Costs and Architecture diagram for COVIDSafe server technologies

Currently waiting for a response from Digital Transformation Agency, they should respond promptly and normally no later than (details).

Dear Digital Transformation Agency,

Please provide documents detailing

1) Monthly cost breakdowns for Amazon Web Services spend related to COVIDSafe server side components
2) Architecture diagrams and related resource requirements for COVIDSafe Amazon Web Services components.

Yours faithfully,
Richard Nelson

Dear Digital Transformation Agency,

To understand why this is being requested as a matter of public interest; I believe taxpayers deserve to know how an application that is of dubious value, and where the vast majority of application data is stored on end users’ phones, costs a reported $100k/month in hosting. The AWS bill, resourcing requirements and architecture diagrams would help explain this - and/or clarify if the reporting is misleading.

I don’t believe that publishing either of these items would be of concern with regards to security of the application or data. Already published design of COVIDSafe data encryption, transport and existing security controls are sufficient; hiding architecture details or cost breakdowns would simply be obscurity.

Yours faithfully,
Richard Nelson

DTA FOI, Digital Transformation Agency

OFFICIAL

Dear Richard

I acknowledge receipt of your request dated 26 March 2021 in which you requested under the Freedom of Information Act 1982 (the FOI Act) access to:

“1) Monthly cost breakdowns for Amazon Web Services spend related to COVIDSafe server side components
2) Architecture diagrams and related resource requirements for COVIDSafe Amazon Web Services components.”


Notice of Consultation

Your request covers a document relating to the business, commercial or financial affairs of an organization. Accordingly, DTA is required to consult with the organisation concerned before making a decision on the release of this document.

Section 27 of the FOI Act provides that if a request is made to an agency for access to a document containing business information organisation, and it appears to the agency that the organization might reasonably wish to make a contention that the document is exempt under section 47 (trade secrets etc), or section 47G (business information) of the FOI Act, then the agency must not decide to give access to the document unless the organisation concerned is given a reasonable opportunity to make submissions in support of their contention, if it is reasonably practicable to do so.

The DTA will take into account any comments we receive from the organisation. However, the final decision on whether to grant access to the document requested rests with DTA.

Extension of time to process the request
In accordance with section 15(6) of the FOI Act, the period for processing your request has been extended by an additional 30 days in order to allow DTA time to consult with the organisation. The processing period for this request will now end on 26 May 2021.

If you have any questions please don’t hesitate to contact me directly

Regards
Suzie Sazdanovic
Privacy and FOI Manager
Digital Transformation Agency (DTA)
T 02 6120 8595

OFFICIAL

show quoted sections