions or duties as a staff member, or functions attached to their professional capacity, facilitates the current or former ASIS or ASD staff member's cover arrangements for the purposes of subsection 41AA(1), in accordance with a determination under subsection 41AB(1). The protection only extends to actions that would not ordinarily be an offence if the Commonwealth authority were the current or former staff member of ASIS or ASD's employer (recommendation 70).
o
Amending the ASIO Act to provide that the Director-General of Security can authorise the use of an authority of the Commonwealth as the cover employer for ASIO employees and affiliates, or former ASIO employees and affiliates, including where the person became an employee or affiliate before the amendments commence or requires cover employment for a period that occurred before the amendments commence. The amendments will also provide an immunity from criminal liability for persons who facilitate or provide support in furtherance of those cover arrangements. Section 92D of the ASIO Act will provide protection from Commonwealth, State or Territory law to a person who, in the performance of the person's powers, functions or duties as a staff member, or functions attached to their professional capacity, facilitates the current or former ASIO employee or ASIO affiliate's cover arrangements for the purposes of subsection 92B(1), in accordance with a determination under subsection 92C(1). The protection only extends to actions that would ordinarily not be an offence if the Commonwealth authority were the current or former ASIO employee or ASIO affiliate's employer.
o
Consolidating the secrecy offences in sections 39-40M of the IS Act (recommendation 143).
o
Protecting the identities of ASIO and ASIS staff members and agents from disclosure under the Archives Act 1983 (recommendation 190).
o
Amending the publication offence in the ASIO Act to strengthen the protections for the identity of ASIO employees and affiliates, and more closely align those protections with the protections currently afforded to the staff members and agents of ASIS under the IS Act.

Enhance the efficacy and efficiency of the authorisation processes for certain intelligence activities (Schedule 3 to the Bill) by:

o
Amending the IS Act ministerial authorisation process to enable the Attorney-General's agreement to enable an agency to produce intelligence on, or undertake activities that will or are likely to have a direct effect on, an Australian person, to be obtained before or after the authorisation of the responsible Minister to authorise an agency. This measure will allow the Attorney-General and relevant Minister to provide agreement or authorisation in any order, providing practical flexibility. Regardless of the order in which the authorisation is sought, it will not take effect until the Attorney-General has given their agreement (recommendation 2).
o
Providing that under the ASIO Act and the Telecommunications (Interception and Access) Act 1979 (TIA Act), the powers vested in the Attorney-General may only be exercised by the Attorney-General and not by a junior minister (recommendation 17).
o
Providing that applications to the Attorney-General for a special intelligence operation authorisation should only be made by the Director-General of Security (recommendation 68).
o
Clarify the references to 'a person' in Division 1 of Part 2 of the IS Act.
o
Updating the 'serious risk' to safety threshold in section 9B of the IS Act to 'significant risk' to safety, in line with other provisions in that Act.

Increase oversight and clarify provisions relating to security vetting and security clearance related activities in the ASIO Act (Schedule 4 to the Bill) by:

o
Amending paragraph 16(1C)(b) of the ASIO Act to allow the Director-General to delegate the power or function to make non-prejudicial security clearance suitability assessments (SCSAs) to any suitable ASIO employee or affiliate.
o
Clarifying the application of the definitions in section 82A in the ASIO Act.
o
Amending the ASIO Act to require ASIO, to notify the IGIS, in accordance with a protocol, where it has taken longer than 12 months to finalise a security clearance suitability assessment or security clearance decision. However, the requirement to notify will not apply for ASIO initiated assessments or decisions, or if ASIO is notified the security clearance suitability assessment or security clearance decision is no longer required (recommendation 199).

Human rights implications

4. This Bill engages the following rights under the International Covenant on Civil and Political Rights (ICCPR):

the prohibition on interference with privacy in Article 17;
the right to a fair hearing in Article 14(1); and
the right to freedom of expression in Article 19(2).

5. The Bill may also engage the right to work in Article 6(1) under the International Covenant on Economic, Social and Cultural Rights (ICESCR).

The prohibition on interference with privacy

6. Article 17 of the ICCPR provides:

(1) No person shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence.
(2) Everyone has the right to the protection of the law against such interference or attacks.

7. Although the United Nations Human Rights Committee has not defined privacy, it should be understood to comprise freedom from unwarranted and unreasonable intrusions into activities that society recognises as falling within the sphere of individual autonomy.

8. This right may be subject to permissible limitations where those limitations are provided by law and are non-arbitrary. In order for limitations to not be arbitrary, they must be aimed at a legitimate objective and be reasonable, necessary and proportionate to that objective.

The right to a fair hearing

9. Article 14(1) of the ICCPR relevantly provides that all persons shall be equal before the courts and tribunals and, in the determination of their rights and obligations in a suit at law, everyone shall be entitled to a fair and public hearing before a competent, independent and impartial court or tribunal established by law.

The right to freedom of expression

10. The right to freedom of expression in Article 19(2) of the ICCPR includes the freedom to seek, receive and impart information and ideas of all kinds, regardless of frontiers, either orally, in writing or in print, in the form of art, or through any other media of his choice. This extends to a right of access to information held by public bodies.

11. Article 19(3) relevantly states that the exercise of the right to freedom of expression carries with it special duties and responsibilities, and may therefore be subject to certain restrictions but only where these are provided by law and are necessary, for the protection of national security or public order.

Right to Work

12. The right to work in Article 6(1) of the ICESCR provides that States recognise the right to work, which includes the right of everyone to the opportunity to gain his or her living by work which he or she freely chooses or accepts, and will take appropriate steps to safeguard this right. The right to work does not equate to a guarantee to particular employment. As the Parliamentary Joint Committee on Human Rights (PJCHR) notes in its Guide to Human Rights, the right to work:

... is not to be understood as providing an unconditional right to obtain employment or for the state to provide everyone with employment; rather it is a right to choose an occupation and engage in work. It applies to all types of work, both in the public and private sectors, and to the formal and informal labour market.

Schedule 1 – Security assessments

13. Schedule 1 to the Bill relates to security assessments under Part IV of the ASIO Act. A security assessment is a statement in writing furnished by ASIO to a Commonwealth agency, State or authority of a State expressing any recommendation, opinion or advice on, or otherwise referring to, the question whether it would be consistent with the requirements of security for prescribed administrative action to be taken in respect of a person, or whether the requirements of security make it necessary or desirable for prescribed administrative action to be taken in respect of a person.

14. Subsection 35(1) of the ASIO Act defines the types of action that are 'prescribed administrative action' for the purpose of Part IV.

15. Part IV of the ASIO Act currently provides that, subject to certain exceptions, a Commonwealth agency, State or authority of a State cannot take, refuse to take or refrain from taking prescribed administrative action on the basis of any communication in relation to a person made by ASIO, otherwise than in the form of a security assessment.

16. Part IV also provides that if ASIO furnishes a security assessment, then unless an exception applies, ASIO must notify the affected person of the security assessment, and that person may apply to the Administrative Appeals Tribunal (AAT) to seek merits review of the decision.

17. Schedule 1 to the Bill will amend subsection 35(1) of the ASIO Act to expressly classify certain actions that are and are not prescribed administrative action. It will also create new exceptions to the rule that ASIO cannot communicate information to a Commonwealth agency, State or authority of a State in relation to a person, otherwise than in the form of a security assessment.

Article 17 – Right to Privacy

18. New paragraphs 35(1)(g) and (h) will insert as new classes of prescribed administrative action the exercise of any power or performance of any function relating to parole, or a decision whether to issue or revoke a firearms licence or a licence to work as a security guard. Currently, ASIO's functions include communicating intelligence relevant to security with Commonwealth agencies and States, which can include information that may inform a decision by the Commonwealth agency, the State or authority of the State regarding parole or whether to issue or revoke a firearms licence or a licence to work as a security guard. The introduction of paragraphs 35(1)(g) and (h) will include decisions about parole, granting or revoking a firearms licence or granting or revoking a security guard licence as 'prescribed administrative action' and bring these communications within Part IV of the ASIO Act.

19. By providing that ASIO must communicate this information by way of a security assessment for the purposes of prescribed administrative action, subject to limited exceptions, this amendment will engage the right to privacy. To the extent that the right to privacy is engaged by classifying decisions about parole, firearms licences or security guard licences as prescribed administrative action, this measure will promote the right to privacy by bringing these communications within the scope of Part IV of the ASIO Act, including the requirement to notify the affected person of an assessment and AAT review mechanisms.

20. New subsection 39(3) of the ASIO Act will allow a Territory body (being a Commonwealth agency for the purposes of the ASIO Act) to take prescribed administrative action that are decisions relating to a firearms licence or a licence to work as a security guard, on the basis of certain ASIO communications other than security assessments, where ASIO has information relevant to the possible commission of a serious crime or a matter of national interest (subsections 18(3) and 19A(4)).

21. New subsection 40(3) of the ASIO Act will enable ASIO to communicate information to a State or authority of a State, other than by way of assessment, under subsections 18(3) and 19A(4) (which allow ASIO to communicate information to authorities of the Commonwealth or State where the information relates to the commission or intended commission of a serious crime, communications in the national interest or for the purposes of co-operating with or assisting another body in the performance of that body's functions).

22. The effect of these amendments is to ensure ASIO's continued ability to communicate information relevant to subsections 18(3) and 19A(4) to an authority given the effect of the introduction of paragraph 35(1)(h) would otherwise be to remove this ability in relation to firearms licences and licences to work as a security guard.

23. Without this change, the introduction of paragraph 35(1)(h) would prevent ASIO from providing information relevant to a firearms licence or a licence to work as a security guard to an authority under subsections 18(3) and 19A(4) of the ASIO Act, where they are considering prescribed administrative action in relation to the issuance or revocation of a firearms licence or licence to work as a security guard, until it is communicated in the form of a security assessment. For example, without this amendment, ASIO would not be able to provide a State authority with information under subsection 18(3) about a planned armed robbery, for the purpose of the State authority to use that information to cancel a firearms or security guard licence until it was received in the form of a security assessment. This could create a risk to public order and the rights and freedoms of others.

24. As this amendment is intended to enable ASIO to continue to communicate information under subsections 18(3) and 19A(4), the measure does not limit the right to privacy any further than the current ASIO Act provisions enable.

25. Currently, ASIO may communicate intelligence to States and authorities of States in relation to parole decisions, firearms licences and security guard licences, for purposes relevant to security, where it is relevant to security. ASIO is not required to provide this by way of a security assessment as decisions relating to these licences, and parole are generally, not prescribed administrative action. Consequent to new paragraph 35(1)(h), ASIO would not be permitted to communicate that intelligence otherwise than in the form of a security assessment, by operation of subsection 40(2). New subsection 40(1A) of the ASIO Act will enable ASIO to make a preliminary communication, pending the furnishing of a security assessment to a State or authority of a State (whether directly, or indirectly through a Commonwealth agency) as a matter of urgency for these purposes. New subsection 40(1B) sets out the temporary actions that a State or authority of a State may decide to take in response to a preliminary communication under new subsection 40(1A).

26. Currently, the ASIO Act prohibits ASIO from providing information to States and authorities of States other than in the form of a security assessment where it knows that information is intended or likely to be used by the State or authority of the State in considering prescribed administrative action against a person. As a result, ASIO may be faced with a situation where it is legally barred from communicating security advice to a State or authority of a State, even where it knows urgent action is required to prevent a threat to security.

27. Commonwealth and State authorities are increasingly working closely on security issues and ASIO has been called on to provide advice to State agencies more regularly. These measures will allow ASIO to communicate information to States and authorities of States in the event of an urgent threat to security where it is not possible to provide a formal security assessment in the timeframe. This will allow the State or authority to take temporary action as needed to address the threat. ASIO must follow up the preliminary communication by furnishing a formal security assessment as soon as reasonably practicable. The notification and review rights afforded under Part IV of the ASIO Act will then be available to the person the subject of the subsequent security assessment.

28. New paragraph 40(1B)(a) will enable ASIO to provide communications to States or authorities of States, or to Commonwealth agencies to transmit to States or authorities of States, as a matter of urgency to take action of a temporary nature to prevent access by a person to any information or place, access to which is controlled or limited on security grounds, or to prevent a person from performing an activity in relation to or involving a thing (other than an information or place), if the person's ability to perform that activity is controlled or limited on security grounds.

29. Enabling ASIO to provide communications for this purpose will engage and limit the right to privacy. However, the limitation is reasonable and necessary to ensure that States and authorities of States, are able to take action upon receipt of information that identifies imminent security risks to the Australian community. It is in the interests of public order, community safety and protecting the rights and freedoms of others to allow ASIO to communicate information, as a matter of urgency pending the furnishing of a security assessment, to a State or authority of a State. In particular, it enables States and authorities of States, and/or Commonwealth agencies transmitting to State and authorities of States, to take immediate action to prevent a threat to public order or national security. Further, such communication would enable ASIO to meet community expectations that, if it came into possession of relevant information, it would be provided to another agency for action as quickly as possible. Such action may only be of a temporary nature, and ASIO would be required to subsequently furnish a security assessment to give effect to that advice on a more permanent basis.

30. To the extent that new paragraph 40(1B)(b) enables States or authorities of States to take temporary action, the effect of this amendment is to ensure ASIO's continued ability to communicate information of this kind that is related to security as a matter of urgency. New paragraph 40(1B) does not further limit the right to privacy beyond existing provisions in the ASIO Act.

31. While the measure will engage the right to privacy, it will not limit the right beyond ASIO's existing powers and functions to communicate information related to security.

32. To the extent that new measures will limit the right to privacy, the limitations are reasonable and necessary to achieve the legitimate objectives of protecting national security and public order. Defining prescribed administrative action to include decisions about parole, firearms licences and security guard licences promotes the right to privacy and amendments to the ASIO Act consequent to this enable ASIO to continue to communicate advice in urgent situations does not change the existing engagement with the right to privacy.

Article 14(1) – Right to a Fair Hearing

33. Part IV of the ASIO Act provides that, subject to relevant exceptions, ASIO may only communicate information in relation to a person, to a Commonwealth agency, State or authority of a State, for the purposes of prescribed administrative action, in the form of a security assessment. Schedule 1 will amend the ASIO Act to introduce new categories of prescribed administrative action.

34. Part IV of the ASIO Act provides a mechanism for review in the AAT, where ASIO has furnished a person with an adverse or qualified security assessment.

35. Providing that decisions about parole, firearms licences and security guard licences are prescribed administrative actions will provide affected persons with access to the notification and review rights available under Part IV. Part IV provides that a person the subject of an adverse or qualified security assessment must be notified of that assessment. The person can then seek review of that assessment by the AAT. The availability of notification and review rights reduces any limitations on other rights that may be impacted by the furnishing of security assessments under Part IV.

Article 6(1) – Right to Work

36. Schedule 1 may impact a person's right to work by enabling ASIO to provide preliminary communications to a State or an authority of a State, or to a Commonwealth agency to transmit to a State or authority of a State, where the information could be used for the purposes of prescribed administrative action, in relation to matters that might impact a person's access to any information or place, or ability to perform an activity in relation to, or involving a thing, which is controlled on security grounds, in relation to their employment.

37. Subsection 40(1A) will make it a function of ASIO to make a preliminary communication directly to the State or the authority of the State, or indirectly through a Commonwealth agency for transmission to a State or authority of State, if the Director-General or an authorised person is satisfied that the requirements of security make it necessary as a matter of urgency for the State or authority to take action of a temporary nature. Following the preliminary communication, ASIO must furnish a security assessment, to support the taking of permanent action.

38. Temporary actions under paragraph 40(1B)(a) can include preventing access by a person to any information or place, or preventing a person from performing an activity in relation to, or involving, a thing on security grounds pending the furnishing of a security assessment. Such preliminary communications could result in a person's employment or employment prospects with that State in relation to particular roles or industries requiring such access or ability to carry out such activities being adversely affected. The right to work does not equate to a right to work in a particular position and this measure will not otherwise prevent a person seeking employment of their choosing that is not subject to the requirement to obtain and maintain a firearms licence or a security guard licence.

