NSW Privacy Commissioner investigates USB key auction
- 13 December, 2011 16:30
- Comments
The lost property auction of more than 50 USB keys by RailCorp in Sydney has prompted an investigation by the NSW Privacy Commissioner into possible breaches of privacy laws around the use and distribution of personal information.
The keys, which were acquired at the auction by security vendor Sophos, were all unencrypted with 33 of the keys containing malware. Tax deductions, photo albums and Web source codes were just some of the kinds of personal information Sophos found.
Deputy NSW Privacy Commissioner, John McAteer, told Computerworld Australia that a series of questions were sent to RailCorp on Friday, 9 December to ascertain what steps the organisation took before selling the USB keys.
McAteer’s main concern was that the organisation may have breached sections of NSW privacy laws by selling keys with personal information.
“The allegation is that some of that data is what you would call personal information," he said. "For example, a contract to build a tollway is not personal information even though it might be in commercial confidence, whereas a CV would be considered personal.”
He added that RailCorp sold a number of laptops at the same auction but wiped the data contained on the computers.
“Our starting point would be that maybe RailCorp need to review the selling of these keys and dispose of them in some other way,” he said.
“When you clean out an office and find things sometimes you throw them away because it’s safer.”
While McAteer’s investigation has the power of a royal commission and he can make findings and recommendations, the Privacy Commissioner cannot issue fines. However, individuals who believe their privacy has been breached could obtain damages from the Administrative Decisions Tribunal.
McAteer expected to move to the second stage of the investigation before 25 December.
Got a security tip-off? Contact Hamish Barwick at hamish_barwick at idg.com.au
Follow Hamish Barwick on Twitter: @HamishBarwick
Follow Computerworld Australia on Twitter: @ComputerworldAU
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- HP and Closed Circuit Print Security Podcast featuring Quorcirca
- Spear Phishing Attacks - Why they are successful and how to stop them
- Workshifting: How IT is Changing the Way Business is Done
- Best Practices for Secure Enterprise Content Mobility
- Information Security Policies, Standards and Procedure
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Apple aims iPads at High Schools
-
Managing IBM License Complexity
IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on. -
Revolutionizing Enterprise Storage Infrastructure with Enterprise Flash Technology
Businesses increasingly rely on datacenters to provide access to services, applications, and data. As demand rises and applications grow in complexity, datacenter infrastructure must provide tremendous capacity and rapid access to information in order to keep pace with business priorities. Read on. -
Seven Steps to Effective Data Governance
Creating a framework to ensure the confidentiality, quality, and integrity of data – the core meaning of data governance – is essential to meet both internal and external requirements, such as financial reporting, regulatory compliance, and privacy policies. At its best, data governance roots out risk – both business and compliance risk – by increasing oversight. This white paper provides seven steps for taking such an approach, concluding with a real world example, taking an incremental approach using a repeatable framework that is a practical, proven strategy that any size organization can implement to suit their immediate and long-term needs and budget.
-
Microsoft Office
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7








Comments
Post new comment