Piper Alderman
Contact Us
05/12/2017
The incoming mandatory breach obligations that are soon taking effect, and outline the steps that you can take to prepare for these changes now.
Snapshot of new obligations
A mandatory data breach notification regime under the new Privacy Amendment (Notifiable Data Breaches) Act 2017 will come into force from 22 February 2018, under which various entities will be required to assess data breaches and notify individuals and the Commissioner of any such breaches in certain circumstances.
Who will be affected?
Any entity which is currently, or will be, subject to the Privacy Act 1998 will be required to comply with these notification obligations. This broadly includes entities which:
What do the new obligations relate to?
The new obligations focus on the steps that a relevant entity is required to take in respect of an ‘eligible data breach’.
Broadly, there is an ‘eligible data breach’ where there is unauthorised access to, unauthorised disclosure of, or loss of, information held, where such access, disclosure or loss is likely to result in ‘serious harm’ to any of the individuals to whom the information relates.
‘Serious harm’ may include serious physical, psychological, or emotional harm, in addition to economic, reputational and financial harm.
When assessing whether a data breach is likely to result in ‘serious harm’, consideration should be given to:
What to do if you suspect a breach
If you suspect that there is an eligible data breach but do not have reasonable grounds to believe there has in fact been a breach, the first step to take is to assess the suspected breach. This involves carrying out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that there has in fact been an eligible data breach, and taking all reasonable steps to complete the assessment within 30 days of suspecting a breach.
What to do if you become aware of a breach
Notify the Commissioner
If there are reasonable grounds to believe that there has been an eligible data breach, then you must, as soon as practicable, provide a statement to the Commissioner setting out:
If there are reasonable grounds to believe that the eligible data breach was also an eligible data breach of another entity, the Notification Statement may also set out the identity and contact details of the other entity.
If the Commissioner is aware that there are reasonable grounds to believe that there has been an eligible data breach, then the Commissioner has the power to direct that a Notification Statement be prepared.
Notify individuals
After providing a Notification Statement to the Commissioner, you must also notify the individuals or the public in one of three ways, as soon as practicable:
You may notify individuals in the first two options by using the normal method of communication for those individuals, including by email. If there is no normal method of communication, then notification can be made by post.
What are the exceptions to notification?
There are a number of exceptions to the notification obligations which apply in certain circumstances. Broadly, these include:
What you should do to prepare for these notification obligations
Given the impending commencement of these notification obligations, consideration should be given to taking steps now to review your internal systems and prepare for these changes. The steps that you should be taking now include:
Seek assistance from the experts
Most entities do not have the specific skills, knowledge, experience or expertise to put in place appropriate cyber security measures and protections on their own. It is therefore crucial to engage cyber security experts who are skilled and experienced to assist in managing and reducing the impact of cyber security risks, both from a legal and an IT security perspective.
Legal experts who specialise in cyber security can assist by working with IT security experts to raise awareness and educate the board, assist organisations to understand their legal, regulatory and contractual obligations, prepare a cyber security action plan, establish good corporate governance procedures, prepare appropriate policies, provide training, and review contracts and insurance policies to ensure you are ready for these new changes.