39. The amendment pursues the legitimate objectives of protecting the life and security of the Australian community, mitigating any imminent and significant risks to their safety, and addressing national security risks to Australia. To the extent that a person may be prevented from employment in a particular position as a result of a preliminary communication, any limitation on the right to work is reasonable, necessary and proportionate to achieving these objectives as it serves to protect people from a heightened risk of imminent harm. Currently, ASIO currently may face a situation where it is unable to communicate security advice to a State or authority of the State, even where it has information that urgent action is required to prevent a threat to security. These amendments intend to rectify this limitation.

40. Any limitation on the right to work is proportionate and the least rights restrictive means of achieving the above objectives, and will be implemented alongside a number of safeguards and preconditions:

action taken in reliance on the preliminary communication by a State or authority of the State must be of a temporary nature, and must only be taken to prevent access by a person to information, places or things, access to which is controlled on security grounds
ASIO must only communicate advice other than in the form of a security assessment where it is satisfied that the requirements of security make it necessary to provide the advice as a matter of urgency, and
the preliminary advice must be followed by a formal security assessment which must be furnished as soon as reasonably practicable.

To the extent that a preliminary communication may limit the right to work, any limitation is reasonable, necessary and proportionate in achieving a legitimate objective.

Schedule 2 – Protecting Identities and Information

Article 17 – Right to Privacy

41. Schedule 2 to the Bill includes measures which promote the right to privacy by:

exempting documents that identify or have the potential to identify current and future ASIO employees, ASIO affiliates, staff members of ASIS or agents of ASIS, from being accessed under the Archives Act 1983 (Archives Act); and
updating and modernising the publication offence in the ASIO Act, relating to ASIO employees and ASIO affiliates, to take into account developments in technology and modern communications. It introduces a new offence under the ASIO Act relating to disclosure of the identity of an ASIO employee or ASIO affiliate.

42. Section 31 of the Archives Act provides that a Commonwealth record that is in the open access period as defined in subsection 3(1) of the Archives Act, that is in the care of the Archives or in the custody of a Commonwealth institution and is not an exempt record, must be made available for public access. Proposed subsections 33(4A) and (4C) of the Archives Act will provide that a Commonwealth record is an exempt record if it contains information or matter that identifies or has the potential to identify an ASIO employee, an ASIO affiliate, a staff member of ASIS or an agent of ASIS.

43. The measures to exempt documents which identify ASIO and ASIS agents and affiliates from access under the Archives Act aims to protect personal information that identifies, or has the potential to identify, officers and agents who undertake action to support the proper performance of ASIO and ASIS. Given the sensitive nature of the work they perform, it is necessary that their identity be, and remain, protected even after their employment ceases. In furtherance of this objective, this measure promotes the right to protection against arbitrary interference with privacy by providing that identifying documents are exempt records under the Archives Act.

44. New section 92 modernises the publication offence so that any form of publication which identifies an ASIO employee or affiliate will be an offence, regardless of the mode by which the publication is made. The amendments will repeal and replace section 92 to remove the method of publication, namely in a newspaper or other publication, or by radio broadcast or television, or otherwise make public from the offence of making public the identity of ASIO employees and ASIO affiliates. The removal of particular types of publication methods takes into account developments in technology and modern methods of communication including social media, and ensures that the offences apply to making information public by any means. The existing designation of specific methods of publication rather than a blanket inclusion of all methods resulted in a potential gap in the legislation whereby methods of publication not specifically mentioned may not be considered as an offence. An exception to the offence provides that a former ASIO employee or affiliate can consent to their identity being made public.

45. This measure promotes the right to privacy of ASIO employees and affiliates by ensuring that offences relating to disclosure of identifying documents are not limited to particular modes of communication.

46. New section 92A introduces a new offence that will also promote the right to privacy of existing ASIO employees and affiliates, by prohibiting the disclosure of information that results in their identification where the person intended or knew that the disclosure would endanger the health or safety of a person, or where they intend to prejudice the effective performance of ASIO's functions. This offence promotes the right to privacy of current ASIO employees and affiliates by providing a penalty for the disclosure of identifying information about those persons.

Article 19(2) – Right to Freedom of Expression

47. Schedule 2 to the Bill includes measures which may engage the right to freedom of expression by:

exempting records that identify an ASIO or ASIS employees, affiliates and agents from the requirements of the Archives Act; and
updating and modernising the publication offence in the ASIO Act to take into account developments in technology and modern communications.

48. The effect of the amendments to the Archives Act is such that a document that includes information that identifies, or has the potential to identify, an ASIO employee, an ASIO affiliate, or a staff member or agent of ASIS cannot be made public. This restriction on access to documents limits the right to freedom of expression as it could curtail public reporting on matters relating to ASIO and ASIS. The measure is required to protect the lives and safety of ASIO employees, ASIO affiliates, or staff members or agents of ASIS as they may be targeted due to the nature of their work if their identity was published. To the extent that the measure limits the right to freedom of expression, any limitation is reasonable, necessary and proportionate in achieving the legitimate objective of protecting national security and the rights and freedoms of others.

49. To the extent that new section 92 extends the scope of the offence for making public the identity of ASIO employees and affiliates to additional medium types, the measure may engage the right to freedom of expression. This engagement is limited to means of expression not already an offence under current section 92 of the ASIO Act. It is necessary to protect the identity of certain classes of persons who provide services to ASIO in the performance of their statutory functions. ASIO employees and affiliates often perform their roles, at great personal risk, in the interests of Australia's national security. Identification of such persons, whether published broadly or in limited circumstances, has the potential to result in grave harm to these individuals, including risk to life, if their connections to ASIO were exposed. If such protections were not afforded to these individuals this might impact their willingness to provide assistance. It is reasonable and proportionate that the current offence be updated to remove limitations on the methods of publication, so that the offence will apply regardless of the means by which the information is made public.

50. New subsection 92(2) provides an exception to the offence in subsection 92(1) where the responsible Minister or Director-General of Security has consented in writing to the information being made public, which is currently allowed for under the replaced subsection 92(1). New subsection 92(2A) allows for a third party to rely on consent from a former ASIO employee or affiliate to make information public where it would otherwise be an offence under subsection 92(1). It will also be an exception under subsection 92(3) where the former ASIO employee or affiliate causes or authorises the information to be made public. The offence is proportionate to the legitimate objectives of seeking to protect the identities of former ASIO employees and affiliates, and protecting national security, as prosecution for the offence can only be instituted by or with the consent of the Attorney-General.

51. New section 92A of the ASIO Act will make it an offence for a person to disclose information that identifies, or is likely to result in the identification of an ASIO employee or ASIO affiliate or a former ASIO employee or affiliate, where the person intends or knows that the disclosure will endanger the health or safety of a person or where they intend to prejudice the effective exercise of ASIO's powers. Identification of such persons, whether published broadly or in limited circumstances, has the potential to result in grave harm to these individuals, including risk to life, if their connections to ASIO were exposed. This measure addresses this risk by providing that it is an offence to publicly identify former or current ASIO employees or affiliates where the health or safety of a person would be at risk, or where the intent is to prejudice ASIO's operations.

52. This restriction on disclosure of information regarding the identities of ASIO personnel may limit the right to freedom of expression.

53. The purpose of these amendments is to protect the identity of certain classes of persons who provide services to ASIO in the performance of their statutory functions. ASIO employees and ASIO affiliates often perform these roles, at great personal risk, in the interests of Australia's national security. If such protections were not afforded to these individuals this might impact their willingness to provide assistance. This could also have national security and public order implications. As such, it is reasonable that publication of such information be treated as a serious offence. Article 19(3) states that the exercise of the right to freedom of expression carries with it special duties and responsibilities, and may therefore be subject to certain restrictions but only where these are provided by law and are necessary, for the protection of national security or public order. It is reasonable, necessary and proportionate to provide a strong disincentive to publishing the identities of former and current ASIO employees and affiliates to protect those employees and affiliates and the operations of ASIO.

Article 14(2) – Right to a Fair Hearing

54. The right to a fair hearing and a fair trial includes the right in article 14(2) to the presumption of innocence until guilt is proven. Offences which place an evidence burden on a defendant limit the right to be presumed innocent.

55. Notes to subsections 92(2) and 92(3) provide that the defendant bears the evidential burden of proving that they have the written consent or have received authorisation to make public the information. This will limit the right to be presumed innocent in Article 14(2). However this limitation is reasonable, necessary and proportionate due to the deteriorating security environment making those working in the intelligence community 'high value targets'. Publication of the identity of a former ASIO employee or ASIO affiliate has the potential to cause grave harm to security. Release of the identity of former ASIO employees or ASIO affiliates would substantially increase the risk they will be targeted by hostile third parties to undermine Australia's security, and put the lives of ASIO employees and affiliates, as well as their families, at risk. In these circumstances, it is appropriate that a person seeking to rely on consent or authorisation to make public the identity of a former ASIO employee or affiliate bear the burden of providing evidence that they had the relevant consent or authorisation to do so. In most circumstances, it will be evidence that will be held by the person seeking to rely on the exception. To the extent that the reverse onus of proof limits the right to be presumed innocent, the limitation is reasonable, necessary and proportionate.

Schedule 3 – Authorisations for intelligence activities

Article 17 – Right to Privacy

56. Schedule 3 to the Bill includes amendments to the ministerial authorisation framework in the IS Act.

57. Section 8 of the IS Act provides that the responsible Minister in relation to ASIS, the Australian Geospatial-Intelligence Organisation (AGO) and ASD must issue a written direction, that amongst other things, must require ASIS, AGO and ASD to obtain an authorisation before undertaking activities for the specific purpose of producing intelligence on, or that will, or are likely to, have a direct effect on, an Australian person.

58. Section 9 of the IS Act provides that, before the responsible Minister may give an authorisation, the Minister must be satisfied of a number of matters, including the matters specified in subsection 9(1A): that the Australian person is, or is likely to be involved in different categories of activities including, among other things, activities that present a serious risk to a person's safety and activities that are, or are likely to be, a threat to security. Pursuant to existing paragraph 9(1A)(b), before the Minister may give an authorisation in relation to a person who is, or is likely to be involved in activities that are, or are likely to be, a threat to security, they must first obtain the agreement of the Attorney-General.

59. The amendments proposed to be introduced by Schedule 3 do not substantially alter the privacy impact of the ministerial authorisation framework. New subsections 9(1A), (1AAA), (1AAC) and (1AAD) will amend the IS Act to provide that the agreement of the Attorney-General can be provided before or after the authorisation of the Minister. The effect remains the same, in that both the responsible Minister's authorisation and the Attorney-General's agreement is required before ASIS, AGO or ASD may undertake the activity to produce intelligence, or that is likely to have a direct effect on the person.

Conclusion

60. The Bill is compatible with human rights because it promotes human rights and, to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate.

NOTES ON INDIVIDUAL CLAUSES

Clause 1 Short title

This clause would provide for the short title of the Bill on its enactment to be the National Security Legislation Amendment (Comprehensive Review and Other Measures No. 3) Act 2023.

Clause 2 Commencement

This clause would provide for the commencement of each provision of the Act.

Subclause 2(1) would provide each provision of the Act specified in column 1 of the table commences, or is taken to have commenced, in accordance with column 2 of the table, and any other statement in column 2 would have effect according to its terms.

Table item 1 would provide sections 1 to 3 and anything in the Act not elsewhere covered by the table would commence the day the Act receives the Royal Assent.

Table item 2 would provide Division 1 of Part 1 of Schedule 1 would commence the day after the Act receives the Royal Assent.

Table item 3 would provide Division 2 of Part 1 of Schedule 1 would commence immediately after the commencement of the provisions covered by table item 2, to ensure the paragraphs relating to the definition of prescribed administrative action are inserted into the Australian Security Intelligence Organisation Act 1979 in the correct order.

Table item 4 would provide Divisions 1 and 2 of Part 2 of Schedule 1 would commence the day after the Act receives the Royal Assent.

Table item 5 would provide Divisions 3 and 4 of Part 2 of Schedule 1 would commence at the same time as the provisions covered by table item 3, to ensure the provisions amending sections 39 and 40 of the Australian Security Intelligence Organisation Act 1979 are inserted in the correct order.

Table item 6 would provide Part 3 of Schedule 1 would commence on a single day to be fixed by Proclamation, or if the provisions do not commence within the period of 6 months beginning on the day the Act receives the Royal Assent, the day after the end of that period. This would provide ASIO with up to 6 months to develop a protocol in consultation with the IGIS, ensure its staff are appropriately trained, and ensure its systems, policies and procedures are adequate to perform the powers, functions and duties in accordance with Part IV of the Australian Security Intelligence Organisation Act 1979 and that protocol.

Table item 7 would provide Schedules 2 and 3 would commence the day after the Act receives the Royal Assent.

Table item 8 would provide Part 1 of Schedule 4 would commence the day after the Act receives the Royal Assent.

Table item 9 would provide Part 2 of Schedule 4 would commence at the same time as the provisions covered by table item 6. This would provide ASIO with up to 6 months to develop a protocol in consultation with the IGIS, ensure its staff are appropriately trained, and ensure its systems, policies and procedures are adequate to perform the powers, functions and duties in accordance with Part IVA the Australian Security Intelligence Organisation Act 1979 and that protocol.

Subclause 2(2) would provide any information in column 3 of the table is not part of the Act, and information may be inserted in the column, or information in it may be edited, in any published version of the Act.

Clause 3 Schedules

This clause would provide that the legislation specified in a Schedule to the Act is amended or repealed as set out in the applicable items in the Schedule. Any other item in a Schedule to the Act has effect according to its terms.

SCHEDULE 1 - Security assessments

Part 1 – Prescribed administrative action

Division 1 – Decisions relating to parole, firearm licences and security guard licences

1. This division would amend the application of Part IV of the ASIO Act in respect of certain decisions.

2. Part IV, amongst other things, sets out the manner in which ASIO may provide advice to Commonwealth agencies, States and authorities of a State. It also provides a mechanism for review of adverse or qualified security assessments in the Administrative Appeals Tribunal (AAT).

3. Specifically, this division would provide that the exercise of power or the performance of functions in relation to a decision relating to parole, firearms and security guard licences is prescribed administrative action. These amendments will not change ASIO's ability to provide advice to States and Territories or authorities of a State or Territory about an individual's suitability to hold firearms or security guard licences, and to provide advice in relation to parole decisions. The amendments however would ensure the individual affected by the decision is to be notified of the advice, and also allows for review by the AAT. It also provides for circumstances in which ASIO may communicate information, not amounting to a security assessment, relating to these decisions.

4. This division would implement recommendation 193 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 1 Subsection 35(1) (after paragraph (f) of the definition of prescribed administrative action )

5. This item would insert in the definition of prescribed administrative action two new categories.

6. Paragraph (g) relates to the exercise of any power or performance of any function in relation to a decision relating to parole.

7. Paragraph (h) relates to the exercise of any power or performance of any function in relation to a decision relating to a firearms licence or a licence for a person to work as a security guard.

Item 2 Subsection 39(1)

8. This item would omit "subsection (2)" and substitute "subsections (2) and (3)" in subsection 39(1). This would be a consequence of Item 3.

Item 3 At the end of section 39

9. This item would add subsection 39(3) to section 39. Subsection 39(3) would provide an exception to the restriction in subsection 39(1) which prevents Commonwealth agencies from taking, refusing to take or refraining from taking prescribed administrative action on the basis of communications by ASIO that does not amount to a security assessment.

10. Subsection 39(3) would enable a Commonwealth agency to make a decision relating to a firearms licence or a licence for a person to work as a security guard on the basis of a communication made by ASIO under subsections 18(3) or 19A(4). Subsections 18(3) and 19A(4) allow ASIO to communicate information to authorities of the Commonwealth or State that ASIO has received in the course of ASIO performing its functions where the information relates to the commission or intended commission of a serious crime, communications in the national interest or for the purposes of co-operating with or assisting another body in the performance of that body's functions.

