Latest Comments
"I urge every business person and IT person, management or staff, to get hold of a copy of "I.T. ..."
by John Franks | Sep 6, 2008 1:20 AM
 
"iam intrested in porn movies workes in actors from 36/m india pleas help me thanks."
by vinod agarwal | Sep 5, 2008 8:26 PM
 
"test for intresting"
by cocoboy | Sep 5, 2008 5:39 PM
 
"It's great that Google have recognised that security needs to be an important consideration with ..."
by Lloyd Borrett | Sep 5, 2008 11:53 AM
 
""Google arrived on the browser scene with the launch of Chrome"... Seems a bit misplaced to ..."
by Jeme | Sep 5, 2008 12:33 AM

Data breach disclosure, new guidelines to help Australian businesses

  • Email a Friend
  • Print Page
Data breach disclosure, new guidelines to help Australian businesses
By Negar Salek
Feb 14, 2008 6:00 AM
Tags: "data | breach" | "privacy | commissioner" | "data | law" | "data | disclosure | law"
The guide, a response to growing public sentiment surrounding the subject, will provide best practices and advice surrounding voluntary data breach disclosure.

“[The guide] is actually in response to requests, particularly from Commonwealth agencies but also from the private sector,” said Andrew Hayne, acting director of Policy at the OPC in his keynote speech at the SecurityPoint 2008 conference in Sydney today.

“It will explain when they should tell us about a notification and when they should go to the expense and trouble of telling consumers.”

The Australian Law Reform Commission (ALRC) is yet to announce its rulings regarding the Privacy Commissioner, Karen Curtis’s December 2007 submission urging a review of the Privacy Act.

Early indicators suggest that at the very least mandatory disclosure laws will soon be a reality in Australia, to what extent is a concern for Hayne.

“The ALRC has supported the idea of data breach notification requirement, however, in our Office’s view, it’s the detail of how such a requirement should neither impose an unreasonable burden on agencies and organisations nor result in unnecessary or alarmist notfications to individuals,” he said.

According to Hayne, a requirement to notify significant data breaches would also encourage organisations and agencies to take adequate steps in the first place to ensure information is secure.

Australian and ACT government agencies are compelled by the Privacy Act as well as those in the private sector with a turnover exceeding $3 million.

All health services, credit providers and Tax file number recipients are also obliged. SMBs are conditional.

These draft guidelines will be available for consultation in the near future.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Legal Whitepapers