Computerworld
Draft guidelines issued for mandatory reporting of data breaches
Privacy Act full of 'loopholes'
Sandra Rossi  15 April, 2008 12:58

The Australian Privacy Commissioner, Karen Curtis, is seeking feedback from the businesses community in response to the release of a draft Voluntary Information Security Breach Notification Guide today.

Currently there are no specific requirements under the Privacy Act for organisations to notify individuals of an information security breach.

However, a proposal to make notification of information security breaches mandatory is being considered by the Australian Law Reform Commission (ALRC) as part of a national privacy review.

"The development of a voluntary guide offers a timely opportunity for stakeholders to comment on this important issue and we look forward to hearing their views," Curtis said.

The draft Guide draws upon voluntary guidelines developed by the Privacy Commissioners of Canada and New Zealand and public submissions close on June 16, 2008. Details at www.privacy.gov.au.

While agencies and organisations are required to safeguard data, Curtis said breaches still occur and information can go missing.

"Not all breaches result from malicious, intentional behaviour such as computer hacking for example - they can occur because of human error, from a failure to follow established protocols, or from information going missing," she said.

"Recognising that this is the current reality of the modern information handling environment, the Guide aims not only to assist agencies and organisations to minimise the possibility of a breach occurring, but also to prepare for and respond effectively to any breaches when they do occur."

The Australian Democrats welcomed the guidelines to regulate the reporting of data breaches with privacy spokesperson Senator Natasha Stott Despoja warning this stop-gap measure should not delay a permanent legislative solution.

"While voluntary guidelines may provide some useful guidance for prudent organisations, I am concerned that the voluntary and non-binding nature of the guide will mean that data security breaches will continue to fall through the cracks," Stott Despoja said.

"I am also concerned that under the guidelines, a decision on whether or not to notify a customer of a data breach will reside with the organisation involved in that breach."

In 2007, the Senator introduced a Private Bill to parliament to amend the Privacy Act and introduce mandatory reporting.

"In order to give individuals more control over their personal information and to satisfy public expectations Parliament must legislate; organisations must advise individuals when their personal information has been compromised," she said.

Stott Despoja said notification requirements would lessen the impact of identity theft and facilitate greater awareness of data security breach issues and improve security practices.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about ACT, Bill

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Speeding business innovation with Data Centre Transformation solutions

Data centre transformation helps your organization shift spending from maintenance and management to focus on projects that support business growth and innovation while significantly reducing operating costs. Read more now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.