Insight

New Australian Data Breach Notification Laws

The Privacy Act 1988 (Cth) (Act) has been amended by the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) (the Amending Act). The Amending Act introduces a mandatory data breach notification regime where an “eligible data breach” occurs. The amendments will commence on February 23, 2018, unless they are proclaimed to commence earlier.

Data Breach Notification Laws

Giovanni Marino

May 30, 2017 12:06 PM

Introduction

The Privacy Act 1988 (Cth) (Act) has been amended by the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) (the Amending Act). The Amending Act introduces a mandatory data breach notification regime where an “eligible data breach” occurs. The amendments will commence on February 23, 2018, unless they are proclaimed to commence earlier.

Who is required to comply with the new laws?

The new reporting regime will apply to APP entities that hold personal information. In general, private health care organizations, including community health centers and other private health providers will be considered APP entities.

What is an eligible data breach?

An eligible data breach occurs where there is:

  • unauthorized access to or unauthorized disclosure of information; or
  • loss of the information where unauthorized access or disclosure is likely; and

a) a reasonable person would conclude that the access or disclosure would likely result in serious harm to any of the individuals to whom the information relates.

These individuals to whom the serious harm would likely result are defined as being “at risk.”

Serious harm is not defined in the act, but the explanatory memorandum to the amendments states that serious harm could include “serious physical, psychological, emotional, economic and financial harm, as well as serious harm to reputation, and other forms of serious harm that a reasonable person in the entity’s position would identify as a possible outcome of the data breach.”

What are the notification requirements?

If an organization has reasonable grounds to believe that there has been an eligible data breach, then it must provide a statement to the Australian Information Commissioner (the Commissioner), which sets out a range of mandated matters.

As soon as practicable after preparing the statement for the Commissioner, the organization must also take reasonable steps to notify the statement information to either:

  • each individual to whom the information relates; or
  • if not, all these individuals are deemed to be at risk, only those affected individuals who are deemed to be at risk.

Are there any exceptions to the data breach notification requirements?

There are certain exceptions to the notification regime, including where an organization takes remedial action to address any unauthorized access to or disclosure of information or loss of information, and:

  • in relation to unauthorized access or disclosure, the remedial action occurs before there is any serious harm to any affected individuals to whom the information relates, and a reasonable person would conclude the access or disclosure would not likely result in serious harm to any of those individuals; or in relation to loss of information, the remedial action occurs:

a) before there is any unauthorized access to or disclosure of the information, and as a result of the action there is no unauthorized access or disclosure; or

b) after there is any unauthorized access to or disclosure of the information, but before the access or disclosure results in serious harm to any individuals to whom the information relates and a reasonable person would conclude the access or disclosure would not likely result in serious harm to any of those individuals.

What happens if an organization does not comply with the requirements?

Breach of the data breach notification requirements are taken to be acts that are “an interference with the privacy of an individual.” Section 13G of the act provides that a civil penalty applies to serious or repeated interferences with the privacy of an individual. An individual penalty of $360,000 and a maximum corporate penalty of $1,800,000 currently apply for breach of this provision.

Conclusion

Organizations should review their policies and procedures regarding data breaches and prepare data breach response plans in line with the requirements of the Amending Act (if these are not in place already). The data breach response plans should contemplate potential remedial action to prevent any serious harm from occurring to any affected individuals.

Organizations that hold or share data in collaboration with other entities or service providers may wish to establish processes to enable a coordinated response to any data breach.

------------------------

Giovanni Marino is a senior solicitor with Health Legal, who prior to joining Health Legal, was a physiotherapist. This health background brings practical experience to Giovanni’s work as a lawyer. Giovanni provides a broad range of legal assistance to health care providers across Australia, including advice on their legal obligations (in areas such as medico-legal, privacy, and employment) and assistance with contract drafting and negotiations. More can be found at www.healthlegal.com.au.

Trending Articles

The 2024 Best Lawyers in Spain™


by Best Lawyers

Best Lawyers is honored to announce the 16th edition of The Best Lawyers in Spain™ and the third edition of Best Lawyers: Ones to Watch in Spain™ for 2024.

