23 May 2018

New security rules for investors in critical infrastructure in Australia

This article was written by Louis Chiam, Malcolm Brennan, Intan Eow and Liqing Mao.

Investors and operators of critical infrastructure in Australia will soon need to comply with new security rules.  The new rules, introduced as part of the Australian Government’s new Critical Infrastructure Centre, will apply to most infrastructure in telecommunication, ports, water, electricity and natural gas.

The Security of Critical Infrastructure Act 2018 (the Act) has just been passed and will soon commence on 11 July 2018.

The rules impose new obligations in 2 broad areas: a new register of owners and operators and potential new security requirements.

Register of owners and operators

The rules require owners and operators of critical infrastructure to file their details on a register with the Critical Infrastructure Centre.  There are complex rules that may require disclosure of some upstream investors (including ultimately offshore investors) and some operator and management agreements. 

As this relates to a high profile Government policy on security, it is likely the Australian Government will take a very strict approach to compliance.  It is important, both for legal compliance and reputational reasons, that all international investors ensure they comply fully with these requirements.

The Act applies to the following reporting entities:

  • a responsible entity must provide the operational information in relation to the assets.  Such information includes the arrangements under which each operator operates the asset and arrangements under which data is maintained; and
  • a direct interest holder must provide the interest and control information in relation to the entity and the asset.  Such information includes:
    • the direct interest holder’s influence or control in relation to the assets;
    • the ability of its nominee to access networks or systems necessary for the operation or control of the assets; and
    • information on its direct and indirect controlling entities, and their influence or control in relation to the direct interest holder or an intermediate entity.

The Act has a six-month grace period for reporting entities to report information about critical infrastructure assets to be included in the Register of Critical Infrastructure Assets.  This grace period ends on 11 January 2019.

Potential new security requirements

Further, the Minister has a wide power of direction (the “last resort” power) to require a reporting entity to do or refrain from doing an act if the Minister is satisfied that there is a risk that such an act or omission would be prejudicial to security.

There is no detail publicly available on what these additional requirements may be, but they could extend to matters such as use of non-Australian information technology suppliers, data storage and offshore access to data.

Critical Infrastructure Centre

The Act follows the Australian government’s recent launch of the Critical Infrastructure Centre, now housed in the newly established Department of Home Affairs. The Centre is intended to bring together expertise and capability from across the Australian government to manage national security risks from foreign involvement in Australia’s critical infrastructure.  It focuses on the risks of sabotage, espionage and coercion in the five priority sectors of telecommunications, electricity, gas, water and ports. 

Despite the Centre’s focus on foreign involvement, the Foreign Investment Review Board (FIRB) continues to be responsible for Australia’s foreign investment review process.  But FIRB will work cooperatively with the Critical Infrastructure Centre in assessing foreign acquisitions of critical infrastructure.

For more details, you may refer to our previous KWM Insight Critical infrastructure security – what lies ahead for electricity, ports and water and Espionage, sabotage and infrastructure: what you need to know about the Security of Critical Infrastructure Bill.

Key contacts

A Guide to Doing Business in China

We explore the key issues being considered by clients looking to unlock investment opportunities in the People’s Republic of China.

Doing Business in China
Share on LinkedIn Share on Facebook Share on Twitter Share on Google+
    You might also be interested in

    The US Second Circuit rules that non-US individuals and companies are not subject to the US Foreign Corrupt Practices Act if they are not employees or agents of a US company and if they do not commit...

    31 August 2018

    According to minister Altmaier, the German government seeks to obtain more details about who is involved in takeovers of German businesses and the intention of such investors

    16 August 2018

    we briefly compare some key general differences between PRC law-governed contracts and common law-governed contracts.

    08 August 2018

    It’s particularly worth noting that, the NDRC made restrictive interpretations with respect to the scope of sensitive projects.

    10 July 2018