South Australian Democrats Senator, Natasha Stott Despoja, today introduced a private Bill to parliament seeking the introduction of laws which force businesses to notify consumers of a data security breach involving their personal information.
Labelling existing privacy laws as deficient, Senator Stott Despoja introduced the Bill seeking immediate amendments to the Privacy Act.
Even if the Bill is rejected and doesn't gain the numbers on both sides of politics necessary to support the amendments, the introduction of data disclosure laws in Australia may still go ahead as early as 2008.
Data disclosure laws have attracted wide-ranging support since a review of the Privacy Act began early this year by the Australian Law Reform Commission (ALRC).
The ALRC is releasing a discussion paper next month recommending the introduction of security breach disclosure laws in Australia with the final report to be delivered to the federal Attorney General, Philip Ruddock in March, 2008.
The recommendation also has the support of the Federal Privacy Commissioner, Karen Curtis, who believes Australia should be following the lead of the United States.
"I think its good business to notify customers [of a breach] although I don't think notification is appopriate in all circumstances, it really depends on the level of damage created," she told Computerworld.
Only this week Gartner's vice president of research, Rich Mogull, said legislative protection in Australia is critical.
Mogull said the introduction of disclosure laws in the US have been the biggest single driver in improving the IT security landscape.
He said 40 states in the US now have data breach disclosure laws.
Introducing the private senators Bill to parliament, Senator Stott Despoja, said research shows that more than two-thirds of Australian organizations experience six losses of sensitive data each year.
She said a report from the IT Policy Compliance Group found these breaches reportedly include customer, financial, corporate employee and IT security data which is stolen, leaked or inappropriately destroyed.
"These reports of data security breaches and losses of personal information have coincided with an increase in identity theft, which has implications for affected persons' finances, harassment by debt collectors, credit denials and law enforcement scrutiny for crimes committed by another individual," Senator Stott Despoja said.
"At the same time, there has been an increase in the number of proposals to rationalise, centralise and streamline many government services and databases, the purchase of Australian companies by offshore private equity funds and a series of business mergers and acquisitions which will make it easier for large-scale data breaches.
"There is a need for this legislation to protect Australians and their personal information.
"The incidence and severity of identity theft can be ameliorated through greater awareness and pre-warning when personal information is obtained by or disclosed to, an unauthorised party," she said.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Taking On Demand CRM Integration to the Next Level
Best Practice in Building an Integrated Information Management Strategy
Achieving the impossible: Unlimited application scalability
Strategies for Eliminating .PST Files
The state of Middleware
Email Archiving 101—Customer Case Study
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
Email Archiving Implementation: Five Costly Mistakes to Avoid
Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.












