ALRC renews data loss financial penalty call
- 15 January, 2010 06:38
- Comments
The ALRC has renewed its call for the government to introduce financial penalties for data breaches
The Australian Law Reform Commission (ALRC) has renewed its call for fines for failing to notify the privacy commissioner of data breaches after the UK introduced penalties of up to half a million pounds.
The ALRC initially made the call in its report: For Your Information: Australian Privacy Law and Practice released in 2008.
Authorities in the UK recently amended the Data Protection Act to allow the Information Commissioner to issue fines for data breaches of up to £500,000.
ALRC research manager Jonathan Dobison said the penalty method would be effective in the current information age, where there is an increasing number of ways information can be leaked through technology such as flash drives and laptops.
In February 2006, the Federal Government announced a major review of the Privacy Act 1988 would be undertaken by the ALRC that included how to deal with data loss situations.
In October, the Federal Government released its response to the ALRC's Privacy Act review and said the accepted recommendations will be implemented in two stages.
At the time, the government said draft legislation to implement the first stage changes will be available early this year for consultation
However, the data loss recommendations were not included in the first stage and it is not yet clear whether the government will force organisations to reveal if they have suffered a breach.
Dobison said even though the penalty approach might not stop data breaches, organisations will be more cautious about data protection.
“The idea of penalty is not only to punish but also to deter,” he said.
As part of the ALRC's data breach recommendation, the privacy commissioner only needs to be notified of a breach if there is a real risk, such as the leak of a name, address or another unique identifier.
Dobison added that notification to the privacy commissioner would not be required if the incident is not in the public interest.
There are few high-profile cases of Australian organisations having suffered a data breach in the public domain.
However, in the past few years there have been several notable cases in the UK and US where laws are more stringent and organisations are obliged to report breaches.
For instance, in late 2008 an unencrypted laptop with data on up to 600,000 people was stolen from a UK Ministry of Defence recruiting officer's car.
One infamous case was the loss of a CD with data on almost half of the UK's population - including dates of birth, addresses, bank accounts and national insurance numbers - in the post by HM Revenue & Customs.
And in October last year The Guardian newspaper was forced to notify 500,000 people that details they posted to the newspaper's employment site may be in the hands of hackers.
The Australian Federal Government has recently called in Symantec for consulting advice on the data breach notification laws aimed at notifying consumers when a business has lost or compromised data linked to them.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- <i>For Your Information: Australian Privacy Law and Practice</i>
- Federal Government releases response to Privacy Act recommendations
- UK Ministry of Defence in new data loss scandal
- Security experts savage UK gov't over data breach
- Guardian jobs site falls victim to 'sophisticated' hack
- Fed Govt calls in Symantec for advice on draft data notification breach laws
- Oracle Business Intelligence and Data Warehousing From Storage to Scorecard
- The Pathways ICT Leadership Development Program | Turning today’s ICT professionals into tomorrow’s business leaders | 2012 Course Curriculum
- Better Insights and Alignment with Business Intelligence and Scorecards
- Transforming Software Delivery: An IBM Rational Case Study
- Sanmina-SCI | Webcast
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Office 2007 for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies












Comments
Post new comment