11. As a communication under subsections 18(3) or 19A(4) may be for purposes unrelated to security, such a communication might not meet the definition of a security assessment.

Item 4 At the end of section 40

12. This item would add subsection 40(3) to section 40 to provide an exception to the restriction in subsection 40(2). Subsection 40(2) prevents ASIO from furnishing information, recommendations, opinions or advice (except in the form of a security assessment) to States or authorities of a State where ASIO knows the State or authority intends or is likely to use the recommendation, opinion or advice in considering prescribed administrative action. Subsection 40(2) also prevents ASIO from furnishing information, recommendations, opinions or advice (except in the form of a security assessment) to a Commonwealth agency if ASIO knows the Commonwealth agency intends to communicate it to a State or authority for use in considering prescribed administrative action.

13. Subsection 40(3) would enable ASIO to communicate information under subsections 18(3) or 19A(4), to a State or authority of a State, to enable the State or authority of a State to make a decision relating to a firearms licence or a licence for a person to work as a security guard. Subsection 18(3) and 19A(4) allow ASIO to communicate information to authorities of the Commonwealth or State that ASIO has received in the course of ASIO performing its functions where the information relates to the commission or intended commission of a serious crime, communications in the national interest or for the purposes of co-operating with or assisting another body in the performance of that body's functions.

14. As a communication under subsections 18(3) or 19A(4) may be for purposes unrelated to security, such a communication might not meet the definition of a security assessment.

15. Without Item 4, the effect of Item 1 would be to prevent ASIO from communicating information under subsections 18(3) or 19A(4) which ASIO knows is intended or likely to be used by a State or an authority of a State in considering decisions about firearms or security licences, because subsection 40(2) prohibits ASIO from furnishing information for use by a State or an authority of a State in considering prescribed administrative action, otherwise than in the form of a security assessment. Item 4 is therefore necessary to ensure ASIO maintains its ability to communicate information in its possession consistent with subsections 18(3) and 19A(4).

Item 5 Application of amendments

16. This item would provide that the amendments made by this division apply only in relation to a communication by ASIO on or after the commencement of this item.

Division 2 – Regulations to prescribe actions as prescribed administrative action

17. This division would provide a mechanism to introduce new classes of prescribed administrative action, for the purposes of determining whether a recommendation, opinion or advice by ASIO constitutes a security assessment for the purposes of Part IV. This division would implement recommendation 194 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 6 Subsection 35(1) (after paragraph (h) of the definition of prescribed administrative action )

18. This item would insert paragraph (i) in the definition of prescribed administrative action, an action prescribed by the regulations for the purposes of this paragraph.

Item 7 After section 35

19. This item would insert new section 36AA of the ASIO Act, which relates to prescribing action as prescribed administrative action.

20. Subsection 36AA(1) would provide that regulations made for the purposes of paragraph (i) of the definition of prescribed administrative action may only prescribe an action if the action is likely to affect a person's liberty or livelihood and matters relating to security would be a primary consideration in deciding whether to take the action.

21. This threshold is included to ensure that ASIO advice about actions that may substantially adversely affect a person's interests, where the matters relating to security would be a primary consideration in deciding whether to take action, is regulated by Part IV (which may require the person to be notified and provide for review by the AAT).

22. For the avoidance of doubt, there is no requirement for security to be the primary consideration whether action is taken, as long as it is a primary consideration, amongst other key considerations.

23. Subsection 36AA(2) would provide that a decision to prescribe new types of prescribed administrative action must be reviewed by the Parliamentary Joint Committee on Intelligence and Security as soon as possible after relevant regulations are made, and the Committee's comments and recommendations must be reported to each House of the Parliament before the end of the applicable disallowance period.

24. This will ensure there is parliamentary scrutiny in respect of matters that may impact a person's rights, whilst at the same time providing greater flexibility to clarify when notification requirements and review rights should be available in respect of ASIO advice and communications.

25. Subsections 36AA(3) and (4) extends the applicable disallowance period for the regulations, depending on when the Committee provides its report under subsection 36AA(2). This will ensure that each House of Parliament has at least a week from when the report is tabled in that House to consider the regulations in light of the Committee's comments and recommendations.

Item 8 At the end of section 95

26. Section 95 of the ASIO Act is a regulation making power relating to matters required or permitted by the ASIO Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the ASIO Act.

27. Generally, the disallowance period for a legislative instrument is 15 sitting days of a House after a copy of the instrument was laid before that House under section 42 of the Legislation Act 2003.

28. This item inserts a note in section 95 stating that the disallowance period for regulations made for the purposes of paragraph (i) of the definition of prescribed administrative action in section 35(1) could be extended by reason of section 36AA. The purpose of this note is to highlight the different disallowance periods that could apply to regulations made under the ASIO Act to facilitate the proper administration of the legislation.

Part 2 – Security assessments and preliminary communications

Division 1 – Decisions under the Foreign Acquisitions and Takeovers Act 1975

29. This division would amend the application of Part IV of the ASIO Act in respect of certain decisions.

30. Part IV, amongst other things, sets out the manner in which ASIO may provide advice to Commonwealth agencies, States and authorities of a State. It also provides a mechanism for review of adverse or qualified security assessments in the AAT.

31. Specifically, this division would provide that decisions made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act are not prescribed administrative action. As such, a recommendation, opinion or advice by ASIO would not constitute a security assessment for the purposes of Part IV. This item would give effect to recommendation 197 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 9 Subsection 35(1) (definition of prescribed administrative action )

32. This item would insert the phrase ", subject to subsections (1A) and (2)," into the definition of prescribed administrative action. This would be a consequence of Item 11.

Item 10 Subsection 35(1) (at the end of the note to the definition of prescribed administrative action )

33. This item would add to the note to the definition of prescribed administrative action that a decision made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act is also not prescribed administrative action (see subsection (1A)). This would be a consequence of Item 11.

Item 11 After subsection 35(1)

34. This item would insert new subsection 35(1A) to clarify that a decision made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act is not prescribed administrative action.

35. Under the Foreign Acquisitions and Takeovers Act 1975, the Treasurer may make orders to prohibit a foreign entity from taking certain action on grounds relating to national security. In considering whether to make a decision, ASIO may provide advice relating to security to the Treasurer.

36. The effect of Item 11 is to clarify therefore that any advice provided by ASIO to the Treasurer for the purpose of a decision under the Foreign Acquisitions and Takeovers Act 1975 would not be covered by Part IV of the ASIO Act, as the action taken as a result of such communication would not be prescribed administrative action. The entity would not be required to be notified of that advice and would have no right of merits review at the AAT. Clarifying that ASIO advice is not covered by Part IV is also consistent with the position on the Treasurer's decisions under the Foreign Acquisitions and Takeovers Act 1975 themselves, which are exempt from review under the Administrative Decisions (Judicial Review) Act 1977.

Item 12 Application of amendments

37. This item would provide that the amendments made by this division apply only in relation to a communication by ASIO on or after the commencement of this item.

Division 2 – Clarification of effect of definitions on certain security assessments

Australian Security Intelligence Organisation Act 1979

Item 13 Subsection 36(1)

38. This item would insert a reference to section 35 in subsection 36(1), to ensure the defined terms set out in section 35 apply in respect of security assessments to which Part IV does not otherwise apply.

39. Section 35 contains a number of definitions for the purposes of Part IV of the Act. Section 36 sets out certain security assessments to which the notice and review provisions of Part IV does not apply. In addition the chapeau in subsection 36(1) provides an exception for these security assessment so that subsections 37(1), 37(3) and 37(4) (which are in Part IV of the Act) will apply to these security assessments. By inserting a reference to section 35 into subsection 36(1), the amendment clarifies that the definitions in section 35 apply to the security assessments described in section 36 to which Part IV of the Act does not otherwise apply.

Item 14 At the end of section 36

40. This item would add subsection 36(3), which clarifies that section 36 is not intended to affect the interpretation of any other provision of Part IV.

Division 3 – Preliminary communications to States

41. This division would amend the ASIO Act to enable ASIO to communicate information, whether directly, or indirectly through a Commonwealth agency, to a State or an authority of a State for the purpose of enabling that State or authority to take certain prescribed administrative action, where it would be necessary as a matter of urgency to take that action. These provisions are modelled on the existing section 39, which relate to Commonwealth agencies. This would give effect to recommendation 198 of the Comprehensive Review.

42. Nothing in this division is intended to impact or otherwise limit ASIO's ability to provide information, recommendation, opinion or advice concerning a person, which is not intended or likely to be used by a State or an authority of a State in considering prescribed administrative action in relation to the person, or ASIO's ability to cooperate with Departments, Police Forces and authorities of the States.

Australian Security Intelligence Organisation Act 1979

Item 15 Paragraph 17(1)(ca)

43. This item would insert the words "and make preliminary communications" to ASIO's function at paragraph 17(1)(ca) to ensure that ASIO can make preliminary communications to a State or authority of a State in accordance with section 40.

Item 16 Paragraph 17(1)(ca)

44. This item would insert a reference to paragraph 40(1A)(a) to ASIO's function at paragraph 17(1)(ca) to ensure that ASIO can make preliminary communications to a State or authority of a State in accordance with section 40.

Item 17 Section 40 (heading)

45. This item would insert "and preliminary communications" into the heading of section 40.

Item 18 After subsection 40(1)

46. This item would insert provisions to ensure that ASIO can make a preliminary communication to a State, an authority of a State, or a Commonwealth agency for transmission to a State or an authority of a State to enable that State or authority to take certain prescribed administrative action as a matter of urgency, pending the furnishing of a security assessment.

47. Subsection 40(1A) would make it a function of ASIO to make a preliminary communication directly to the State or the authority of the State, or indirectly through a Commonwealth agency for transmission to a State or authority of State, if the Director-General or an authorised person is satisfied that the requirements of security make it necessary as a matter of urgency for the State or authority to take certain prescribed administrative action. The classes of action that can be taken is specified in paragraph 40(1B)(a). Following the preliminary communication, ASIO must furnish a security assessment, to inform the taking of permanent action. The provision does not specify a timeframe for ASIO to furnish the security assessment, but this should take place as soon as reasonably practicable taking into account the circumstances of each case.

48. Paragraph 40(1B)(a) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature to prevent access by a person to any information or place access to which is controlled or limited on security grounds, or prevent a person from performing an activity in relation to, or involving, a thing if the person's ability to perform that activity is controlled or limited on security grounds. This is intended to align with paragraph (a) of the definition of prescribed administrative action in subsection 35(1) of the ASIO Act.

49. Paragraph 40(1B)(b) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature, of a kind referred to in paragraphs (g) and (h) of the definition of prescribed administrative action, being action in relation to decisions relating to parole, firearms licences and licences to work as a security guard. This aligns with the new categories of prescribed administrative action that would be introduced by Item 1.

50. Paragraph 40(1B)(c) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature, of a kind referred to in paragraph (i) of the definition of prescribed administrative action, that has also been prescribed by the regulations for the purpose of subparagraph 40(1B)(c)(ii). This is to account for the possibility that it might be appropriate for ASIO to communicate information, on an urgent basis to a State or an authority of a State in respect of new classes of prescribed administrative action, pending the furnishing of a security assessment. New classes of prescribed administrative action, as introduced by Item 6, also need to be prescribed for subparagraph 40(1B)(c)(ii) in order for ASIO to make a preliminary communication directly or indirectly to a State or authority.

Item 19 Subsection 40(2)

51. This item would omit "shall not" and substitute "must not, other than in the form of an assessment or in accordance with subsection (1A)" in subsection 40(2).

52. This item, and Item 20 would modify the provision that prohibits ASIO from giving advice to a State or an authority of State otherwise than in the form of a security assessment. Relevantly, it enables ASIO to make a preliminary communication in accordance with subsection 40(1A).

Item 20 Paragraphs 40(2)(a) and (b)

53. This item would omit the words "otherwise than in the form of an assessment" in paragraphs 40(2)(a) and 40(2)(b).

54. This item, and Item 19 would modify the provision that prohibits ASIO from giving advice to a State or an authority of State otherwise than in the form of a security assessment. Relevantly, it enables ASIO to make a preliminary communication in accordance with subsection 40(1A).

Item 21 At the end of section 40

55. This item would insert subsection 40(4) to enable the Director-General of Security to authorise in writing, a person for the purposes of subsection 40(1A). The authorisation can be made in respect of a person who is an ASIO employee or an ASIO affiliate who holds, or is acting in a SES equivalent or higher position within ASIO.

56. The effect of an authorisation is that ASIO may, make a preliminary communication to a State or an authority of a State if the Director-General of Security or an authorised person is satisfied the requirements of security make it necessary as a matter of urgency for the State or authority to take the action.

57. Under this item, the Director-General of Security may authorise an ASIO employee or an ASIO affiliate who holds, or is acting in an SES equivalent or higher position within ASIO. The inclusion of ASIO affiliates is necessary to ensure persons seconded to ASIO from partner agencies can exercise these functions. Any action taken by the ASIO affiliate would be done on behalf of ASIO in the performance of its statutory functions, as set out in section 17. This ability to only authorise persons holding or acting in a SES position is important in that it significantly limits who may enable ASIO to make a preliminary communication to a State or authority of a State (or a Commonwealth agency who intends to communicate it to a State or authority of a State), where they are satisfied that the requirements of security make it necessary as a matter of urgency for relevant action to be taken.

58. Insofar as the authorisation extends to ASIO affiliates holding or acting in an ASIO SES position, the ASIO affiliate could be a secondee from another agency. The Director-General of Security can be expected to give appropriate consideration as to whether such an affiliate is suitable to occupy such a position when appointing the affiliate to that position. Persons holding SES positions within ASIO are the most senior public servants in ASIO, with extensive relevant experience, whether they are ASIO employees or ASIO affiliates.

Item 22 Application of amendments

59. This item would provide that the amendments made by this Division apply in relation to a communication made by ASIO after the commencement of this item.

Division 4 – Temporary action by Commonwealth agencies

60. This division would amend the ASIO Act to expand the circumstances in which a Commonwealth agency can take prescribed administrative action on the basis of a communication made by ASIO not amounting to a security assessment, where it would be necessary as a matter of urgency to take that action. These provisions are a consequence of the new categories of prescribed administrative action that would be introduced by Item 1.

Australian Security Intelligence Organisation Act 1979

Item 23 Subsection 39(1)

61. This item would include a reference to subsection 39(4) in subsection 39(1). This would be a consequence of Item 24.

Item 24 At the end of section 39

62. This item would insert provisions to enable a Commonwealth agency to take certain prescribed administrative action as a matter of urgency on the basis of a communication made by ASIO not amounting to a security assessment, pending the furnishing of a security assessment.

63. Paragraph 39(4)(a) would provide that subsection 39(1) does not prevent a Commonwealth agency from taking action that is of a temporary nature and is of a kind referred to in paragraphs (g) and (h) of the definition of prescribed administrative action, being decisions relating to parole, firearms licences and licences to work as a security guard, if on the basis of a preliminary communication by ASIO, the Commonwealth agency is satisfied the requirements of security make it necessary to take action as a matter of urgency, pending the furnishing of a security assessment. This aligns with the new categories of prescribed administrative action that would be introduced by Item 1.

64. Paragraph 39(4)(b) would provide that subsection 39(1) does not prevent a Commonwealth agency from taking action that is of a temporary nature and is prescribed administrative action of a kind prescribed in the regulation, that is also prescribed for the purposes of subparagraph 39(4)(b)(ii), if on the basis of a preliminary communication by ASIO, the Commonwealth agency is satisfied the requirements of security make it necessary to take action as a matter of urgency, pending the furnishing of a security assessment. This is to account for possibility that it might be appropriate for a Commonwealth agency to take action of a temporary nature, on an urgent basis on the basis of a communication made by ASIO not amounting to a security assessment, pending the furnishing of a security assessment in respect of new classes of prescribed administrative action. This aligns with the new category of prescribed administrative action that would be introduced by Item 6.