Tall buildings and rushing traffic against clouds and sun in sky

Presenting The Best Lawyers in Australia™ 2025


by Best Lawyers

Best Lawyers is proud to present The Best Lawyers in Australia for 2025, marking the 17th consecutive year of Best Lawyers awards in Australia.

Australia flag over outline of country

Best Lawyers Expands Chilean 2024 Awards


by Best Lawyers

Best Lawyers is pleased to announce the 14th edition of The Best Lawyers in Chile™ and the inaugural edition of Best Lawyers: Ones to Watch in Chile™, honoring the top lawyers and firms conferred on by their Chilean peers.

Landscape of city in Chile

Best Lawyers Expands 2024 Brazilian Awards


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Brazil™ and the first edition of Best Lawyers: Ones to Watch in Brazil™.

Image of Brazil city and water from sky

Announcing The Best Lawyers in South Africa™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 15th edition of The Best Lawyers in South Africa™ for 2024, including the exclusive "Law Firm of the Year" awards.

Sky view of South Africa town and waterways

The Best Lawyers in Mexico Celebrates a Milestone Year


by Best Lawyers

Best Lawyers is excited to announce the 15th edition of The Best Lawyers in Mexico™ and the second edition of Best Lawyers: Ones to Watch in Mexico™ for 2024.

Sky view of Mexico city scape

How Palworld Is Testing the Limits of Nintendo’s Legal Power


by Gregory Sirico

Many are calling the new game Palworld “Pokémon GO with guns,” noting the games striking similarities. Experts speculate how Nintendo could take legal action.

Animated figures with guns stand on top of creatures

The Best Lawyers in Portugal™ 2024


by Best Lawyers

The 2024 awards for Portugal include the 14th edition of The Best Lawyers in Portugal™ and 2nd edition of Best Lawyers: Ones to Watch in Portugal™.

City and beach with green water and blue sky

The Best Lawyers in Peru™ 2024


by Best Lawyers

Best Lawyers is excited to announce the landmark 10th edition of The Best Lawyers in Peru, the prestigious award recognizing the country's lop legal talent.

Landscape of Peru city with cliffside and ocean

How To Find A Pro Bono Lawyer


by Best Lawyers

Best Lawyers dives into the vital role pro bono lawyers play in ensuring access to justice for all and the transformative impact they have on communities.

Hands joined around a table with phone, paper, pen and glasses

Presenting the 2024 Best Lawyers Family Law Legal Guide


by Best Lawyers

The 2024 Best Lawyers Family Law Legal Guide is now live and includes recognitions for all Best Lawyers family law awards. Read below and explore the legal guide.

Man entering home and hugging two children in doorway

The Best Lawyers in Colombia™ 2024


by Best Lawyers

Best Lawyers is honored to announce the 14th edition of The Best Lawyers in Colombia™ for 2024, which honors Colombia's most esteemed lawyers and law firms.

Cityscape of Colombia with blue cloudy sky above

Announcing the 2024 Best Lawyers in Puerto Rico™


by Best Lawyers

Best Lawyers is proud to announce the 11th edition of The Best Lawyers in Puerto Rico™, honoring the top lawyers and firms across the country for 2024.

View of Puerto Rico city from the ocean

Announcing The Best Lawyers in Japan™ 2025


by Best Lawyers

For a milestone 15th edition, Best Lawyers is proud to announce The Best Lawyers in Japan.

Japan flag over outline of country

Canada Makes First Foray Into AI Regulation


by Sara Collin

As Artificial Intelligence continues to rise in use and popularity, many countries are working to ensure proper regulation. Canada has just made its first foray into AI regulation.

People standing in front of large, green pixelated image of buildings

Announcing The Best Lawyers in New Zealand™ 2025 Awards


by Best Lawyers

Best Lawyers is announcing the 16th edition of The Best Lawyers in New Zealand for 2025, including individual Best Lawyers and "Lawyer of the Year" awards.

New Zealand flag over image of country outline