ALRC renews data loss financial penalty call
- 15 January, 2010 06:38
- Comments
The ALRC has renewed its call for the government to introduce financial penalties for data breaches
The Australian Law Reform Commission (ALRC) has renewed its call for fines for failing to notify the privacy commissioner of data breaches after the UK introduced penalties of up to half a million pounds.
The ALRC initially made the call in its report: For Your Information: Australian Privacy Law and Practice released in 2008.
Authorities in the UK recently amended the Data Protection Act to allow the Information Commissioner to issue fines for data breaches of up to £500,000.
ALRC research manager Jonathan Dobison said the penalty method would be effective in the current information age, where there is an increasing number of ways information can be leaked through technology such as flash drives and laptops.
In February 2006, the Federal Government announced a major review of the Privacy Act 1988 would be undertaken by the ALRC that included how to deal with data loss situations.
In October, the Federal Government released its response to the ALRC's Privacy Act review and said the accepted recommendations will be implemented in two stages.
At the time, the government said draft legislation to implement the first stage changes will be available early this year for consultation
However, the data loss recommendations were not included in the first stage and it is not yet clear whether the government will force organisations to reveal if they have suffered a breach.
Dobison said even though the penalty approach might not stop data breaches, organisations will be more cautious about data protection.
“The idea of penalty is not only to punish but also to deter,” he said.
As part of the ALRC's data breach recommendation, the privacy commissioner only needs to be notified of a breach if there is a real risk, such as the leak of a name, address or another unique identifier.
Dobison added that notification to the privacy commissioner would not be required if the incident is not in the public interest.
There are few high-profile cases of Australian organisations having suffered a data breach in the public domain.
However, in the past few years there have been several notable cases in the UK and US where laws are more stringent and organisations are obliged to report breaches.
For instance, in late 2008 an unencrypted laptop with data on up to 600,000 people was stolen from a UK Ministry of Defence recruiting officer's car.
One infamous case was the loss of a CD with data on almost half of the UK's population - including dates of birth, addresses, bank accounts and national insurance numbers - in the post by HM Revenue & Customs.
And in October last year The Guardian newspaper was forced to notify 500,000 people that details they posted to the newspaper's employment site may be in the hands of hackers.
The Australian Federal Government has recently called in Symantec for consulting advice on the data breach notification laws aimed at notifying consumers when a business has lost or compromised data linked to them.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- <i>For Your Information: Australian Privacy Law and Practice</i>
- Federal Government releases response to Privacy Act recommendations
- UK Ministry of Defence in new data loss scandal
- Security experts savage UK gov't over data breach
- Guardian jobs site falls victim to 'sophisticated' hack
- Fed Govt calls in Symantec for advice on draft data notification breach laws
- Setting a strategy for secure mobile printing
- Optimizing Data Quality in the Enterprise - How to Tackle Your Bad Information
- Developing an Information Strategy - Strategize, Align, Govern, Execute, and Optimize
- Optimised Data Protection for VMware® Environments with Symantec NetBackup™ Appliances
- Oracle Business Process Analysis Suite
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Managing IBM License Complexity
IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on. -
Restore control, Reinforce security & Reduce Cost
Uncontrolled print environments and practices present a serious risk to the profit and security of your organisation. IT is under pressure to protect sensitive information, secure devices, and improve the way they manage the entire fleet. To gain better control, your organisation needs to implement plans that meet industry regulations while also increasing productivity, lowering costs, and providing users with more flexible imaging and printing solutions. Read more. -
CIO Executive Council ROI
This document was created by Council CIOs as a means to illustrate ROI for membership. It outlines the services available to member CIOs and their deputies.

















Comments
Post new comment