Item 25 Application of amendments

65. This item would provide that the amendments made by this Division apply in relation to a communication made by ASIO after the commencement of this item.

Part 3 – Delayed security assessments

66. This part would amend the ASIO Act to require the Director-General to cause the Inspector-General of Intelligence and Security to be notified of certain security assessments not made within 12 months from when ASIO commences preparation of the assessment.

67. This part would respond to recommendation 199 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 26 Subsection 35(1)

68. This item would insert a definition of "delayed security assessment" into subsection 35(1). The effect of this item would be that a reference to "delayed security assessment" in Part IV would have the meaning given by subsection 41(1).

Item 27 Subsection 36(1)

69. This item would omit the reference to "subsection 35" and substitute "sections 35, 41 and 42" into subsection 36(1). The effect of this item would be that notwithstanding that the requirements of Part IV do not apply to the classes of security assessments mentioned in section 36, ASIO would still be required to notify the Inspector-General of Intelligence and Security of delays in the furnishing of such assessments should they fall within the definition of delayed security assessment.

Item 28 At the end of Division 2 of Part IV

70. This item would add provisions to require the Director-General of Security to cause the Inspector-General of Intelligence and Security to be notified of certain security assessments that are not furnished within 12 months after ASIO starts to prepare the assessment, in accordance with a written protocol made by the Director-General of Security.

71. Subsection 41(1) would provide that if a security assessment is not furnished under Part IV within 12 months after ASIO starts to prepare the assessment, the Director-General of Security must cause the Inspector-General of Intelligence and Security to be notified of the delayed security assessment. These security assessments are defined as "delayed security assessments". The method by which the Director-General may cause the Inspector-General of Intelligence and Security to be notified is not prescriptive, but may include directing an ASIO employee or ASIO affiliate, developing policies and procedures requiring a person holding a particular position to do the notifying, or set up processes (including automated processes) to cause the notification.

72. The note to subsection 41(1) would direct the reader to subsection 42(1) which provides that a protocol must be made under that subsection, and specify when ASIO is taken to have started to prepare a security assessment, which may be specified differently for different classes of security assessments (referencing subsections 42(3) and (4)).

73. Subsection 41(2) would provide that the notification under subsection 41(1) must be made within the period specified in the protocol for the purposes of subparagraph 42(3)(b)(i), include the information specified in the protocol as required by subparagraph 42(3)(b)(ii), and comply with any other requirements specified in the protocol for the purposes of paragraph 42(3)(d). The reference to the protocol in subsection 41(2) is a reference to the protocol made under subsection 42(1) as in force from time to time (i.e. at the time the notification is made).

74. Subsection 41(3) would set out exceptions to the requirement to notify. Notification would not be required where ASIO has been notified that the security assessment is no longer required, or where ASIO had initiated the preparation of the security assessment. Paragraph 41(3)(a) is required because from time to time requests for security assessments will be withdrawn or are otherwise not required. Paragraph 41(3)(b) is required because ASIO, in the course of its activities, might self-initiate enquiries to establish whether prescribed administrative action is required in the interests of security. As this would be done internally by ASIO, without the subject being aware, it may be unnecessary for the assessment to be furnished within 12 months and therefore notification to the Inspector-General of Intelligence and Security would not be appropriate in the circumstances.

75. Subsection 41(4) would set out the application of section 41. It would provide that section 41 applies to a security assessment that ASIO starts to prepare on or after the commencement of section 41.

76. Subsection 42(1) would require the Director-General of Security to make a written protocol for dealing with delayed security assessments.

77. Note 1 to subsection 42(1) would alert the reader to subsection 33(3) of the Acts Interpretation Act 1901, which provides that where an Act confers a power to make an instrument, the power includes a power exercisable in the like manner and subject to the like conditions (if any) to repeal, rescind, revoke, amend, or vary any such instrument. This would confirm the power for the Director-General of Security to repeal, rescind, revoke, amend or vary a protocol made under subsection 42(1). For the avoidance of doubt, the Director-General of Security would be required to consult with the Inspector-General of Intelligence and Security before repealing, rescinding, revoking, amending or varying the protocol.

78. Note 2 to subsection 42(1) would note that such a protocol may be combined with a protocol made under subsection 82GB(1), which relates to delayed security clearance decisions and delayed security clearance suitability assessments. It is anticipated the Director-General of Security will prefer to make only one instrument, covering both subsection 42(1) and 82GB(1).

79. Subsection 42(2) would provide that the Director-General of Security must consult with the Inspector-General of Intelligence and Security before making a protocol under subsection 42(1).

80. Subsection 42(3) would set out what can, and must be dealt with in a protocol.

81. Paragraph 42(3)(a) provides that the protocol must specify when ASIO is taken to have started to prepare a security assessment.

82. ASIO's functions to advise Ministers and authorities of the Commonwealth in respect of matters relating to security and to furnish security assessments to a State or an authority of a State span across a broad range of Commonwealth, State and Territory functions and purposes. It is critical to the performance of these functions that ASIO has all the information necessary to give its security advice. Different classes of security assessments may require more information to be collected before ASIO is able to start to prepare the assessment, due to the nature and complexity of the advice sought and the function to which the advice would be applied. This paragraph would enable greater flexibility to deal with different classes of security assessments, to ensure ASIO is not required to notify the Inspector-General of Intelligence and Security of delays in the furnishing of security assessments, when the delays are a result of matters that are beyond ASIO's control.

83. Paragraph 42(3)(b) would provide that the protocol must specify the period in which notification of a delayed security assessment must be made, and the information to be included in the notification. These matters will necessarily engage questions of ASIO's internal processes and procedures which are classified. It is therefore necessary they be included in the protocol and not made public or set out in legislation.

84. Paragraph 42(3)(c) would provide that the protocol must deal with steps to be taken by ASIO in relation to a delayed security assessment, after the notification under section 41 is made. The purpose of the paragraph is to ensure the protocol includes steps to be taken beyond merely notifying the Inspector-General of Intelligence and Security of the delayed security assessment. Such steps could include providing an explanation to Inspector-General of Intelligence and Security of the reasons for taking longer than 12 months, directions to take steps as set out in relevant policies or procedures, or requiring relevant senior executive officers to be briefed.

85. Paragraph 42(3)(d) would provide that the protocol may specify other requirements, or deal with any other matters that relate to a delayed security assessment, or the notification of the assessment under section 41 and the Director-General of Security considers appropriate.

86. Subsection 42(4) would provide that the protocol may provide differently for different classes of security assessments. For example, the protocol may provide differently for security assessments relating to visa referrals from the Department of Home Affairs compared to security assessments relating to the AusCheck scheme.

87. Subsection 42(5) would provide that a protocol made under subsection 42(1) is not a legislative instrument. This provision would exempt the protocol from being a legislative instrument under the Legislation Act 2003.

88. ASIO provides security assessments to Ministers and authorities of the Commonwealth and States in respect of matters relating to security, on a broad range of different subject matters. The nature and purpose of this advice may expand over time – for example, to include decisions relating to parole, firearms licensing, and licences to work as a security guard as set out in Part 1 of Schedule 1 of this Bill.

89. It is necessary for this notification framework to take into account, the complexities and dependencies, relating to the classes of security assessments sought by the different Ministers and authorities, in the performance of their functions and responsibilities. It is thus, appropriate for the protocol to be made by instrument, which provides greater flexibility and adaptability for the provision of security advice, taking into account the environment in which ASIO operates.

90. Noting the types of information that are likely to be included in the protocol, including how ASIO manages different classes of security assessments ASIO furnishes, and the types of information ASIO requires to be able to perform its functions, the protocol will need to be classified in order to operate as intended. It therefore would not be suitable for inclusion in a legislative instrument, which would otherwise be available to the public. These processes are a key pillar of the Australian Government's overall ability to provide assurance that its classified information is secure. That the protocol is subject to consultation with the Inspector-General of Intelligence and Security, and its implementation will be monitored by the Inspector-General of Intelligence and Security, provides a safeguard to ensure the protocol is appropriately configured to the underlying purpose of promoting ASIO being accountable in respect of delayed security assessments.

91. Subsection 42(6) would provide that ASIO must in relation to a delayed security assessment to which subsection 41(1) applies, comply with a protocol made under subsection 42(1) as in force from time to time.

92.

SCHEDULE 2 - Protecting identities and information

Part 1 – Cover employment

Australian Security Intelligence Organisation Act 1979

93. This part would amend the ASIO Act to enable current and former ASIO employees and affiliates to identify an authority of the Commonwealth as the person's employer or place of work, where the authority has been determined by the Director-General of Security. Persons using cover employment, or facilitating cover under these arrangements would be protected from criminal liability if done in the proper performance of that person's duties, or in their professional capacity.

94. This part is intended to formalise and update existing cover arrangements for ASIO where it would be inappropriate for current and former ASIO employees and affiliates to identify ASIO as their employer for security reasons. It would give effect to recommendation 71 of the Comprehensive Review.

95. For the avoidance of doubt, it is not intended that a person who identifies another authority of the Commonwealth as their employer or place of work, would be able to perform the functions of that authority of the Commonwealth, or exercise the powers conferred on officers of that authority (however described). The amendments that would be introduced by this part only relates to the identification of that authority as the person's employer or place of work.

Item 1 Subsection 16(1)

96. This item would include the words "Subject to subsection 92C(8)" into subsection 16(1). This item would be a consequence of Item 2.

Item 2 At the end of Part V

97. This item would add provisions to enable current and former ASIO employees and affiliates to employ cover arrangements, in accordance with a determination given by the Director-General of Security under subsection 92C(1), and protect persons employing cover, or facilitating cover in accordance with the arrangements from criminal liability.

98. Subsection 92B(1) would provide that a person who is a current or former ASIO employee or ASIO affiliate, may identify as their employer or place of work, an authority of a Commonwealth determined by the Director-General of Security. The period for which the current or former ASIO employee or ASIO affiliate may identify that authority as their employer or place of work, is limited to those periods in which that person is or was an ASIO employee or ASIO affiliate.

99. Subsection 92B(2) would provide that subsection 92B(1) applies despite any other law of the Commonwealth, a State or a Territory (whether passed or made before or after the commencement of section 92B), including any other law that is expressed to apply despite any other law. This provision is intended to protect the current or former ASIO employee or ASIO affiliate from criminal liability arising from any action permitted to be undertaken under subsection 92B(1).

100. Subsection 92C(1) would provide that the Director-General of Security may, in writing, determine one or more authorities of the Commonwealth that may be identified as the employer or place of work for a current or former ASIO employee or ASIO affiliate. The authorities of the Commonwealth that can be determined is limited to paragraphs (a), (aa), (b) and (c) of the definition of authority of the Commonwealth, being:

a Department of State or an Agency within the meaning of the Public Service Act 1999;
a Department within the meaning of the Parliamentary Service Act 1999;
the Defence Force; or
a body, whether incorporated or not, established for public purposes by or under a law of the Commonwealth or of a Territory.

101. A written determination under subsection 92C(1) enables the immunity provisions under subsection 92B(2) and section 92D. It is not intended to be exhaustive of the relevant arrangements, policies, procedures or requirements for the use of cover. A determination need not have a date of expiry. For example, a determination made under subsection 92C(1) could take the form of a simple statement.

102. Subsection 92C(2) would provide that a determination made under subsection 92C(1) may determine a specified authority in relation to a specified class of current or former ASIO employees or ASIO affiliates, or specify limitations or restrictions.

103. Subsection 92C(3) would be an avoidance of doubt provision, providing that if a determination under subsection 92C(1) determines a specified authority in relation to a class of current or former ASIO employees or ASIO affiliates, the class includes an office or position that comes into existence after the determination is made.

104. Subsection 92C(4) would provide that subsection 92C(3) does not affect the interpretation of any other provision of the ASIO Act. For example, the provision is not intended to demonstrate a contrary intention to subsection 33(3AB) of the Acts Interpretation Act 1901 in respect of any other provision of the ASIO Act, insofar as it may relate to specifying, declaring or prescribing matter, or doing anything in relation to a matter, and classes.

105. Subsection 92C(5) would require the Director-General of Security to obtain in writing the agreement of the head of the authority of the Commonwealth before making a determination under subsection 92C(1). As with a determination under subsection 92C(1), this agreement need not be exhaustive of the relevant cover arrangements, policies, procedures or requirements, and need not have a date of expiry. For example, a written agreement for the purposes of subsection 92C(5) could be a simple exchange.

106. Subsection 92C(6) would be an avoidance of doubt provision that clarifies that the Chief of the Defence Force (within the meaning of the Defence Act 1903) is the head of the Defence Force for the purposes of subsection 92C(5). The Defence Force would be an authority of the Commonwealth (see paragraph (b) of the definition) which may be specified in a determination under subsection 92C(1).

107. Subsection 92C(7) would provide that a determination under subsection 92C(1) and an agreement under subsection 92C(5) are not legislative instruments. The provision is intended to assist the reader as a determination made under subsection 92C(1) and an agreement under subsection 92C(5) are not legislative instruments as they do not determine or alter the content of the law.

108. Subsection 92C(8) would provide that the Director-General of Security may, in writing, delegate his or her powers or duties under section 92C, in relation to cover employment, to an ASIO employee, or an ASIO affiliate, who holds or is acting in a position in the Organisation that is equivalent to or higher than a position occupied by an SES employee with a classification of SES Band 3. This power is in addition to, and is not intended to limit the operation of the Director-General's power to delegate powers, functions or duties under section 16.

109. The inclusion of ASIO affiliates who hold or are acting in a position in the Organisation that is equivalent to or higher than a position occupied by an SES employee with a classification of SES Band 3 is necessary to ensure persons seconded to ASIO from partner agencies can exercise these functions. Any action taken by the ASIO affiliate would be done on behalf of ASIO in the performance of its statutory functions, as set out in section 17. This ability to delegate only to persons holding or acting in a SES Band 3 position is important in that it significantly limits who may exercise the power to authorise a person for the purposes of subsection 40(1A). The Director-General of Security can be expected to give appropriate consideration as to whether such an affiliate is suitable to occupy such a senior position when appointing the affiliate to that position.

110. Subsection 92C(9) would provide that in exercising powers or discharging duties under a delegation under subsection 92C(8), the delegate must comply with written directions (if any) given by the Director-General of Security. This is consistent with subsection 16(2).

111. Subsection 92D would provide protection from criminal responsibility to particular categories of persons who facilitate or provide support to a current or former ASIO employee or ASIO affiliate, for the purposes of cover employment under section 92B.

112. Subsection 92D(1) would provide protection from Commonwealth, State or Territory law to persons who are staff members of any authority of the Commonwealth for things done in the course of exercising or performing the staff member's powers, functions or duties to facilitate the current or former ASIO employee or ASIO affiliate to employ their cover arrangements for the purposes of cover employment under subsection 92B(1), in accordance with a determination under subsection 92C(1). The protection only extends to things that would ordinarily not be an offence if the authority of the Commonwealth were the current or former ASIO employee or ASIO affiliate's employer.

113. A staff member of an authority of the Commonwealth is defined in section 4 to include the head (however described) of the body, or another person who holds an office or appointment in relation to the body, and a person who is otherwise a member of the staff of the body, including employees, consultants, contractors and secondees from an authority of the Commonwealth or State, or other persons engaged to perform services for the body.

114. For example, a staff member within ASIO might need to provide documents to support cover arrangements for the ASIO employee or ASIO affiliate who requires cover employment. Equally, a staff member of an authority of the Commonwealth might need to facilitate the provision of such documents. These documents might identify the cover employer as the ASIO employee or ASIO affiliate's employer. In the absence of the protection afforded by subsection 92D(1) from criminal liability, the ASIO staff members or staff members of the authority of the Commonwealth could potentially commit a forgery offence under the Criminal Code. Accordingly, subsection 92D(1) would provide that the staff members is protected from criminal liability.

