• About
  • Careers
  • Charity and Not-For-Profit
  • Client Portal
  • Commercial
  • Contact Us
  • Dispute Resolution
  • Home
  • News & Insights
  • Our Team
  • Pay Your Bill
  • Portfolio
  • Privacy Policy
  • Home
  • About
  • OUR PRACTICE GROUPS
    • Commercial
    • Dispute Resolution
    • Charity and Not-For-Profit
  • Our Team
  • News & Insights
  • Contact Us
    • Careers
  • (03) 9629 9629 (Main Line)
Business  ·  News

To Report or not to Report: Mandatory Privacy Breach Reporting Obligations

By admin  Published On 16/02/2017

To Report or not to Report: Mandatory Privacy Breach Reporting Obligations

The Federal government has recently passed new legislation which amends the Privacy Act 1988 (Cth) (“Privacy Act”), by making it mandatory for entities to self-report a privacy breach.

Overview

The Privacy Amendment (Notifiable Data Breaches) Bill 2016 amends the Privacy Act to oblige certain entities to notify affected persons and the Privacy Commissioner if an eligible data breach in the Privacy Act) occurs.

Who does the Privacy Act apply to?

Broadly, certain entities, credit reporting bodies, credit providers and file number recipients all have obligations under the Privacy Act.

Small business operators (businesses with less than $3 million turnover) are generally exempt from the privacy obligations, although there are some instances where they may need to comply with the Privacy Act – including if they hold health information in relation to the provision of a health service, they are a credit reporting body or they are a contracted service provider for a Commonwealth contract.

If you’re not sure whether your organisation is required to comply with the Privacy Act, we recommend seeking our advice in order to avoid the consequences of failing to comply with any applicable obligations.

What is an eligible data breach?

Not every privacy breach constitutes an eligible data breach. An eligible data breach arises where there is either:

  • unauthorised access to, or unauthorised disclosure of, personal information, and a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to which it relates; or
  • loss of personal information, making unauthorised access to or unauthorised disclosure of the information likely to occur and, if it were to occur, it would be likely to result in serious harm.

The Privacy Act gives guidance on determining whether a reasonable person would conclude that serious harm will likely result from the unauthorised access or disclosure of personal information. Amongst other things, you will need to assess:

  • the sensitivity of the information
  • whether the information is encrypted and the likelihood of the encryption being overcome
  • the persons to whom the information has been disclosed or the persons who have accessed the information.

When is a data breach not an eligible data breach?

It is possible to avoid having a privacy breach be considered an eligible data breach, however your actions will need to remove the likelihood of serious harm resulting from the unauthorised access, disclosure or loss of information.

What will you have to do if you suspect there is an eligible data breach?

If you are aware of reasonable grounds to suspect that there is an eligible data breach, you will need carry out a reasonable and expeditious assessment of whether there are in fact reasonable grounds to believe that the relevant circumstances amount to an eligible data breach. You must take all reasonable steps to complete the assessment within 30 days of becoming aware of the possible breach.

What will you need to do if there is an eligible data breach?

If there has been an eligible data breach, you will need to prepare a statement that includes the identity of the entity (or entities) that suffered the eligible data breach, a description of the eligible data breach, the kinds of information that have been accessed, disclosed or lost, and the recommended steps that affected individuals should take in response. You will need to provide this statement to the affected individuals and the Privacy Commissioner as soon as practicable following the preparation of the statement. You must provide the notice in the manner outlined in the Privacy Act.

A breach of these mandatory breach notification provisions constitutes an interference with the privacy of an individual. Serious or repeated offences are punishable by a civil penalty of up to $1.7 million.

What to do next?

  1. Determine if you’re required to comply with the Privacy Act.
  2. Review your privacy policies and procedures in relation to the handling of personal information.
  3. Update your privacy policies and procedures to ensure that you’re prepared in the unfortunate event there is unauthorised access or disclosure or loss of information.

If you need assistance, please contact Peter North, Senior Associate or Caroline James, Lawyer from the Business Team on 03 9629 9629.


Privacy Actprivacy breachself-report breach

Related Articles


Business
Privacy Act Changes
Business  ·  News
The rise of the drones and what it means for your privacy
Business  ·  Corporate  ·  News
5 Things You Need to Know About Privacy
Termination for misuse of social media – police with the right policy in place
Previous Article
Not Such a Signature Trade Mark
Next Article

QUICK LINKS

HOME ABOUT OUR PRACTICE GROUPS OUR TEAM NEWS & INSIGHTS CONTACT US CLIENT PORTAL PRIVACY POLICY
  • +613 9629 9629 (Main Line)
  • office@lewisholdway.com.au
  • Level 10, 91 William St. Melbourne VIC 3000
  • P.O. Box 138, Collins Street West VIC 8007

OUR PARTNERS

Copyright © 2021 Lewis Holdway Lawyers.