In the past few months, we’ve had a number of clients grappling, struggling or failing to deal with Mandatory Data breaches.
The obligation to identify and report breaches might be scary, but most licensees already have Incident and breach management policies that can accomodate these obligations. Most licensees (with a few exceptions) can identify, escalate and report breaches of the financial services laws.
These obligations aren’t new. As you know, if you were previously subject to the Privacy Act, you’ve had, since 22 February 2018, a legal obligation to record, manage and report ‘eligible data breaches’.
The Privacy Act applies to private sector organisations, including not-for-profits, with annual (group) turnover of more than $3 million. It also includes small businesses that may be earning $3 million or less where they are health service providers involved in trading in personal information, contractors that provide services under a Commonwealth contract or credit reporting bodies, amongst others.
Your obligation to report
It’s important to understand that you are not obliged to report to the OIAC all breaches, but you are required to report all eligible data breaches. It’s an important qualification to understand.
First, an eligible data breach occurs if:
(a) there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by you; and
(b) the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates; and
(c) you haven’t been able to prevent the likely risk of serious harm with remedial action.
Second, it’s critically important to appreciate that all ‘eligible data breaches’ – likely to result in serious harm – need to be reported as soon as practicable to both to the OAIC and to those individuals (potentially) affected by a data breach.
While you may think ‘eligible data breaches’ are the province of Russian Hackers, the reality is that even simple, everyday errors can trigger the obligation. For example, an eligible data breach can occur if you mistakenly provide a client’s personal information to the wrong person.
Responsiveness provides rewards
If you’re a business that quickly identifies and remediates incidents, you’ll be pleased to know that the threshold conditions for mandatory breach reporting provide you with a degree of flexibility:
- First, an assessment of serious harm requires an objective and reasonable assessment made from your perspective. It does not require you to make a subjective assessment of the likely harm based on the affected individual’s relevant personal circumstances. Act reasonably and prudently but appreciate the broader implications of the breach and your reaction.
- Second, You don’t need to report data breaches that you’ve quickly remediated or have started to remediate. We’ve addressed effective remediation previously and we remind you that effective remediation needs to be reasonable, prompt, effective and appropriate. Your remediation and consequence management policy should provide you with the framework and guidance you need to satisfy this requirement but contact us if you need assistance.
“Serious harm”? Seriously?
The requirement to consider the impact and likely consequences of a data breach – serious harm – introduce a materiality assessment that’s both clear and intuitive. Advisers, and advice businesses, routinely collect, retain and use personal information from their clients. So it’s not hard to identify the information that, if lost or released, could cause serious harm. For simplicity consider
- taxation information such as returns or TFN;
- Credit reporting data;
- Personally identifiable information.
- ‘sensitive information’, such as information about an individual’s health
- documents commonly used for identity fraud (including Medicare card, driver licence, and passport details)
- financial information
- a combination of types of personal information (rather than a single piece of personal information) that allows more to be known about the individuals the information is about.
The key is CPD
It’s important to understand these obligations (particularly given the possible penalties) but it’s more important to ensure your staff are adequately trained.
We offer a “Privacy Fundamentals” Workshop, mapped against FASEA’s requirements for Regulatory Compliance, that addresses these requirements in a practical, commercial and detailed way.
Our full training catalogue is also available to you.