115. Subsection 92D(2) would provide protection from Commonwealth, State or Territory law to a person who, in the proper performance of functions attached to their professional capacity, facilitate the current or former ASIO employee or ASIO affiliate to employ their cover arrangements for the purposes of cover employment under subsection 92B(1), in accordance with a determination under subsection 92C(1). This subsection would cover persons who are not a staff member of any authority of the Commonwealth. The protection only extends to things that would ordinarily not be an offence if the authority of the Commonwealth were the current or former ASIO employee or ASIO affiliate's employer.

116. For example, a medical professional might produce a report relating to a current or former ASIO employee or ASIO affiliate. That report might be prepared for an official government purpose, and require the professional to identify the cover employer as the ASIO employee or ASIO affiliate's employer. In the absence of the protection afforded by subsection 92D(2) from criminal liability, the professional might otherwise be providing false or misleading information which is an offence under the Criminal Code. Accordingly, subsection 92D(2) would protect the person from criminal liability.

117. For the avoidance of doubt, it is not intended that a person who identifies another authority of the Commonwealth as their employer or place of work, would be able to perform the functions of that authority of the Commonwealth, or exercise the powers conferred on officers of that authority (however described). The amendments that would be introduced by this part only relates to the identification of that authority as the person's employer or place of work.

Intelligence Services Act 2001

118. This part would also amend the IS Act to enable current and former staff members of ASIS or ASD to identify a Commonwealth authority as the person's employer or place of work, where the authority has been determined by Director-General of ASIS or ASD. Persons using cover employment, or facilitating cover under these arrangements would be protected from criminal liability.

119. This part is intended to formalise and update existing, or enable, cover arrangements for ASIS or ASD where it would be inappropriate for current and former staff members to identify ASIS or ASD as their employer for security reasons. Its operation is intended to be consistent with the arrangements for ASIO staff and affiliates above. It would give effect to recommendation 70 of the Comprehensive Review.

Item 3 Subsection 3(1) (definition of staff member )

120. This item would include the words ", subject to subsection 41AC(3)," into the definition of staff member in subsection 3(1). This item would be a consequence of Item 5.

Item 4 Subsection 27(1)

121. This item would include the words "Subject to subsection 41AB(8), the" into subsection 27(1). This item would be a consequence of Item 5 .

Item 5 After section 41

122. This item would add provisions to enable current and former staff members of ASIS or ASD to employ cover arrangements, in accordance with a determination given by the Director-General of ASIS or ASD under subsection 41AB(1), and protect persons employing cover, or facilitating cover in accordance with the arrangements from criminal liability.

123. Subsection 41AA(1) would provide that a person who is a current or former staff member of ASIS or ASD, may identify as their employer or place of work, a Commonwealth authority determined by the Director-General of ASIS or ASD. The period for which the current or former staff member may identify that authority as their employer or place of work, is limited to those periods in which that person is or was a staff member.

124. Subsection 41AA(2) would provide that subsection 41AA(1) applies despite any other law of the Commonwealth, a State or a Territory (whether passed or made before or after the commencement of section 41AA), including any other law that is expressed to apply despite any other law. This provision is intended to protect the current or former staff members from criminal liability arising from any action permitted to be undertaken under subsection 41AA(1).

125. Subsection 41AB(1) would provide that the Director-General of ASIS or ASD may, in writing, determine one or more Commonwealth authorities that may be identified as the employer or place of work for a current or former staff member of ASIS or ASD. The Commonwealth authorities that can be determined is limited to paragraphs (a), (b) (c) and (d) of the definition of Commonwealth authority, being:

an Agency within the meaning of the Public Service Act 1999;
a Department within the meaning of the Parliamentary Service Act 1999;
the Defence Force; or
a body (whether incorporated or not) established, or continued in existence, for public purposes by or under a law of the Commonwealth.

126. A written determination under subsection 41AB(1) enables the immunity provisions under subsection 41AA(2) and section 41AC. It is not intended to be exhaustive of the relevant arrangements, policies, procedures or requirements for the use of cover. A determination need not have a date of expiry. For example, a determination made under subsection 41AB(1) could take the form of a simple statement.

127. Subsection 41AB(2) would provide that a determination under subsection 41AB(1) may determine a specified authority in relation to a specified class of current or former staff members of ASIS or ASD, or specify limitations or restrictions.

128. Subsection 41AB(3) would be an avoidance of doubt provision, providing that if a determination under subsection 41AB(1) determines a specified authority in relation to a class of current or former staff members, the class includes an office or position that comes into existence after the instrument is made.

129. Subsection 41AB(4) would provide that subsection 41AB(3) does not affect the interpretation of any other provision of the IS Act. For example, the provision is not intended to demonstrate a contrary intention to subsection 33(3AB) of the Acts Interpretation Act 1901 in respect of any other provision of the IS Act, insofar as it may relate to specifying, declaring or prescribing a matter, or doing anything in relation to a matter, and classes.

130. Subsection 41AB(5) would require the Director-General of ASIS or ASD to obtain in writing the agreement of the head of the Commonwealth authority before making an instrument under subsection 41AB(1). For example, a written agreement for the purposes of subsection 41AB(5) could be a simple exchange.

131. Subsection 41AB(6) would be an avoidance of doubt provision that clarifies that the Chief of the Defence Force (within the meaning of the Defence Act 1903) is the head of the Defence Force for the purposes of subsection 41AB(5). The Defence Force would be a Commonwealth authority (see paragraph (c) of the definition) which may be specified in a determination under subsection 41AB(1).

132. Subsection 41AB(7) would provide that a determination under subsection 41AB(1) and an agreement under subsection 41AB(5) are not legislative instruments. This provision is intended to assist the reader as a determination made under subsection 41AB(1) and an agreement under subsection 41AB(5) are not legislative instruments as they do not determine or alter the content of the law.

133. Subsection 41AB(8) would provide that the Director-General of ASIS or ASD may, in writing, delegate his or her powers or duties under section 41AB, in relation to cover employment, to a staff member of their agency, who holds or is acting in a position in the agency that is equivalent to or higher than a position occupied by an SES employee with a classification of SES Band 3. This power is in addition to, and is not intended to limit the operation of the Director-General's power to delegate powers, functions or duties under sections 27 or 27N.

134. Subsection 41AB(9) would provide that in exercising powers or discharging duties under a delegation under subsection 41AB(8), the delegate must comply with written directions (if any) given by the Director-General of ASIS or ASD. This is consistent with subsection 27N(2).

135. Subsection 41AC would provide protection from criminal responsibility to particular categories of persons who facilitate or provide support to a current or former staff members of ASIS or ASD, for the purposes of cover employment under section 41AA.

136. Subsection 41AC(1) would provide protection from Commonwealth, State or Territory law to persons who are staff members of any Commonwealth authority for things done in the course of exercising or performing the staff member's powers, functions or duties to facilitate the current or former staff members of ASIS or ASD to employ their cover arrangements for the purposes of cover employment under subsection 41AA(1), in accordance with a determination under subsection 41AB(1). The protection only extends to things that would ordinarily not be an offence if the Commonwealth authority were the current or former staff member of ASIS or ASD's employer.

137. For example, a staff member within ASIS or ASD might need to provide documents to support cover arrangements for the ASIS or ASD staff member who requires cover employment. These documents might identify the cover employer as the ASIS or ASD staff member's employer. In the absence of the protection afforded by subsection 41AC(1) from criminal liability, the staff member could potentially commit a forgery offence under the Criminal Code. Accordingly, subsection 41AC(1) will provide that the staff member is protected from criminal liability.

138. Subsection 41AC(2) would provide protection from Commonwealth, State or Territory law to other persons who, in the proper performance of functions attached to their professional capacity, facilitate the current or former staff member of ASIS or ASD to employ their cover arrangements for the purposes of cover employment under subsection 41AA(1), in accordance with a determination under subsection 41AB(1). This subsection would cover persons who are not a staff member of any authority of the Commonwealth. The protection only extends to things that would ordinarily not be an offence if the Commonwealth authority were the current or former staff member of ASIS or ASD's employer.

139. For example, a medical professional might produce a report relating to a current or former staff member of ASIS or ASD. That report might be prepared for an official government purpose, and require the professional to identify the cover employer as the staff member's employer. In the absence of the protection afforded by subsection 41AC(2) from criminal liability, the professional might otherwise be providing false or misleading information which is an offence under the Criminal Code. Accordingly, subsection 41AC(2) would protect the person from criminal liability.

140. For the avoidance of doubt, it is not intended that a person who identifies another authority of the Commonwealth as their employer or place of work, would be able to perform the functions of that authority of the Commonwealth, or exercise the powers conferred on officers of that authority (however described). The amendments that would be introduced by this part only relates to the identification of that authority as the person's employer or place of work.

141. Subsection 41AC(3) would provide that, for the purposes of paragraphs 41AC(1)(a) and 41AC(1)(b), a staff member of a Commonwealth authority means the head (however described) of the Commonwealth authority, or another person who holds an office or appointment in relation to the Commonwealth authority and a person who is otherwise a member of the staff of the Commonwealth authority. A person will otherwise be a member of the staff of the Commonwealth authority whether an employee of the Commonwealth authority, consultant or contractor to the Commonwealth authority or a secondee from the Commonwealth, State, or other persons who performs services for the authority. This is described broadly, and is intended to capture other members, however described, including members of the Defence Force (within the meaning of the Defence Act 1901).

142. Subsection 41AC(3) is intended to be broader than the definition of a staff member in relation to ASIO or an agency in section 3, in that it includes the head (however described) of the Commonwealth authority.

Item 6 Application of amendments

143. This item would provide that the amendments of the ASIO Act and IS Act made by this part apply in relation to a person identifying, on or after the commencement of this part, their employer or place of work in relation to a period regardless of whether the person became an ASIO employee, ASIO affiliate or staff member of ASIS or ASD before, on or after that commencement and regardless of whether the period occurred, partly or wholly, before on or after that commencement.

Part 2 – Consolidating secrecy offences

Division 1 – Main amendments

144. This part would amend the IS Act to consolidate the secrecy offences in Division 1 of Part 6 of the IS Act. The purpose of these amendments would be to increase the protection of identity of staff members of agencies that are regulated by the IS Act and to reduce the number of secrecy offences in Commonwealth laws. By consolidating these offences, it would reduce the ability to identify the precise agency to whom the conduct giving rise to the offence relates. It is not intended for these amendments to alter, or otherwise affect the scope of these secrecy offences. This would give effect to recommendation 143 of the Comprehensive Review.

Intelligence Services Act 2001

Item 7 Subsection 3(1) (at the end of the definition of staff member )

145. This item would add paragraph (c) to the definition of staff member in relation to DIO. It would largely mirror the definition of staff member in relation to ASIO and to an agency, and would include employees, consultants, contractors and secondees from an authority of the Commonwealth or State, or other persons engaged to perform services for DIO. Noting DIO is not a statutory authority, it refers to that part of the Defence Department known as DIO.

Item 8 Section 39 (at the end of the heading)

146. This item would insert a reference to AGO, DIO and ASD into the heading of section 39. This item and Items 9 to 15 consolidate the communication offences in sections 39 to 40B into section 39.

Item 9 Paragraph 39(1)(a)

147. This item would insert a reference to AGO, DIO and ASD into paragraph 39(1)(a). It would also define the ASIS, AGO, DIO or ASD as "the relevant agency" for the purposes of section 39.

Item 10 Paragraph 39(1)(b)

148. This item would repeal paragraph 39(1)(b) and substitute it with a new paragraph 39(1)(b). The amended paragraph 39(1)(b) would require, as an element of the offence, that the information or matter has come to the knowledge or into the possession of the person by reason of the person being or having been a staff member of the relevant agency or an agent of ASIS, having entered into any contract, agreement or arrangement with the relevant agency or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the relevant agency. As a result of the amendment made by item 9, the relevant agency means ASIS, AGO, DIO or ASD.

149. This amendment maintains the intent of the existing paragraph 39(1)(b) and sections 39A to 40B (which are repealed by item 15) requiring that an element of the communication offence is that the person has knowledge or possession of the information by reason of being a staff member, entered into any contract, agreement or arrangement with the agency, or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the agency.

Item 11 Subparagraphs 39(1)(c)(i) and (ii)

150. This item would replace the reference to "the Director-General of ASIS or staff member" with the more general "head of the relevant agency or a staff member of the relevant agency" into subparagraphs 39(1)(c)(i) and (ii).

Item 12 Subparagraphs 39(1)(c)(iii)

151. This item would replace the reference to "the Director-General of ASIS" with the more general "head of the relevant agency" into subparagraph 39(1)(c)(iii).

Item 13 Subparagraphs 39(1)(c)(iv)

152. This item would replace the reference to "the Director-General of ASIS or of a staff member having the authority of the Director-General of ASIS" with the more general "head of the relevant agency or of a staff member of the relevant agency having the authority of the head of the relevant agency" into subparagraph 39(1)(c)(iv).

Item 14 At the end of section 39

153. This item would insert a definition of head of the relevant agency at subsection 39(4). In relation to ASIS, AGO or ASD, which are agencies under the IS Act, that person is the agency head, as defined in section 3. In relation to DIO, that person is the Director of DIO, which would be consistent with section 40B.

Item 15 Sections 39A to 40B

154. This item would repeal sections 39A to 40B. The effect of these provisions would be maintained in section 39, as amended by Items 8 to 14.

Item 16 Section 40C (at the end of the heading)

155. This item would insert a reference to AGO, DIO and ASD into the heading of section 40C. This item and Items 17 to 21 consolidate the unauthorised dealing with records offences in sections 40C, 40E, 40G and 40L into section 40C.

Item 17 Paragraph 40C(1)(b) and (c)

156. This item would repeal paragraphs 40C(1)(b) and 40C(1)(c) and substitute new paragraphs 40C(1)(b) and 40C(1)(c).

157. Amended paragraph 40C(1)(b) would insert a reference to AGO, DIO and ASD into paragraph 40C(1)(b). It would also describe ASIS, AGO, DIO or ASD as "the relevant agency".

158. The amended paragraph 40C(1)(c) would require, as an element of the offence, the record to be obtained by the person by reason of the person being or having been a staff member of the relevant agency or an agent of ASIS, having entered into any contract, agreement or arrangement with the relevant agency or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the relevant agency. As a result of the amended paragraph 40C(1)(b), the relevant agency means ASIS, AGO, DIO or ASD.

159. This amendment maintains the intent of the existing paragraph 40C(1)(c) and sections 40E, 40G and 40L (which are repealed by item 28) requiring that an element of the unauthorised dealing with records offences is that the record is obtained by the person by reason of the person being a staff member, entered into any contract, agreement or arrangement with the agency, or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the agency.

Item 18 Subparagraph 40C(1)(d)(ii)

160. This item would replace the reference to "ASIS" with the more general "the relevant agency" in subparagraph 40C(1)(d)(ii).

Item 19 Subparagraph 40C(1)(d)(iii)

161. This item would replace the reference to "the Director-General of ASIS" with the more general "head of the relevant agency" into subparagraph 40C(1)(d)(iii).

Item 20 Subparagraphs 40C(1)(d)(iv)

162. This item would replace the reference to "the Director-General of ASIS or of a staff member having the authority of the Director-General of ASIS" with the more general "head of the relevant agency or of a staff member of the relevant agency having the authority of the head of the relevant agency" into subparagraph 40C(1)(d)(iv).

Item 21 At the end of section 40C

163. This item would insert subsection 40C(5). The item would provide that the head of the relevant agency for the purpose of section 40C has the same meaning as in section 39.

