Privacy Law

Data security – the increasing burden

HomePrivate: BlogLegal insightsData security – the increasing burden

by

reviewed by

Malcolm Burrows

The consequences for an Australian business victim for a breach of cyber security are forecast to exponentially increase. In February 2015 the Parliamentary Joint Committee on Intelligence and Security (Committee) recommended the introduction of mandatory data breach notification scheme (Scheme) by the end of 2015.[1] Whilst the details of the incoming Scheme are currently scant, it is understood that the enacting legislation will have bi-partisan support in federal parliament.

Mandatory data breach notifications requirements a la the Scheme are far from a recent development. They were first recommended by the Australian Law Reform Commission in 2008 and have been in place in the United States since 2003.

Lessons from the United States

Australian businesses have the benefit of approximately fifteen (15) years’ worth of practical guidance from the United States alone. In these fifteen (15) years it is estimated that 675 million data records have been reported as being compromised and 783 data breaches occurred last year alone.[2]

By and large the United States experience demonstrates the significant costs incidental to a data breach that may arise by virtue of mandatory notification schemes. Amongst these costs are the damages to reputation and public relations and the potential litigation commenced by notified parties.

Preparing for the change

Australian businesses should take heed of the United States experience and undertake a comprehensive review of their data breach policies. By ensuring that your policies for reacting to a data breach are airtight you can mitigate any damage that may arise from your obligations under the Scheme. The guidelines for dealing with data breaches released by the Office of the Australian Information Commissioner in 2012 provide a solid foundation (outlined by Dundas Lawyers here) for preparing a policy but you should seek professional advice to develop a policy more tailored to your individual business.

Links and further references

Office of the Australian Information Commissioner, A guide to securing personal information

Office of the Australian Information Commissioner, A guide to data breach preparation and response

Parliamentary Joint Committee on Intelligence and Security, Advisory report on the Telecommunications (Interception and Access) Amendment (Data Retention) Bill 2014

Further information about data security

If you would like further advice on your obligations concerning data breaches please contact us for a confidential and obligation free discussion.

[1] Smith, P, Litigation, PR disasters and higher insurance costs expected from new data breach laws, (2015). Accessed at http://www.afr.com/technology/litigation-pr-disasters-and-higher-insurance-expected-from-new-data-breach-laws-20150805-gis75j accessed on 13 August 2015.

[2] Parliamentary Joint Committee on Intelligence and Security, Advisory report on the Telecommunications (Interception and Access) Amendment (Data Retention) Bill 2014, (2015) at p. 299.


Related insights about data security

  • Data Breach Bill 2016 – key data security considerations

    Data Breach Bill 2016 – key data security considerations

    The Privacy Amendment (Notifiable Data Breaches) Bill 2016 has been passed, making notification of data breaches mandatory from 23 February 2018. Find out how this could affect you and what measures you can take to protect your data.

    Read more …

  • Data security – the increasing burden

    Data security – the increasing burden

    The consequences for an Australian business victim for a breach of cyber security are forecast to exponentially increase. In February 2015 the Parliamentary Joint Committee on Intelligence and Security (Committee) recommended the introduction of mandatory data breach notification scheme (Scheme) by the end of 2015.[1] Whilst the details of the incoming Scheme are currently scant,…

    Read more …

  • Revenge porn – legal options

    Revenge porn – legal options

    Revenge porn (Revenge Porn) refers to sexually explicit media that is distributed without the consent of the individual(s) involved.[1]  An act of Revenge Porn therefore involves the recording of video or still images of a person that is usually engaged in sexual acts (Revenge Content) and publishing or threatening to publish it.  A person’s participation…

    Read more …

  • Cupid Media risks privacy of the dateless

    Cupid Media risks privacy of the dateless

    The Privacy Act 1988 (Cth) (Privacy Act) requires entities to take reasonable steps to secure personal information.

    Read more …

  • Getting confidentiality agreements in place

    Getting confidentiality agreements in place

    Part 5 – Planning a business acquisition Confidentiality Agreements (Confidentiality Agreement or NDA’s) are essential in business Acquisitions, particularly if either the Target or Acquirer is subject to the ASX Listing Rules. Whilst generally an equitable obligation of confidence is applicable, a Confidentiality Agreement reduces the obligations of the parties to writing to ensure that…

    Read more …

  • Changes to the Privacy Act commence today!

    Changes to the Privacy Act commence today!

    Changes to the Privacy Act 1988 (Cth) included the introduction of thirteen Australian Privacy Principles (App’s). Learn more about potential civil penalty orders if you are a business with a turnover of over 3 million or more, a health care provider or a business that trades in personal information.

    Read more …

Send this to a friend