Preparing for mandatory data breach notification
- 26 June, 2013 10:28
With the Privacy Amendments (Privacy Alerts) Bill 2013 likely to become law following a standing committee report, now is a good time to start looking at security systems, says K&L Gates partner Cameron Abbott.
If passed, the bill will require government agencies and businesses to notify customers of serious data breaches in relation to personal, credit reporting, credit eligibility or tax file number information.
A Senate Standing Committee on Legal and Constitutional Affairs urged the Senate to pass the bill, stating that mandatory data breach notifications would benefit both Australian consumers and industry stakeholders.
Abbott told Computerworld Australia that the bill will force companies to prioritise security systems.
“Executives should be engaging with the IT department about their systems so the people that understand this bill and what’s at stake can communicate that to the people who are making cost benefit decisions on the degree of security,” he said.
“One of the practical ways to breach the divide between those who understand the legal risks and the people making the budget decisions is to create a privacy impact statement for these projects.”
According to Abbott, the bill will also affect cloud service providers as they will need to make some “serious commitments” about the security of the data they have been entrusted with.
“To date, there has been a tendency to accept the cloud providers terms and conditions which don’t promise much,” he said.
“Companies should also be looking at the serious ramifications of not getting their security right. If you have a data breach you are going to have to tell all of your customers that you’ve stuffed up and you can’t be trusted.”
Abbot said that this will crystallise brand value far faster than any other consequence that comes out of the legislation.
He added that mandatory reporting of serious data breaches will act as a far greater motivator for companies than fines.
“Sony was fined 250,000 pounds in the UK by the privacy officer following the PlayStation Network breach but it is rumoured to have spent over $150 million to rectify its security issues after the event,” Abbott said.
This article and the comments within it should not be construed as legal advice
Follow Hamish Barwick on Twitter: @HamishBarwick
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
Queensland government to provide 200 services online by 2015
CIOs need to get their house in order, CFO panel says
Is Data Complexity Blinding Your IT Decision-Making?
Why IT projects really fail
CIOs say cost, complexity impede true mobile gains in enterprise
At one point, it seemed that phishing was receding to the status of a minor issue threatening only naïve consumers. However new cybercriminals and phishing techniques have lead this to become a greater concern. Download how to find out how phishing became the No. 1 web threat, and which web security solution can best protect your company.
Pathways Course Curriculum 2014
Developed by the CIO Executive Council, Pathways is a unique, flexible, self-managed, self-paced 12-month professional development program that brings together best practices, thought leadership and business insights for today’s most promising ICT professionals. Pathways is designed and delivered by leading local and global CIOs; enabling participants to capitalise on mentor CIOs personal experiences, expertise and knowledge.
Is your data centre growing too complex for your backup?
Backing up data today is growing more complex - and in an era of virtualisation, big data and cloud deployments, it can be difficult to maintain control over your data, resulting in loss and downtime. This hour-long webcast features expert commentary on navigating the complexity of backing up a heavily virtualised infrastructure; simplifying your backup software and hardware ecosystem; reducing the cost of backing up your organisation’s data, and modernising your backup infrastructure with integration. The presentations will conclude with an interactive Q&A session.