Item 22 Section 40D (at the end of the heading)

164. This item would insert a reference to AGO, DIO and ASD into the heading of section 40D. This item and Items 23 to 27 consolidate the unauthorised recording offences in sections 40D, 40F, 40H and 40M into section 40D.

Item 23 Paragraphs 40D(1)(b) and (c)

165. This item would repeal paragraphs 40D(1)(b) and 40D(1)(c) and substitute with new paragraphs 40D(1)(b) and 40D(1)(c).

166. Amended paragraph 40D(1)(b) would insert a reference to AGO, DIO and ASD into paragraph 40C(1)(b). It would also describe ASIS, AGO, DIO or ASD as "the relevant agency".

167. The amended paragraph 40D(1)(c) would require as an element of the offence, the information or matter to come into the knowledge or possession of the person by reason of the person being or having been a staff member of the relevant agency or an agent of ASIS, having entered into any contract, agreement or arrangement with the relevant agency or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the relevant agency. As a result of the amended paragraph 40D(1)(b), the relevant agency means ASIS, AGO, DIO or ASD.

168. This amendment maintains the intent of the existing paragraph 40D(1)(c) and sections 40F, 40H and 40M (which are repealed by item 28) requiring that an element of the unauthorised recording offences is that information or matter comes into the knowledge or possession of the person by reason of the person being a staff member, entered into any contract, agreement or arrangement with the agency, or having been an employee or agent of a person who has entered into a contract, agreement or arrangement with the agency.

Item 24 Subparagraph 40D(1)(d)(ii)

169. This item would replace the reference to "ASIS" with the more general "the relevant agency" in subparagraph 40D(1)(d)(ii).

Item 25 Subparagraph 40D(1)(d)(iii)

170. This item would replace the reference to "the Director-General of ASIS" with the more general "head of the relevant agency" into subparagraph 40D(1)(d)(iii).

Item 26 Subparagraphs 40D(1)(d)(iv)

171. This item would replace the reference to "the Director-General of ASIS or of a staff member having the authority of the Director-General of ASIS" with the more general "head of the relevant agency or of a staff member of the relevant agency having the authority of the head of the relevant agency" into subparagraph 40D(1)(d)(iv).

Item 27 At the end of section 40D

172. This item would insert subsection 40D(5). The item would provide that the head of the relevant agency for the purpose of section 40D has the same meaning as in section 39.

Item 28 Sections 40E to 40M

173. This item would repeal sections 40E to 40M. The effect of these provisions would be maintained in sections 40C and 40D, as amended by Items 16 to 27.

Item 29 Subsection 41B(3) (definition of information offence provision )

174. This item would repeal and replace the definition of information offence provision in section 41B. This would be a consequence of the offences in Division 1 of Part 6 of the IS Act being consolidated into subsections 39(1), 40C(1) and 40D(1).

Item 30 Application of amendments

175. This item contains the application provisions for the amendments in Division 1 of Part 2 of this Bill.

176. Subitem 30(1) provides that the amendment of section 39, and the repeal of sections 39A, 40 and 40B of the IS Act made by Division 1 of Part 2 of this Bill apply in relation to a communication by a person of any information or matter on or after the commencement of this item, regardless of whether the information or matter came to the knowledge or into the possession of the person before, on or after that commencement, or if the information or matter was acquired or prepared by or on behalf of ASIS, AGO, DIO or ASD before, on or after that commencement.

177. Subitem 30(2) provides that the amendment of section 40C, and the repeal of sections 40E, 40G and 40L of the IS Act made by Division 1 of Part 2 of this Bill apply in relation to conduct engaged in by a person in relation to a record on or after the commencement of this item, regardless of whether the record was obtained by the person before, on or after that commencement or whether the record was acquired or prepared by or on behalf of ASIS, AGO, DIO or ASD before, on or after that commencement.

178. Subitem 30(3) provides that the amendment of section 40D, and the repeal of sections 40F, 40H and 40M of the IS Act made by Division 1 of Part 2 of the Bill apply in relation to the making of a record of any information or matter by a person on or after the commencement of this item, regardless of whether the information or matter came to the knowledge or into the possession of the person before, on or after that commencement or whether the record was acquired or prepared by or on behalf of ASIS, AGO, DIO or ASD before, on or after that commencement.

Division 2 – Consequential amendments

Privacy Act 1988

Item 31 Subsection 80P(7) (paragraph (c) of the definition of designated secrecy provision )

179. This item would omit references to sections 39A, 40, 40B to 40H, 40L, 40M of the IS Act in paragraph (c) of the definition of designated secrecy provision, and substitute references to sections 40C and 40D. This would be a consequence of items 8 to 28.

180. Section 80P of the Privacy Act provides that at any time when an emergency declaration under section 80J or 80K is in force, an APP entity may collect, use or disclose personal information, if certain conditions are met. Subsection 80P(2) of the Privacy Act provides that an entity is not liable to any proceedings for contravening a secrecy provision, unless the secrecy provision is a designated secrecy provision. Accordingly, an entity would continue to not be permitted to disclose or use personal information in breach of sections 39, 40C or 40D of the IS Act, even if an emergency declaration is in force.

Part 3 – Protection from disclosure under Archives Act 1983

181. This part would amend the Administrative Appeals Tribunal Act 1975 and the Archives Act to ensure the identity of current and former ASIO employees, ASIO affiliates, staff members of ASIS and agents of ASIS that are included in Commonwealth records that are in the open access period are protected from public access.

182. Under section 31 of the Archives Act, a Commonwealth record that is in the open access period, that is in the care of the Archives or in the custody of a Commonwealth institution, but not an exempt record, must be available for public access. A Commonwealth record is an exempt document if it meets at least one of the criteria set out in section 33.

183. While a Commonwealth record is an exempt record if it contains information or matter, the disclosure of which could reasonably be expected to cause damage to the security, defence or international relations of the Commonwealth, it would be consistent with the requirements of security that the identity of current and former ASIO employees, ASIO affiliates, staff members of ASIS and agents of ASIS are appropriately protected.

184. This part would implement recommendation 190 of the Comprehensive Review.

Administrative Appeals Tribunal Act 1975

Item 32 Subsection 3(1) (paragraph (b) of the definition of exempt security record )

185. This item would insert a reference to subsections 33(4A) and 33(4C) into the definition of exempt security record. This would ensure that a review of a decision of the National Archives of Australia under the Archives Act relating to records that are exempt on the basis of the new categories of exempt records that would be inserted by Item 35 is considered by the Security Division of the Administrative Appeals Tribunal in accordance with section 19F.

Archives Act 1983

Item 33 Subsection 3(1)

186. This item would insert a definition of ASIO affiliate and ASIO employee into subsection 3(1). These terms will have the same meaning as in the ASIO Act.

Item 34 Paragraphs 29(6)(a) and (7)(a)

187. This item would insert a reference to subsections 33(4A) and 33(4C) in paragraphs 29(6)(a) and 29(7)(a).

188. This would provide that a record that is in the open access period is not, by virtue of a determination under subsections 29(1) or 29(2) a record to which the National Archives of Australia is not entitled to have access in accordance with section 28, unless the records are exempt on the basis of the new categories of exempt records that would be inserted by Item 35 and a security classification applies to the record such that access by the National Archives of Australia would not be appropriate.

Item 35 After subsection 33(4)

189. This item would insert new categories of exempt records into section 33 of the Archives Act.

190. Subsection 33(4A) would provide that a Commonwealth record is an exempt record if it contains information or matter that identifies a current or former ASIO employee or ASIO affiliate, or from which the identity of such a person could reasonably be inferred, or that could reasonably lead to the identity of such a person being established, and the information or matter has not been lawfully been made public by means of broadcasting or reporting proceedings of the Parliament.

191. Such a Commonwealth record would not however be an exempt record if the Minister administering section 92 of the ASIO Act or the Director-General of Security has consented in writing for the information or matter being made public.

192. Subsection 33(4B) would provide that if the Minister administering section 92 of the ASIO Act or the Director-General of Security has given consent in writing for the purposes of that section, which relates to the publication of identity of ASIO employees or ASIO affiliates, then that consent is taken to be consent for the purposes of subsection 33(4A). Consent by the Minister or Director-General can be provided before or after the commencement of this item. This would ensure that an ASIO employee or ASIO affiliate whose identity has lawfully been publicly declared, is not covered by subsection 33(4A).

193. Subsection 33(4C) would provide that a Commonwealth record is an exempt record if it contains information or matter that identifies a current or former staff member of ASIS or an agent of ASIS, or from which the identity of such a person could reasonably be inferred, or that could reasonably lead to the identity of such a person being established, and the information or matter has not been lawfully been made public by means of broadcasting or reporting proceedings of the Parliament.

194. Such a Commonwealth record would not however be an exempt record if the responsible Minister for ASIS or the Director-General of ASIS has consented in writing for the information or matter being made public.

195. Subsection 33(4D) would provide that if the responsible Minister for ASIS or the Director-General of ASIS has given consent in writing for the purposes of section 41 of the IS Act, which relates to the publication of identity of agents or staff members of ASIS, then that consent is taken to be consent for the purposes of subsection 33(4C). Consent by the Minister or Director-General can be provided before or after the commencement of this item. This would ensure that an agent or staff member of ASIS whose identity has lawfully been publicly declared, is not covered by subsection 33(4C).

Item 36 At the end of section 33

196. This item would add subsection 33(6) to provide that only the most senior Minister responsible for administering ASIO or ASIS can give consent under section 33. This item would also include a note that a reference to a Minister in section 33 may include a reference to a person acting as that Minister as is provided for in subsection 19(4) of the Acts Interpretation Act 1901. This note is included to assist the reader.

Item 37 At the end of subsection 39(1)

197. This item would add the phrase "or subsections 33(4A) or 33(4C)" to subsection 39(1). This item would provide that nothing in the Act requires the National Archives of Australia to give information as to the existence or non-existence of a record, if it contains information relating to the identity of ASIO employees, ASIO affiliates, staff members of ASIS or an agent of ASIS.

Item 38 Paragraph 39(2)(b)

198. This item would add a reference the phrase "or subsections 33(4A) or 33(4C)" to paragraph 39(2)(b). This item would provide that the National Archives of Australia may give notice to an applicant who makes an application for access to a record relating to certain exempt records, including by virtue of subsections 33(4A) and 33(4C), neither confirming nor denying the existence of such record. The decision to give such a notice would be deemed to be a decision refusing to grant the applicant access to the record, on the ground that the record is an exempt record.

Part 4 – Protecting the identity of ASIO employees and ASIO affiliates

Division 1 – Main amendments

199. This part would amend the ASIO Act to strengthen the protection of identities of ASIO employees or ASIO affiliates, by modernising and updating the publication offence under section 92.

200. Section 92 currently makes it an offence for a person to publish, including through various means, any matter stating, or from which it could reasonably be inferred that a person is a current or former ASIO employee or ASIO affiliate, or is in any way connected with an ASIO employee or ASIO affiliate, without the consent of the ASIO Minister or the Director-General of Security.

Australian Security Intelligence Organisation Act 1979

Item 39 Section 92

201. This item would repeal and replace section 92, which would relate to the publication of the identity of a current or former ASIO employee or ASIO affiliate, and introduce new section 92A, which would relate to the disclosure of the identity of such a person to another person.

202. Sections 92 and 92A have been developed with reference to the principles for framing secrecy offences agreed to by the Government to implement the Commonwealth Government's Review of Secrecy Provisions Final Report.

203. Subsection 92(1) would provide that a person commits an offence if the person makes information public, or causes or permits information to be made public, where the information identifies or could reasonably lead to establishing the identity of a current or former ASIO employee or ASIO affiliate or such an identity could be reasonably inferred from the information. Subsection 92(1) would provide that the penalty for this offence is imprisonment for 10 years, which is consistent with existing subsection 92(1).

204. The effect of this subsection would be that it removes the methods of publication that currently exist in subsection 92(1), namely in a newspaper, or other publication, or by radio broadcast or television. The inclusion of specific methods of publication have caused the provision to become outdated, especially considering the proliferation of modern forms of publication like social media. Removing references to specific publication methods will ensure the section remains current and would be consistent with other publication offences relating to intelligence officials, such as in section 41 of the IS Act.

205. Section 92 was originally introduced in response to a concerted campaign in the 1970s to publicly identify ASIO officers, contrary to the interests of their personal security, and national security. More recently, Australia's deteriorating security environment has been reflected in the Director-General of Security's annual public threat assessments. In his 2023 threat assessment, the Director-General noted those who chose to publicly identify themselves as security clearance holders or revealed they worked in the intelligence community were 'high value targets'.

206. Publication of the identity of an ASIO employee or ASIO affiliate therefore continues to have the potential to cause grave harm to security. Release of the identity of ASIO employees or ASIO affiliates would substantially increase the risk they will be targeted by hostile third parties to undermine Australia's security, and put the lives of ASIO employees and affiliates, as well as their families at risk. This could result in coercive action being directed towards such persons.

207. Recognising the importance that the identity of an ASIO employee or ASIO affiliate is protected, the offence does not distinguish between Commonwealth officers and other persons. The culpability of engaging the conduct does not differ between these classes of persons. The history of the offence, and the current security environment, also means it is important the offence continue to apply to all persons equally.

208. Subsections 92(2) and 92(3) would establish exceptions to the offence at subsection 92(1).

209. Subsection 92(2) would provide an exception to the offence in subsection 92(1) where the ASIO Minister or Director-General of Security has consented in writing to the information being made public. This would be consistent with the existing subsection 92(1).

210. Subsection 92(2) would also include a note that a defendant bears an evidential burden in relation to the matters in the subsection, by reason of subsection 13.3(3) of the Criminal Code. This is appropriate because consent being given would be exceptional. The decision to give consent needs to be made with very careful consideration of the impact of the publication of the identity of current or former ASIO employees and affiliates on their colleagues in ASIO, and other agencies, and the impact on other people in the community or internationally they have engaged with while working for ASIO. It also has to give regard to the sensitive matters they have been involved in that relate to Australia's national security. It is reasonable to expect that any consent is clearly given and therefore can be demonstrated by the defendant. Clarity that the consent has been granted is a necessary consideration in ensuring the offence is operating effectively to protect the interests of the Commonwealth, of ASIO, and of the current or former ASIO employees or affiliates.

211. Subsection 92(3) would provide an exception to the offence in subsection 92(1) where a former ASIO employee or affiliate has consented in writing to their identity being made public, or otherwise caused or authorised their identity to be made public by the third person. This would continue the effect of existing subsection 92(1B), protecting third parties who act in reliance on advice from former ASIO employees or affiliates. However, this defence does not apply for the former ASIO employee or affiliate themselves.

212. This change would ensure that former ASIO employees or affiliates cannot unilaterally publicly 'self-declare' their ASIO affiliation. When the existing subsection 92(1B) exception was first conceived, a self-declaration would not necessarily have an impact on other officers or affiliates around them. Modern technology, however, has meant this is no longer the case, and it is now necessary to clarify the operation of this exception.

213. If a former ASIO employee or affiliate were to publicly self-declare their association with ASIO, other ASIO employees or affiliates around them who are digitally linked to them, whether through social media or other digital means, can be discovered. Public self-declarations are not only the business of the former ASIO employees or affiliates, and it is necessary to clarify the operation of the exception so that it is clear it cannot be relied upon by former ASIO employees or affiliates. Former ASIO employees or affiliates will still, however, be able to seek the permission of the Minister or Director-General to publicly declare their affiliation with ASIO.

214. Subsection 92(4) would provide that section 15.4 of the Criminal Code applies to an offence against subsection 92(1). This would provide that an offence against subsection 92(1) applies whether or not the conduct constituting the alleged offence occurs in Australia and whether or not the result of the conduct constituting the alleged offence occurs in Australia.

215. Subsection 92(5) would provide that subsection 92(4) does not, by implication, affect the interpretation of any other provision of the ASIO Act, or another Act.

