Section 56EOCompetition and Consumer Act 2010 (Cth)

Privacy safeguard 12—security of CDR data, and destruction or de‑identification of redundant CDR data

(1) Each person (a CDR entity) who is:

(a) an accredited data recipient of CDR data; or

(b) a designated gateway for CDR data;

must take the steps specified in the consumer data rules to protect the CDR data from:

(c) misuse, interference and loss; and

(d) unauthorised access, modification or disclosure.

Note: This subsection is a civil penalty provision (see section 56EU).

(2) If:

(a) the CDR entity no longer needs any of that CDR data for either of the following purposes (the redundant data):

(i) a purpose permitted under the consumer data rules;

(ii) a purpose for which the person is able to use or disclose it in accordance with this Division; and

(b) the CDR entity is not required to retain the redundant data by or under an Australian law or a court/tribunal order; and

(c) the redundant data does not relate to any current or anticipated:

(i) legal proceedings; or

(ii) dispute resolution proceedings;

to which the CDR entity is a party;

the CDR entity must take the steps specified in the consumer data rules to destroy the redundant data or to ensure that the redundant data is de‑identified.

Note 1: This subsection is a civil penalty provision (see section 56EU).

Note 2: Australian Privacy Principle 11 will not apply for paragraph (b) (see paragraph 56EC(4)(a) or (d)).

Sourced from the Federal Register of Legislation at 22 May 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au. Verify the current text against the official source before relying on it.

Related sections

Research how courts apply s 56EO

BriefBridge searches Australian caselaw by meaning — every answer cited to the paragraph.

Try BriefBridge free