WorldPrivacyAtlas
Laws by country

Sector-Specific Law

Security of Critical Infrastructure Act 2018

SOCI Act

Australia · July 11, 2018; the 2024 amendments received assent November 29, 2024

SOCI covers eleven sectors — including health care and medical, financial services and markets, data storage or processing, communications, energy, transport and higher education and research — and imposes register, risk-management and incident-notification duties on responsible entities for covered assets, with cyber incidents notifiable on short statutory timeframes and a critical infrastructure risk management program required and annually attested. The change that matters most for a data business came with the 2024 amendments: a DATA STORAGE SYSTEM can now form part of the primary critical infrastructure asset where the responsible entity owns or operates it, it is used in connection with the asset, it holds or processes business-critical data, and a hazard affecting it could have a relevant impact on the asset. That pulls storage and processing environments inside a regime many operators assumed applied only to the physical asset. Regulators also gained power to direct an entity to vary a risk management program with serious deficiencies.

Security of Critical Infrastructure Act 2018 (Cth), as amended by the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.