216. Subsection 92(6) would provide that a prosecution for an offence against subsection 92(1) may only be instituted by, or with the consent of, the Attorney-General. This would continue the effect of existing subsection 92(3).

217. Subsection 92(6) would also include a note referencing subsection 18(3) relating to the communication of information about an offence against subsection 92(1). Subsection 18(3) provides that the Director-General of Security or authorised person may communicate information that relates, or appears to relate, to the commission or intended commission, of a serious crime.

218. Subsection 92(7) would provide that consent given under subsection 92(2) is not a legislative instrument. This provision is intended to assist the reader as consent given under subsection 92(2) is not a legislative instrument as it does not determine or alter the content of the law.

219. Subsection 92A(1) is a new offence that has been introduced to strengthen protections for the identity of ASIO officers and affiliates, bringing them into closer alignment with those afforded to ASIS officers under section 41 of the Intelligence Services Act 2001.

220. Subsection 92A(1) would provide that a person commits an offence if they either disclose, or engage in conduct that results in the disclosure of, information that identifies, could reasonably lead to establishing the identity of or could reasonably infer the identity of a current or former ASIO employee or ASIO affiliate or such an identity could be reasonably inferred from the information.

221. Paragraph 92A(1)(c) provides that a person only commits the offence if they intend to, or the know the disclosure will, endanger the health or safety of a person, or prejudice the effective performance of the functions or duties, or the effective exercise of the powers of ASIO.

222. Introducing the new subsection 92A(1) offence is necessary in light of the deteriorating security environment. As noted by the Director-General of Security in his 2023 annual threat assessment, those who choose to publicly identify themselves as security clearance holders or reveal they work in the intelligence community are 'high value targets'. Those who disclose the identity of ASIO employees similarly render those officers 'high value targets'. Disclosure of the identity of ASIO employees or ASIO affiliates would substantially increase the risk they will be targeted by hostile third parties to undermine Australia's security, and put the lives of ASIO employees and affiliates, as well as their families at risk of harm. Disclosure of the identity of ASIO employees can also degrade the effective performance of ASIO's functions, duties or powers.

223. Although the offence brings the protections for ASIO officers into closer alignment with those afforded to ASIS officers under section 41 of the Intelligence Services Act 2001, there are important distinctions. Under the new offence, the person must also either intend or know, that the disclosure of the information would endanger the health or safety of a person, or would prejudice the effective performance of the functions and duties, or the effective exercise of powers by ASIO. The inclusion of the element in paragraph 92A(1)(c) is not included in the section 41 offence. This is appropriate given the differing operating contexts of ASIO and ASIS employees and affiliates.

224. Recognising the importance that the identity of an ASIO employee or ASIO affiliate is protected, the offence does not distinguish between Commonwealth officers and other persons. The culpability of engaging in the conduct does not differ between these classes of persons.

225. Subsection 92A(2) would provide that section 15.4 of the Criminal Code applies to an offence against subsection 92A(1). This would provide that an offence against subsection 92A(1) applies whether or not the conduct constituting the alleged offence occurs in Australia and whether or not the result of the conduct constituting the alleged offence occurs in Australia.

226. Subsection 92A(3) would provide that subsection 92A(2) does not, by implication, affect the interpretation of any other provision of the ASIO Act, or another Act.

227. Subsection 92A(4) would provide that a prosecution for an offence against subsection 92A(1) may only be instituted by, or with the consent of, the Attorney-General. This would be consistent with the effect of existing subsection 92(3).

228. Subsection 92A(4) would also include a note referencing subsection 18(3) relating to the communication of information about an offence against subsection 92A(1). Subsection 18(3) provides that the Director-General of Security or authorised person may communicate information that relates, or appears to relate, to the commission or intended commission, of a serious crime.

Item 40 Application of amendments

229. This item would provide for the application of the amendments made by the division.

230. Subitem 2(1) would provide that the offence at subsection 92(1) as substituted, applies to information made public, or caused or permitted to be made public, after the commencement of the division (whether the information was obtained before or after that commencement).

231. Subitem 2(2) would provide that subsections 92(2) and 92(3) as substituted, apply to information made public, or consents given, before or after the commencement of the division.

232. Subitem 2(3) would provide that subsection 92A(1) as inserted, applies to information disclosed after the commencement of the Division (whether the information was obtained before or after that commencement).

Division 2 – Consequential amendments

Australian Crime Commission Act 2002

Item 41 Schedule 1 (entry relating to the Australian Security Intelligence Organisation Act 1979 )

233. This item would insert a reference to section 92A of the ASIO Act into Schedule 1. The effect of this item would be that a person is not required to furnish information, or produce a document or thing, to an examiner under section 20, if the disclosure of the information could constitute an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Business Names Registration Act 2011

Item 42 Paragraph 62N(3)(a)

234. This item would insert a reference to section 92A of the ASIO Act into paragraph 62N(3)(a). The effect of this item would be that a person would not be authorised to make a record of, or disclose protected information under subsection 62M(3), if the disclosure of the information could constitute an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Commonwealth Registers Act 2020

Item 43 Paragraph 18(3)(a)

235. This item would insert a reference to section 92A of the ASIO Act into paragraph 18(3)(a). The effect of this item would be that a person would not be authorised to make a record of, or disclose protected information under subsection 17(3), if the disclosure of the information could constitute an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Corporations Act 2001

Item 44 Paragraph 1270M(3)(a)

236. This item would insert a reference to section 92A of the ASIO Act into paragraph 1270M(3)(a). The effect of this item would be that a person would not be authorised to make a record of, or disclose protected information under subsection 1270L(3), if the disclosure of the information could constitute an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Criminal Code Act 1995

Item 45 Paragraph 122.5(7)(a) of the Criminal Code

237. This item would insert a reference to section 92A of the ASIO Act into paragraph 122.5(7)(a) of the Criminal Code. The effect of this item would be to limit the defence in paragraph 122.5(6) of the Criminal Code to secrecy offences in Division 122, to exclude communications and dealings with relevant information, if the communication or dealing would be an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Freedom of Information Act 1982

Item 46 Schedule 3 (entry relating to the Australian Security Intelligence Organisation Act 1979 )

238. This item would insert a reference to section 92A of the ASIO Act into Schedule 3. The effect of this item would be that a document would be an exempt document if it contains information, disclosure of which is prohibited by section 92A of the ASIO Act. This would mean that a person would not have a right to obtain access to the document under section 11 of the Freedom of Information Act 1982. This would be a consequence of Item 39.

National Consumer Credit Protection Act 2009

Item 47 Paragraph 212N(3)(a)

239. This item would insert a reference to section 92A of the ASIO Act into paragraph 212N(3)(a). The effect of this item would be that a person would not be authorised to make a record of, or disclose protected information under subsection 212M(3), if the disclosure of the information could constitute an offence under section 92A of the ASIO Act. This would be a consequence of Item 39.

Privacy Act 1988

Item 48 Subsection 80P(7) (paragraph (a) of the definition of designated secrecy provision )

240. This item would insert a reference to section 92A of the ASIO Act into paragraph (a) of the definition of designated secrecy provision. This would be a consequence of Items 39.

241. Section 80P of the Privacy Act provides that at any time when an emergency declaration under section 80J or 80K is in force, an APP entity may collect, use or disclose personal information, if certain conditions are met. Subsection 80P(2) of the Privacy Act provides that an entity is not liable to any proceedings for contravening a secrecy provision, unless the secrecy provision is a designated secrecy provision. Accordingly, an entity would continue to not be permitted to disclose or use personal information in breach of sections 92A of the ASIO Act, even if an emergency declaration is in force.

SCHEDULE 3 - Authorisations for intelligence activities

Part 1 – Sequencing of ministerial authorisations and clarifying references to persons

242. This part would amend the IS Act to enable a Minister to give an authorisation to ASIS, AGO or ASD to undertake certain activities in respect of Australian persons, in circumstances where Australian persons are, or are likely to be, involved in activities that are, or are likely to be, a threat to security or, involved with a listed terrorist organisation, without first obtaining the agreement of the Attorney-General. However, the authorisation cannot take effect unless and until the agreement of the Attorney-General has been obtained. Under the existing provisions, the Attorney-General must first give their agreement to the authorisation before it is then considered by the relevant Minister. This change allows for either the Minister, or Attorney-General, to first consider the authorisation, while still ensuring both must have agreed to the authorisation before it takes effect. This would give effect to recommendation 2 of the Comprehensive Review.

243. This part would also amend the IS Act to clarify that a Minister may give an authorisation to ASIS, AGO or ASD to undertake such activities, in circumstances where Australian persons are involved in activities that present a significant risk to their own safety, or are themselves involved in activities relating to the contravention, or alleged contravention, of a UN sanction enforcement law.

Intelligence Services Act 2001

Item 1 Subsections 9(1A) and (1AAA)

244. This item would repeal and substitute subsections 9(1A) and (1AAA).

245. Currently, ASIS, AGO and ASD must obtain an authorisation under sections 9 to 9D before undertaking certain activities, for specific purposes, including of producing intelligence on an Australian person, or that will, or is likely to have a direct effect on an Australian person.

246. Subsection 9(1A) would continue to set out when a Minister may give an authorisation for an activity, or a series of activities for the purpose of producing intelligence on Australian persons, or that will or, or are likely to, have a direct effect on Australian persons. The grounds for giving an authorisation have been renumbered and would otherwise be unchanged, subject to the following paragraphs.

247. Paragraph 9(1A)(a) would enable an authorisation where the Australian person is, or is likely to be, involved in activities that present a significant risk to the safety of any person, including the Australian person or member of the class of Australian person, to whom the authorisation relates. The purpose of the amendment is to clarify that an authorisation is not limited to activities that present a risk to a person other than the Australian person. An authorisation can apply where the Australian person is involved in activities that present a significant risk to their own safety and where the Australian person is involved in activities that present a significant risk to the safety of others.

248. Paragraph 9(1A)(f) would enable an authorisation where the Australian person is, or is likely to be, involved in activities related to a contravention, or alleged contravention, of a UN sanctions enforcement law, by any person, including the Australian person or member of the class of Australian person, to whom the authorisation relates. The purpose of the amendment is to clarify that an authorisation is not limited to activities by a person other than the Australian person that relate to a contravention or an alleged contravention of a UN sanction enforcement law. An authorisation can apply where the Australian person is involved in activities related to the contravention or alleged contravention of a UN sanction enforcement law by themselves or by another person.

249. The amendments do not include in subsection 9(1A) the requirement for the Minister to obtain the agreement of the Attorney-General as this would be dealt with in subsection 9(1AAC). A new note to subsection 9(1A) references the requirement for the Minister to obtain the Attorney-General's agreement in subsection 9(1AAC).

250. Subsection 9(1AAA) would set out when a Minister may give an authorisation for an activity, or a series of activities for the purpose of producing intelligence on one or members of a class of Australian persons. The grounds for giving an authorisation would be unchanged.

251. The requirement for the Minister to obtain the agreement of the Attorney-General would be dealt with in subsection 9(1AAD) which is referenced in the note to subsection 9(1AAA).

Item 2 After the heading to subsection 9(1AA)

252. This item would insert subsections 9(1AAC) and (1AAD).

253. Subsection 9(1AAC) would provide that an authorisation under subsection 9(1A) for an activity or series of activities, in relation to Australian persons, who are, or are likely to be involved in activities that are, or are likely to be, a threat to security, cannot take effect unless and until the Minister has obtained the agreement of the Attorney-General. Subsection 9(1AAC) would provide that the agreement can be oral or written and clarifies that the agreement can be sought before or after the authorisation referred to in subsection 9(1A) is given.

254. This amendment would provide that the relevant Minister can give an authorisation under subsection 9(1A) where Australian persons are, or are likely to be, involved in activities that are, or are likely to be, a threat to security either before or after the Attorney-General provides their agreement. However, such an authorisation cannot take effect until the Attorney-General has provided agreement.

255. Subsection 9(1AAD) would provide that an authorisation under subsection 9(1AAA) for an activity or series of activities, in relation to a class of Australian persons, cannot take effect unless and until the Minister has obtained the agreement of the Attorney-General.

256. This amendment would provide that the relevant Minister can give an authorisation under subsection 9(1AAA) either before or after the Attorney-General provides their agreement. However, such an authorisation cannot take effect until the Attorney-General has provided agreement.

257. This amendment is intended to provide flexibility for agencies in seeking ministerial authorisations where the Attorney-General's agreement is required. It is anticipated that the relevant Minister would give an authorisation before the Attorney-General gives their agreement, only where it is operationally necessary.

Item 3 Subsection 9(1AA)

258. This item would omit the reference to "paragraph (1A)(b) or (1AAA)(b)" and substitute "subsections 9(1AAC) and (1AAD)". This would be a consequence of Items 1 and 2.

Item 4 Paragraph 9(5)(b)

259. This item would omit the reference to "paragraph (1A)(b) or (1AAA)(b)" and substitute "subsections 9(1AAC) and (1AAD)". This would be a consequence of Items 1 and 2.

Item 5 Subsection 9(6)

260. This item would omit the reference to "paragraph (1A)(b) or (1AAA)(b)" and substitute "subsections 9(1AAC) and (1AAD)". This would be a consequence of Items 1 and 2.

Item 6 Subsection 9A(2) (note)

261. This item would omit the note to subsection 9A(2). This would be a consequence of Item 1.

Item 7 Subparagraph 9B(2)(c)(ii)

262. This item would omit "serious risk to a person's safety" and substitute "significant risk to the safety of any person". The purpose of this item is to align the threshold at subparagraph 9B(2)(c)(ii) for emergency authorisations with the ministerial authorisation ground at proposed paragraph 9(1A)(a).

Item 8 Subsection 9B(2) (note)

263. This item would repeal the note at subsection 9B(2). This would be a consequence of Items 1 and 2.

Item 9 Subparagraph 9C(1)(c)(i)

264. This item would repeal and substitute subparagraph 9C(1)(c)(i). The effect of the subparagraph would remain unchanged, but would be a consequence of Items 1 and 2.

Item 10 Subsections 9C(2) and (3)

265. This item would repeal and substitute subsections 9C(2) and (3).

266. Subsection 9C(2) would provide that when section 9C applies, an emergency authorisation may be given and take effect without obtaining the agreement of the Attorney-General. This provision is consequential to Items 1 and 2.

267. Subsection 9C(3) similarly makes consequential amendments as to the effect of the Director-General of Security giving agreement for the purposes of section 9C. It does not, however, alter the sequencing in which agreement must be sought from the Director-General of Security.

Item 11 Subsection 9D(2)

268. This item would omit the words "apart from paragraph 9(1A)(b)". This item, and Item 12 are a consequence of Items 1 and 2.

Item 12 Subsection 9D(3)

269. This item would insert subsection 9D(3A) to provide that an authorisation, when section 9D applies, may take effect without obtaining the agreement of the Attorney-General. This item, and Item 11 are a consequence of Items 1 and 2.

Item 13 Paragraph 10AA(3)(a)

270. This item would omit the reference to "paragraph (1A)(b) or (1AAA)(b)" and substitute "subsections 9(1AAC) and (1AAD)". This would be a consequence of Items 1 and 2.

Item 14 Paragraph 11(2AA)(a)

271. This item would omit the reference to "a person's safety" and substitute "the safety of that person or any other person".

Item 15 Subsection 13B(6)

272. This item would omit the reference to "paragraph 9(1A)(a)" and substitute "subsection 9(1A)". This would be a consequence of Item 1.

Item 16 Application of amendments

273. This item would provide that the amendments made by this Part apply only in relation to authorisations given under Division 1 of Part 2, after the commencement of this Part.

