Data and Privacy: Are you prepared for the new laws commencing this week?
You will need to take extra care to safeguard the unauthorised access, loss or disclosure of personal information.
On 22 February 2018, the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) will take effect to introduce a new notifiable data breach scheme (NDB Scheme).
If you already have obligations under the Privacy Act 1988 (Cth) (Act) (including the Australian Privacy Principles (APPs)) to protect personal information, then the NDB Scheme will apply to you.
What are the new laws?
Under the NDB Scheme:
- if you experience a data breach that is likely to result in serious harm, you must notify the Australian Information Commissioner (Commissioner) and all affected individuals in relation to that data breach;
- if you suspect that you have experienced a data breach, you must quickly assess the situation to decide whether or not you have experienced a data breach that may require a notification;
- the Commissioner has wide powers to investigate compliance; and
- a failure to comply may result in fines of up to $2.1 million for corporations and $420,000 for other entities.
What should you do?
Generally, you need to ensure that you are complying with your existing obligations set out in the Act including by:
- ensuring that you obtain all necessary consents, and that you make all relevant notifications, as required by the APPs; and
- implementing personal information management systems, processes and procedures that comply with the requirements of the APPs.
Some specific tips that may assist you to comply with your obligations under the NDB Scheme include to:
- appoint a person (or team) to manage any incident response;
- document a data breach response plan, including guidelines for making a notification; and
- review your contractual arrangements where multiple parties handle personal information.
If you experience any data breach, or if you would like help to prepare compliance policies or any further information, please contact:
P: 9394 1045 | E: firstname.lastname@example.org
P: 9394 1043 | E: email@example.com
- Charity and Not-for-Profit Organisation
- Competition and Consumer Law
- Compliance and Corporate Governance
- Corporate and Commercial
- Dispute Resolution
- Elder Law
- Estate Planning
- Insolvency, Bankruptcy and Restructuring
- Intellectual Property
- Personal Property Securities Act
- Workplace Relations and Safety
Modern families are becoming more complex in their structure and dynamic. As a result, there has been a steady increase in estate litigation, in particular, claims against estates by family members seeking further provision. It is therefore important to review your estate plan to ensure these complexities are addressed and to ensure, where possible, the risk of litigation is mitigated.Read More
As lawyers who have prepared voluntary disclosures for clients as part of the ATO’s Project DO IT (Disclose Offshore Income Today) and for clients since that project ceased in 2014, there are lessons we have learned in relation to dealing with the tax implications of offshore income and entities.Read More