Have you won the privacy trifecta?

Have you won the privacy trifecta?

Winner, Winner.

  • Are you a business operator with an annual turnover of more than $3 million?
  • Have you experienced a data breach?
  • Do you provide advice and services to clients in the European Union?

If you answered “Yes” or “Hell, Yeah”, congratulations, you’ve won the great Privacy trifecta!

Before you celebrate, let’s unpack the elements.

If you are a business operator with an annual turnover of more than $3 million, you will be classified as an APP entity and will be required to comply with the Australian Privacy Principles APPs. If you’re an adviser (or small licensee) breathing a sigh of relief, hold off until you investigate whether you’ve opted into the regime or have been conscripted by virtue of your licensee or the information that collect, access, share and retain.

In addition, if you are an APP entity, and you somehow improperly use, share or release information, you’ve experienced a data breach (i.e. you have emailed a customers’ details to the wrong customer) and you may need to lodge a Notifiable Data Breach Form with the Office of the Australian Information Commissioner (OAIC).

Lastly, if you are an Australian business of any size and you have an establishment in the European Union (EU), or offer goods and services in the EU, or if you have clients in the EU, you may need to comply with the General Data Protection Regulations. 

If you have never heard of Australian Privacy Principles; Notifiable Data Breach Schemes, or General Data Protection Regulation, please read on.

If the thought of reading on makes you break out in compliance hives, enrol in training or contact us instead. 


The Australian Privacy Principles

Taking each element in turn, the APPs are there to help protect the individual privacy of your clients and require you to implement policies and procedures with regards to the collection, use, disclosure, storage and disposal of ‘personal information’  as well as obligations relating to access and correction; credit reporting and providing a complaints mechanism.  The Office of the Information Commissioner suggests you can achieve compliance by implementing 4 simple steps :

Embed a culture of privacy that enables compliance

  • Create a culture that values personal information 
  • Treat personal information as a valuable business asset to be respected, managed and protected and outline how personal information is important for your business 
  • Appoint key roles and responsibilities for privacy management and ensure a senior person has overall accountability and appoint a staff member responsible for handling internal and external privacy enquiries, complaints, and access and correction requests
  • Adopt a privacy by design approach in all your business projects and decisions that involve personal information 
  • Develop and implement a privacy management plan that aligns your business processes wit your privacy obligations 
  • Implement reporting mechanisms that ensure senior management are routinely informed about privacy issues 
  • Ensure employees understand the privacy obligations

Establish robust and effective privacy processes 

  • Keep information about your personal information holdings (including the type of information you hold and where it is held) up to date including information held offshore or that is in the physical possession of a third party
  • Develop processes to ensure you are handling personal information in accordance with your privacy obligations
  • Promote privacy awareness via induction and regular staff training programs 
  • Develop and implement a clearly expressed and up to date privacy policy
  • Implement risk management processes that allow you to identify, assess and manage privacy risks 
  • Establish processes to response to privacy enquiries and complaints 
  • Establish processes that allow individuals to promptly and easily access and correct their personal information 
  • Develop a data breach response plan 

Evaluate your privacy processes to ensure continued effectiveness 

  • Monitor and review your privacy processes regularly 
  • Document your compliant with your privacy obligations 
  • Measure your performance against your privacy management plan

Enhance your response to privacy issues 

  • Consider adopting good privacy practices that go beyond the requirements of the APPs where appropriate 
  • Keep informed of issues and developments in privacy laws and changing legal obligations 
  • Monitor and address new security risks and threats 
  • Introduce initiatives that promote good privacy standards in your business practices 
  • Participate in Privacy Awareness Week 

If despite our previous warning, you have in fact read on and have now broken out in compliance hives, or are interested in exploring or developing your knowledge, or uplifting your risk framework. Contact us, or you might like to join us for Privacy Week and enrol in one of our Privacy courses


Notifiable Data Breach Scheme

If you are an APP entity and you have reasonable grounds to believe an eligible data breach has occurred, then you must promptly notify any individual at risk of serious harm and you may need to  lodge a notifiable data breach form with the Office of the Australian and Information Commissioner. 

We’ve recently addressed this topic, so rather than repeat content, we thought we would highlight some interesting statistics from the Privacy Commissioner’s 12 month insights report:

  • Twelve months to 31 March a total of 964 breach notifications were lodged 
  • 712% increase in breaches since the previous 12-month period  
  • 60% malicious or criminal attacks
  • 153 attributed to phishing 
  • 35% attributable to human error of which 41% related to the finance sector 

Download NDB Insight Report

If you need to update your risk framework and related policies and procedures, or if you think you may be dealing with a Notifiable Data Breach, we are here to help!


General Data Protection Regulation (brought to you by the EU)

The GDPR is a regulation in European Law on data protection in the European Union and the European Economic Area which applied from 25 May 2018. It addresses the transfer of personal data outside the EU. The GDPR primarily gives control to individuals over their personal data.

The GDPR applies to the data processing activities of businesses, regardless of size, that are data processors or controllers with an establishment in the EU. Generally speaking, a controller says how and why personal data is processed and a processor acts on behalf of the controller.

Practically an Australian business may be covered by the GDPR because:

  • They have an office in the EU
  • Their website targets EU customers
  • They offer goods and services to individuals in the EU
  • They track individuals in the EU on the internet and uses data processing techniques to profile individuals to analyse and predict personal preferences, behaviours and attitudes 

While the GDPR and Privacy Act 1988 share many common requirements, there are some notable differences.

To whom does it apply?

Data processing activities of businesses, regardless of size, that are data processors or controllers:

  • With an establishment in the EU
  • Outside of the EU, that offer goods or services to individuals in the EU or monitor the behaviour of individuals in the EU (EU: Art 3) 

To what does it apply?

Personal data – any information relating to an identified or identifiable natural person (EU: Art 4(1))

Accountability and governance

Controllers generally must:

  • Implement appropriate technical and organisational measures to demonstrate GDPR compliance and build in privacy by default and design (Arts 5,24,25) 
  • Undertake compulsory data protection impact assessments 
  • Appoint data protection officers 

Consent

Consent must be:

  • Freely given, specific and informed
  • An unambiguous indication of the data subject’s wishes which, by a statement or by a clear affirmative action, signifies agreement to processing 

Data breach notifications

Mandatory DBNs by controllers and processors (exceptions apply)

Individual rights

Include:

  • Right to erasure (Art 17)
  • Right to data portability (Art 20) 
  • Right to object (Art 21) 

If you are you caught by the GDPR you need to ensure you have evaluated your information handling practices and governance structures.

Keep exploring

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?