Part 2 – References to Attorney-General not to include junior Minister

274. This part would amend the ASIO Act and the TIA Act to provide that the powers vested in the Attorney-General may only be exercised by the Attorney-General and not a junior Minister within the Portfolio. For the avoidance of doubt, these amendments are not intended to prevent a person who is acting as the Attorney-General to exercise those powers that are vested in the Attorney-General. This part would implement recommendation 17 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 17 After section 4

275. This item would insert section 4AA, which provides that despite subsection 19(1) of the Acts Interpretation Act 1901, a reference to the Attorney-General is a reference only to the Minister with that title. It would also insert a note clarifying subsection 19(4) of the Acts Interpretation Act 1901 means that a reference to the Attorney-General may include a reference to a person acting as the Attorney-General.

Telecommunications (Interception and Access) Act 1979

Item 18 After subsection 5(3)

276. This item would insert subsection 5(3A), which provides that despite subsection 19(1) of the Acts Interpretation Act 1901, a reference to the Attorney-General is a reference only to the Minister with that title. It would also insert a note clarifying subsection 19(4) of the Acts Interpretation Act 1901 means that a reference to the Attorney-General may include a reference to a person acting as the Attorney-General.

Item 19 Section 5(4)

277. This item would insert the word "However" before subsection 5(4). This would be a consequence of item 18.

Part 3 – Applicant for special intelligence operation authority

278. This part would amend the ASIO Act to provide that only the Director-General of Security may apply to the Attorney-General for an authority to conduct a special intelligence operation. This part would implement recommendation 68 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 20 Subsection 35B(1)

279. This item would omit references to "a senior position-holder or an ASIO employee". This would ensure that only the Director-General of Security could apply for an authority to conduct a special intelligence operation.

Item 21 Paragraphs 35B(2)(a) and (b)

280. This item would omit references to "the applicant" and substitute "the Director-General". This would be a consequence of Item 20.

Item 22 Subsection 35B(4)

281. This item would omit references to "the applicant" and substitute "the Director-General". This would be a consequence of Item 20.

Item 23 Subsection 35F(1)

282. This item would omit references to "a senior position-holder or an ASIO employee". This would ensure that only the Director-General of Security could apply for a variation to an authority to conduct a special intelligence operation.

Item 24 Paragraphs 35F(2)(a) and (b)

283. This item would omit references to "the applicant" and substitute "the Director-General". This would be a consequence of Item 23.

Item 25 Subsection 35F(3)

284. This item would omit references to "the applicant" and substitute "the Director-General". This would be a consequence of Item 23.

Item 26 Application of amendments

285. This item would provide that the amendments made by this part apply only in relation to applications made under subsections 35B(1) and 35F(1), on or after the commencement of this part.

SCHEDULE 4 - Security vetting and security clearance related activities

Part 1 – Security clearance suitability assessments

286. This part would amend the ASIO Act to clarify the definition of terms used in that Act and enable the Director-General of Security to delegate their power or function to furnish non-prejudicial security clearance suitability assessments to an ASIO employee or ASIO affiliate irrespective of what position within ASIO the person holds.

287. These amendments are required to ensure the effective operation of ASIO's security vetting and security clearance related functions, taking into account the anticipated high volume of security clearance suitability assessments, while ensuring delegations remain commensurate with their impact on a clearance subject.

Australian Security Intelligence Organisation Act 1979

Item 1 Section 4 (paragraph (b) of the definition of security clearance suitability assessment )

288. This item would insert the words "(within the meaning of Part IVA)" after the reference to "security vetting agency" in the definition of security clearance suitability assessment. This would clarify that the reference to "security vetting agency" takes its meaning from Part IVA.

Item 2 At the end of paragraph 16(1C)(b)

289. This item would insert the words "that is a prejudicial security clearance suitability assessment (within the meaning of Part IVA)" after paragraph 16(1C)(b).

290. The effect of this amendment would be to maintain that the Director-General of Security can only delegate the power or function under subsection 82D(1) to furnish a prejudicial security clearance suitability assessment under paragraph 82C(1)(d) to ASIO employees or ASIO affiliates who hold, or who are acting, in a position in ASIO that is equivalent to or higher than an Executive Level 1 (EL 1) position.

291. As a consequence of this amendment to subsection 16(1C), subsection 16(1B) would allow the Director-General of Security to delegate their power or function to furnish non-prejudicial security clearance suitability assessments under paragraph 82C(1)(d) to an ASIO employee or affiliate regardless of the substantive level of the position they hold. This could include an ASIO employee or ASIO affiliate who is not in a substantive position that is equivalent to an EL1.

292. The purpose of this item is to ensure ASIO's continued ability to expeditiously complete non-prejudicial security clearance suitability assessments. These changes are to ensure that ASIO is able to meet security clearance demand in a way which is scalable and commensurate to the impact such assessments and decisions could have on a person.

293. ASIO's Annual Report 2022-23 shows ASIO finalised 35,055 personnel security assessment referrals for the year. Requiring every one of these assessments to be approved by an EL1 officer can be expected to cause significant delays in ASIO's personnel security clearance processes.

294. Additionally, the exercise of the power or function to furnish prejudicial security clearance suitability assessment remains with an EL1 officer, noting such an outcome has an adverse impact on the subjects. The subjects' eligibility for certain roles can be curtailed, or their ability to continue to hold their existing role could be jeopardised. Non-prejudicial assessments, on the other hand, represent good news for the subjects — non-prejudicial decisions allow subjects access to certain employment opportunities or job roles they would not otherwise have. Therefore, because non-prejudicial assessments do not have an adverse outcome for the subject, they should not need to be subject to the same higher levels of approval. The Inspector-General of Intelligence and Security will also continue to have oversight of ASIO's security clearance suitability assessments, ensuring the legality and propriety of their conduct.

295. Finally, notwithstanding that under this amendment the delegation to issue non-prejudicial security clearance suitability assessments can be made regardless of the rank held, ASIO can be expected to continue to maintain appropriate internal management oversight and scrutiny of its security assessment processes, including in relation to non-prejudicial decisions. Employees and affiliates exercising the delegated function or power, regardless of substantive position, can be expected to have suitable training and experience to make non-prejudicial decisions, proportionate and appropriate to the significance of the decision being made. Maintaining the requirement for approval of non-prejudicial security assessments at EL1 is therefore both unnecessary and undesirable, and this amendment would ensure that ASIO is able to meet security clearance demand in a way which is scalable and commensurate to the impact such assessments and decisions could have on a person.

Item 3 At the end of subsection 16(1C)

296. This item would insert a note at the end of subsection 16(1C) that the Director-General of Security may under subsection 16(1B) delegate their power or function under subsection 82D(1) to furnish non-prejudicial security clearance suitability assessments. This item would assist with readability of subsection 16(1C) and is consequential to the amendment made by Item 2.

Item 4 Application of amendments

297. This item would provide that the amendments made by this part apply only in relation to security clearance suitability assessments furnished on or after the commencement of this item.

Part 2 – Delayed assessments and security clearance decisions

298. This part would amend the ASIO Act to require ASIO to cause the Inspector-General of Intelligence and Security to be notified of certain security clearance decisions and security clearance suitability assessments not made within 12 months from when ASIO commences consideration of the decision or preparation of the suitability assessment.

299. This part would respond to recommendation 199 of the Comprehensive Review.

Australian Security Intelligence Organisation Act 1979

Item 5 Subsection 82A

300. This item would insert a definition of "delayed security clearance decision" and "delayed security clearance suitability assessment" into section 82A. The effect of this item would to refer the reader to the definitions at subsections 82GA(1) and (2).

Item 6 Subsection 82B (after the paragraph beginning "There are some limitations")

301. This item would insert in the simplified outline of Part IVA, that the Director-General of Security must cause the Inspector-General of Intelligence and Security to be notified of delayed security clearance decisions and delayed security clearance suitability assessments and that the Director-General must make a protocol for dealing with such decisions and suitability assessments.

Item 7 At the end of Division 2 of Part IVA

302. Subsection 82GA(1) would provide that if a security clearance decision is not made under Part IVA within 12 months after ASIO starts to consider making the decision, the Director-General of Security must cause the Inspector-General of Intelligence and Security to be notified of the delayed security clearance decision. These security clearance decisions are defined as "delayed security clearance decisions". The method by which the Director-General may cause the Inspector-General of Intelligence and Security to be notified is not prescriptive, but may include directing an ASIO employee or ASIO affiliate, developing policies and procedures requiring a person holding a particular position to do the notifying, or set up processes (including automated processes) to cause the notification.

303. The note to subsection 82GA(1) would direct the reader to subsection 82GB(1) which provides that a protocol must be made under that subsection, and specify when ASIO is taken to have started to consider making a security clearance decision, which may be specified differently for different classes of security clearance decisions (referencing subsections 82GB(3) and (4)).

304. Subsection 82GA(2) would provide that if a security clearance suitability assessment is not furnished under Part IVA within 12 months after ASIO starts to prepare the suitability assessment, the Director-General of Security must cause the Inspector-General of Intelligence and Security to be notified of the delayed security clearance suitability assessment. These security clearance suitability assessments are defined as "delayed security clearance suitability assessments". The method by which the Director-General may cause the Inspector-General of Intelligence and Security to be notified is not prescriptive, but may include directing an ASIO employee or ASIO affiliate, developing policies and procedures requiring a person holding a particular position to do the notifying, or set up processes (including automated processes) to cause the notification.

305. The Note to subsection 82GA(2) would direct the reader to subsection 82GB(1) which provides that a protocol must be made under that subsection, and specify when ASIO is taken to have started to prepare a security clearance suitability assessment, which may be specified differently for different classes of security clearance suitability assessments (referencing subsections 82GB(3) and (4)).

306. Subsection 82GA(3) would provide that the notification under subsections 82GA(1) and (2) must be made within the period specified, for the purposes of subparagraph 82GB(3)(b)(i), include the information specified in the protocol as required by subparagraph 82GB(3)(b)(ii), and comply with any other requirements specified in the protocol for the purposes of paragraph 82GB(3)(d). The reference to the protocol in subsection 82GA(3) is a reference to the protocol made under subsection 82GB(1) as in force from time to time (i.e. at the time the notification is made).

307. Subsection 82GA(4) would set out exceptions to the requirement to notify. Paragraph 82GA(4)(a) would provide that notification would not be required where ASIO has been notified that a security clearance decision or security clearance suitability assessment is no longer required. For example, a security vetting agency may notify ASIO that an applicant for a role in the Police Service of a State has withdrawn from the recruitment process.

308. Paragraph 82GA(4)(b) would provide an exception to the requirement to notify where ASIO has initiated the making of the decision or preparation of the suitability assessment, without a request for the decision or suitability assessment being made by another Commonwealth agency, a State or an authority of a State. This exception allows for where ASIO, in the course of performing its functions, might self-initiate enquiries to establish whether an existing security clearance holder should continue to hold a security clearance. As this would be done internally by ASIO, without the subject, or another security vetting agency being aware, it may be unnecessary for the decision or assessment to be made or furnished within 12 months and therefore notification to the Inspector-General of Intelligence and Security would not be appropriate in the circumstances.

309. Subsection 82GA(5) would set out the application of section 82GA.

310. It would provide that section 82GA applies to a security clearance decision that ASIO starts to consider making on or after the commencement of section 82GA.

311. It would also provide that section 82GA applies to a security clearance suitability assessment that ASIO starts to prepare on or after the commencement of section 82GA.

312. Subsection 82GB(1) would require the Director-General of Security to make a written protocol for dealing with delayed security clearance decisions and delayed security clearance suitability assessments.

313. Note 1 to subsection 82GB(1) would alert the reader to subsection 33(3) of the Acts Interpretation Act 1901, which provides that where an Act confers a power to make an instrument, the power includes a power exercisable in the like manner and subject to the like conditions (if any) to repeal, rescind, revoke, amend, or vary any such instrument. This would confirm the power for the Director-General of Security to repeal, rescind, revoke, amend or vary a protocol made under subsection 82GB(1). For the avoidance of doubt, the Director-General of Security would be required to consult with the Inspector-General of Intelligence and Security before repealing, rescinding, revoking, amending or varying the protocol.

314. Note 2 to subsection 82GB(1) would note that such a protocol may be combined with a protocol made under subsection 42(1), which relate to delayed security assessments.

315. Subsection 82GB(2) would provide that the Director-General of Security must consult with the Inspector-General of Intelligence and Security before making a protocol under subsection 82GB(1).

316. Subsection 82GB(3) would set out what can, and must be dealt with in a protocol.

317. Paragraph 82GB(3)(a) provides that the protocol must specify when ASIO is taken to have started to consider making a security clearance decision or prepare a security clearance suitability assessment.

318. The information that is required for ASIO to undertake security vetting and security clearance related activities in accordance with Part IVA can vary considerably depending on a range of factors, including the level of clearance, the person's background and history, and whether the person has previously held a security clearance and at what level. Different circumstances may require more information to be collected before ASIO is able to start to consider the security clearance decision or prepare the security clearance suitability assessment. This paragraph would enable greater flexibility to deal with different classes of security clearance decisions and security clearance suitability assessments, to ensure ASIO is not required to notify the Inspector-General of Intelligence and Security of delays in the furnishing of security clearance decisions and security clearance suitability assessments when the delays are a result of matters that are beyond ASIO's control.

319. Paragraph 82GB(3)(b) would provide that the protocol must specify the period in which notification of a delayed security clearance decision or security clearance suitability assessment must be made, and the information to be included in the notification. These matters will necessarily engage questions of ASIO's internal processes and procedures which are classified. It is therefore necessary they be included in the protocol and not made public or set out in legislation.

320. Paragraph 82GB(3)(c) would provide that the protocol must deal with steps to be taken by ASIO in relation to delayed a security clearance decision or delayed security clearance suitability assessment, after the notification under section 82GA is made. The purpose of the paragraph is to ensure the protocol includes steps to be taken beyond merely notifying the Inspector-General of Intelligence and Security of a delayed security clearance decision or delayed security clearance suitability assessment. Such steps could include providing an explanation to Inspector-General of Intelligence and Security of the reasons for taking longer than 12 months, directions to take steps as set out in relevant policies or procedures, or requiring relevant senior executive officers to be briefed

321. Paragraph 82GB(3)(d) would provide that the protocol may specify other requirements, or deal with any other matters that relate to a delayed security clearance decision or delayed security clearance suitability assessment, or the notification of the decision or suitability assessment under section 82GA, and that the Director-General of Security considers appropriate.

322. Subsection 82GB(4) would provide that the protocol may provide differently for different classes of security clearance decisions or security clearance suitability assessments. For example, the protocol may provide differently for a Baseline clearance than a Positive Vetting clearance, or between a person who is a new applicant for a security clearance and an existing security clearance holder.

323. Subsection 82GB(5) would provide that a protocol made under subsection 82GB(1) is not a legislative instrument. This provision would exempt the protocol from being a legislative instrument under the Legislation Act 2003.

324. ASIO's security vetting and security clearance related activities, including its processes are classified on the basis that it is necessary to keep this information confidential to avoid exploitation by hostile groups. If information pertaining to ASIO's requirements and methodology were made public, entities could study those processes and develop systems and approaches to exploit the security vetting and security clearance process. As such, it would not be appropriate for this information to be included in a legislative instrument, which would make the instrument public.

325. Noting the types of information that are likely to be included in the protocol, including how ASIO manages different classes of security clearance decisions and security clearance suitability assessments, and the types of information ASIO requires to be able to perform its functions, the protocol will need to be classified in order to operate as intended. It therefore would not be suitable for inclusion in a legislative instrument, which would be available to the general public. That the protocol is subject to consultation with the Inspector-General of Intelligence and Security, and its implementation will be monitored by the Inspector-General of Intelligence and Security, provides a safeguard to ensure the protocol is appropriately configured to the underlying purpose of promoting ASIO being accountable in respect of delayed security clearance decisions and delayed security clearance suitability assessments.

326. Subsection 82GB(6) would provide that ASIO must in relation to a delayed security clearance decision or delayed security suitability assessment to which subsections 82GA(1) or (2) applies, comply with a protocol made under subsection 82GB(1) as it force from time to time.


View full documentView full documentBack to top