privacy compliance

Privacy determination –Sensitive Information stored in garden shed

HomePrivate: BlogLegal insightsPrivacy determination –Sensitive Information stored in garden shed

by

reviewed by

Malcolm Burrows

The Privacy Commissioner, Timothy Pilgrim, has found that a Melbourne medical centre has breached the Privacy Act 1988 (Cth) (Privacy Act) in failing to provide adequate security to protect Sensitive Information contained in medical information. The breach occurred before the Australian Privacy Principles (APPs) took effect and therefore the medical centre was found to have breached the National Privacy Principles (NPPs).

The medical centre stored the files of around 960 patients in a locked garden shed. The security of the files was compromised when the shed was broken into. The files contained detailed personal information including individuals’ full name, address, date of birth, Medicare number, treatment details as well as patient’s discharge summaries.

Under section 6(1)(b) of the Privacy Act Sensitive Information includes Health information which under section 6(1)(a) includes, but it not limited to, information or an opinion about: the health or a disability (at any time) of an individual that is also personal information; or other personal information collected to provide, or in providing, a health service.

The Privacy Commissioner highlighted the insecure, temporary nature of a garden shed and its inadequacy to protect sensitive information from unauthorised access and misuse. The files belonged to many patients that existed prior to 2004. In these circumstances many of the patient files should have been destroyed or de-identified as they were no longer necessary for the purpose in which they were collected. The files could have been shredded or disposed of using another secure method. In failing to take these steps, the medical centre placed its patients at risk of identity fraud.

The Commissioner advised the medical center to undergo a privacy risk assessment, train staff and develop a privacy breach response plan.

The amendments

The Privacy Act now contains thirteen (13) new Australian Privacy Principles aimed at protecting Personal Information.   The APPs apply to business with an annual turnover of more than $3 million, as well as some small businesses including Health Service providers. The actions of the medical center breached the new APP 11 which requires businesses to take reasonable steps to secure Personal Information. The finding suggests that keeping Sensitive Information in a locked garden shed does not constitute “reasonable steps”.

Civil Penalty Provisions

Recent amendments to the Privacy Act have provided the privacy commissioner with the new powers. The Commissioner may apply to the Federal Court for civil penalties orders. The civil penalty provisions currently allow for penalties of up to:

  • $A340,000 for an individual; and
  • $A1.7 million for a company.

While the substance of the principles under the Privacy Act have not changed. The penalties and prescriptive requirements have become more onerous. Health Services providers and other small business should consider this finding when assessing the adequacy of their current security procedures.

Links and further references

Legislation

Privacy Act 1988 (Cth)

Privacy Amendment (Enhancing Privacy Protection) Act 2012

Other references

Office of the Australian Information Commissioner, APP Guidelines

Office of the Australian Information Commissioner, Australian Privacy Principles

Further information

If you need further information about complying with the Privacy Act 1988 (Cth), contact us for a confidential and obligation-free discussion:


Related insights about privacy compliance

  • Uber found in breach of Australian privacy laws

    Uber found in breach of Australian privacy laws

    This article provides an overview of interesting decisions of Australian Courts in Corporate Law, Technology Law and Intellectual Property. With cases on Trade Marks, Copyright, Defamation, Negligence, Joint Ventures and Confidential Information, it is an invaluable resource for anyone interested in these areas.

    Read more …

  • Overview of the Ransomware Payments Bill 2021 (Cth)

    Overview of the Ransomware Payments Bill 2021 (Cth)

    Australian government proposed the Ransomware Payments Bill 2021 (Cth) (Bill) to enforce mandatory reporting of ransomware payments. Penalties of up to $110,000 for non-compliance.

    Read more …

  • International businesses subject to Australian privacy laws

    International businesses subject to Australian privacy laws

    Australian Intelligence Community (AIC) Commissioner Falk determined how the Office of the Australian Information Commissioner (OAIC) will assess if international entities have an Australian Link to Privacy Act 1988 (Cth).

    Read more …

  • 7-Eleven customer survey: implied consent?

    7-Eleven customer survey: implied consent?

    The Office of the Australian Information Commissioner found 7-Eleven Stores Pty Ltd are in breach of the Australian Privacy Principles (APP’s). Learn more about the findings, implications, and how businesses can comply with the APP’s.

    Read more …

  • Use of confidential information – the springboard injunction

    Use of confidential information – the springboard injunction

    This article examines the UK decision of Forse & ors v Secarma Ltd & ors [2019] EWCA Civ 215, which discussed the legal concept of a springboard injunction, and its implications in Australia. The Court must consider similar principles to determine if an injunction should be granted.

    Read more …

  • Swiss company hands over user data

    Swiss company hands over user data

    A Court order in Switzerland raises questions about Australian law enforcement’s ability to access encrypted data. This article explores the legislative perspective on accessing private or business communications, and the steps taken to protect transmitted information.

    Read more …

  • Parliament passes Government surveillance bill

    Parliament passes Government surveillance bill

    The Surveillance Legislation Amendment (Identify and Disrupt) Bill 2021 added three (3) warrants, allowing law enforcement to access data and take control of online accounts to obtain evidence of serious online crime.

    Read more …

  • Data breach compliance and response plans

    Data breach compliance and response plans

    Dundas Lawyers create tailored data breach response plans to ensure compliance with the Privacy Act 1988 (Cth). Plans include actions, registers, records, tests and tasks. Get an obligation-free and confidential discussion to learn more.

    Read more …

  • The Australian Cyber Law Map – overview

    The Australian Cyber Law Map – overview

    The Australian Cyber Law Map provides clarity on ever-changing legal landscape, covering commercial enterprises, cyber offences, infrastructure, international law, national security and personal rights. A source for understanding laws and providing safety/security in the digital age.

    Read more …


Posted

in

Send this to a friend