EXPERTISE

PRIVACY

Three significant legal privacy reforms will commence over the course of 2018 in Australia.  The reforms are:

  1. Mandatory notifications of data breaches under the Privacy Act 1988 (Cth);
  2. The General Data Protection Regulation, a European Privacy Law with extraterritorial reach to Australia; and
  3. The Australian Government Agencies’ Privacy Code.

Notifiable data breaches under the Privacy Act will affect almost every organisation in Australia.  This will include all Australian government agencies, almost all businesses and not-for-profit organisations with a turnover of more than $3M per annum together with some smaller businesses such as health service providers and contracted service providers to the Commonwealth.  Also effected are organisations with tax file numbers; credit providers and credit reporting bodies.

The amendments require notification of certain types of data breaches.  Notifiable data breaches are incidents that involve the loss of, or unauthorised access to or disclosure of, personal information that is likely to result in serious harm to one or more individuals.

If the data breach meets this threshold test, notification is required as soon as practicable to the Australian Privacy Commission and the affected individuals.  The legislation sets out the factors that impact whether a data breach is ‘likely to result in serious harm’; the timeframes in which an assessment must be carried out on a suspected breach; and what a notification must contain and how the notification must be made.

Based on an early engagement, William Roberts Lawyers can assist Boards and Management in navigating and complying with their legal obligations.

The General Data Protection Regulation
The general data protection regulation regulates businesses based in the European Union and any organisation around the world that provides goods and services to, or monitors the behaviour of, people in the European Union including the United Kingdom post Brexit.

One of the new principles in the general data protection regulation is the accountability principle which requires organisations to be proactive in that if an organisation does not have an effective privacy compliance program, the organisation can be found to be in breach of its data protection obligations even if there is no actual data breach.

William Roberts Lawyers can work actively with the assist Boards and Management so as to document and audit an insured’s privacy compliance program

Related News

‘Reliance on Third-Party Providers is Always a Risk’: ASIC’s Renewed Focus on Cybersecurity for Financial Institutions

Major cyber-attacks against Medibank and Optus in 2022 pushed cyber security to the forefront for many Australian businesses. Last month, the Australian Securities and Investment

Read More

A COVID-Safe Approach to Privacy

On 2 September 2021, the Office of the Australian Information Commissioner (OAIC) released a framework of 5 universal privacy principles which provide a nationally consistent,

Read More

Hacker-proof? Unpacking the new Privacy Amendments

– what this means for companies Organisations covered by the Australian Privacy Act 1988 (Cth) will soon need to notify eligible data breaches to the Office of

Read More

Home Affairs breaches privacy and ordered to pay compensation to asylum seekers

The Department of Home Affairs has been ordered to pay compensation to 1,297 asylum seekers after mistakenly publishing their personal information online in 2014. The

Read More

Privacy Management Framework: the Commissioner’s expectations for APP entities

The week of 3 to 9 May 2015 is Privacy Awareness Week (PAW) in Australia. PAW is an annual initiative of the Asia Pacific Privacy Authorities Forum,

Read More

Privacy Reforms Update: Introduction of a tort for invasion of privacy

The Privacy and Other Legislation Amendment Act 2024 (Cth) (the Act) is now in effect, following the Privacy and Other Legislation Amendment Bill 2024 being passed by

Read More

Privacy and Cyber Risk – Turning uncertainty into opportunity

Introduction: Australia’s current technological landscape. Australia’s technological landscape is ever evolving. Across sectors, digital technologies are constantly shifting business rules by facilitating new business models.

Read More

The Clearview Case: Privacy and data protection by foreign companies

When foreign companies expand to do business in Australia, they usually consider compliance matters such as taxation, however, they seldom think about compliance issues such

Read More

The Modernisation of Australia’s Privacy Regime

Cyber-security has rapidly emerged as a subject of critical concern across government, business, and the legal profession. The significance of data-security and digital privacy largely

Read More

The Rise of AI: Security vs Privacy

Artificial Intelligence is no longer confined to the realm of science fiction—it is a driving force that is shaping our future in ways most never

Read More

A giant leap for Telcos with the new TCP code

With the introduction of the Telecommunications Consumer Protections (TCP) Code and more regulator scrutiny, telecommunication and internet service providers must ensure their advertising, customer service

Read More

GIPA in the new era

The Government Information (Public Access) Act 2009 (“GIPA”) came into effect on 1 July 2010. On the eve of the seven year anniversary, the NSW Information Commissioner,

Read More

General Data Protection Regulation – What is it?

In 1995, the European Union (EU) adopted the Data Protection Directive (95/46/EC) which protected the rights of individuals with “regard to the processing of [their]

Read More

Learning from others: Notifiable data breach – latest quarterly figures

Since the commencement of the Notifiable Data Breach (NBD) scheme under the Privacy Act 1988 (Cth) in February 2018, the Office of the Australian Information

Read More

NSW to Introduce Mandatory Notification of Data Breach Scheme

NSW will become the first Australian state or territory to introduce a mandatory scheme that requires state public sector agencies to notify the Privacy Commissioner

Read More

The Brave New World of Data (in) Security

It is prudent to be scared rather than brave in the modern world of data breaches and cyber-attacks, where criminal enterprise endeavours to breach effective

Read More

Proposed mandatory data breach notification scheme: An overview

In the context of an ever increasing number of reported data breaches, both locally and internationally, some of which have attracted very significant media interest1,

Read More

Robert Ishak

Principal Lawyer, Director

Carlos Jaramillo

Principal Lawyer, Director

VIEW OUR TEAM

Get in touch

Contact our team today

William Roberts Lawyers

Sydney

Level 22
66 Goulburn Street
SYDNEY NSW 2000

PO Box 20424, World Square NSW 2000

Melbourne

Level 7,

171 La Trobe Street
MELBOURNE VIC 3000

 

PO Box 13171, Law Courts VIC 8010

Brisbane

Level 9
193 North Quay
BRISBANE QLD 4000

 

PO Box 12170, George Street QLD 4003

Singapore

Level 19
Singapore Land Tower
50 Raffles Place
SINGAPORE 048623