Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

ALRC renews data loss financial penalty call

ALRC says fines could help after UK introduced penalties of up to half a million pounds for data breaches
The ALRC has renewed its call for the government to introduce financial penalties for data breaches

The ALRC has renewed its call for the government to introduce financial penalties for data breaches

The Australian Law Reform Commission (ALRC) has renewed its call for fines for failing to notify the privacy commissioner of data breaches after the UK introduced penalties of up to half a million pounds.

The ALRC initially made the call in its report: For Your Information: Australian Privacy Law and Practice released in 2008.

Authorities in the UK recently amended the Data Protection Act to allow the Information Commissioner to issue fines for data breaches of up to £500,000.

ALRC research manager Jonathan Dobison said the penalty method would be effective in the current information age, where there is an increasing number of ways information can be leaked through technology such as flash drives and laptops.

In February 2006, the Federal Government announced a major review of the Privacy Act 1988 would be undertaken by the ALRC that included how to deal with data loss situations.

In October, the Federal Government released its response to the ALRC's Privacy Act review and said the accepted recommendations will be implemented in two stages.

At the time, the government said draft legislation to implement the first stage changes will be available early this year for consultation

However, the data loss recommendations were not included in the first stage and it is not yet clear whether the government will force organisations to reveal if they have suffered a breach.

Dobison said even though the penalty approach might not stop data breaches, organisations will be more cautious about data protection.

“The idea of penalty is not only to punish but also to deter,” he said.

As part of the ALRC's data breach recommendation, the privacy commissioner only needs to be notified of a breach if there is a real risk, such as the leak of a name, address or another unique identifier.

Dobison added that notification to the privacy commissioner would not be required if the incident is not in the public interest.

There are few high-profile cases of Australian organisations having suffered a data breach in the public domain.

However, in the past few years there have been several notable cases in the UK and US where laws are more stringent and organisations are obliged to report breaches.

For instance, in late 2008 an unencrypted laptop with data on up to 600,000 people was stolen from a UK Ministry of Defence recruiting officer's car.

One infamous case was the loss of a CD with data on almost half of the UK's population - including dates of birth, addresses, bank accounts and national insurance numbers - in the post by HM Revenue & Customs.

And in October last year The Guardian newspaper was forced to notify 500,000 people that details they posted to the newspaper's employment site may be in the hands of hackers.

The Australian Federal Government has recently called in Symantec for consulting advice on the data breach notification laws aimed at notifying consumers when a business has lost or compromised data linked to them.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Australian Federal Government, Federal Government, Symantec
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: alrc, data breach, data loss, privacy act, UK
Latest Blog Posts
Whitepapers
  • Managing IBM License Complexity
    IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on.
    Learn more »
  • Restore control, Reinforce security & Reduce Cost
    Uncontrolled print environments and practices present a serious risk to the profit and security of your organisation. IT is under pressure to protect sensitive information, secure devices, and improve the way they manage the entire fleet. To gain better control, your organisation needs to implement plans that meet industry regulations while also increasing productivity, lowering costs, and providing users with more flexible imaging and printing solutions. Read more.
    Learn more »
  • CIO Executive Council ROI
    This document was created by Council CIOs as a means to illustrate ROI for membership. It outlines the services available to member CIOs and their deputies.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments