Navigating the Proposed Privacy Act Reforms: What AFS Licensees and Advisers Need to Know

Navigating the Proposed Privacy Act Reforms: What AFS Licensees and Advisers Need to Know

Navigating the Proposed Privacy Act Reforms: What AFS Licensees and Advisers Need to Know

Introduction

The Australian Government’s response to the Attorney-General’s Privacy Act Review Report signifies a major shift in privacy regulation. With 38 proposals agreed upon and 68 more accepted in principle, these changes will significantly affect AFS licensees and advisers. This article delves into these reforms, their implications, and what industry professionals should anticipate.

Background

On 28 September 2023, the Australian Government released its response to the Attorney-General’s Privacy Act Review Report after extensive public consultation. This review proposed 116 amendments to the Privacy Act 1988 (Cth) to align more closely with global privacy standards. The response details the proposals that have been accepted and those agreed upon in principle, with legislative amendments anticipated in 2024.

“Updating privacy policies and procedures is like upgrading the locks on your doors; it’s essential for protecting what you have.”

Key Agreed Reforms

The government’s commitment to enhancing privacy protections includes several critical areas of reform that AFS licensees and advisers must be prepared for:

  1. Security and Destruction of Personal Information The government plans to bolster the requirements for securing and destroying personal information by specifying that “reasonable steps” include both technical and organisational measures. The Office of the Australian Information Commissioner (OAIC), with input from the Australian Cyber Security Centre, will offer further guidance.
  2. Automated Decision-Making Privacy policies will need to specify the types of personal information utilised in automated decisions that significantly impact individuals’ rights, enhancing transparency and accountability in the use of AI and automated systems.
  3. Enforcement Enhancements The government will implement a tiered civil penalty system for privacy breaches, including mid-tier penalties for moderate breaches and low-level penalties for administrative errors. The courts will also gain expanded powers to issue a wider range of orders following a breach.
  4. APP Codes The Information Commissioner will be empowered to develop APP Codes for specific industries, ensuring appropriate privacy protections are in place when there is no suitable industry representative.

Agreed In-Principle Reforms

Several significant proposals have been agreed in principle, pending further consultation and impact analysis:

  1. Small Business Exemption Removal The removal of the small business exemption is being considered, which would extend privacy obligations to cover more groups.
  2. Employee Privacy Protections Extending privacy protections to private sector employees is under review to enhance the privacy rights of employee data.
  3. Consent Requirements The definition of consent may be updated to ensure it is voluntary, informed, current, specific, and unambiguous, requiring businesses to thoroughly review their consent mechanisms.
  4. Fair and Reasonable Data Practices Personal information must be collected, used, and disclosed in a fair and reasonable manner, irrespective of consent, setting a higher standard for privacy practices and requiring businesses to assess the fairness and reasonableness of their data handling procedures.

Impact on AFS Licensees and Advisers

The proposed reforms will have several specific implications for AFS licensees and advisers:

  1. Enhanced Compliance Requirements

    • Policy and Procedure Updates: Licensees will need to update privacy policies to comply with new requirements, including detailing the use of personal information in automated decisions. This may involve reviewing and overhauling existing documentation to meet the enhanced standards.
    • Data Handling and Destruction: Strengthened obligations for data security and destruction will necessitate AFS licensees to implement robust technical and organisational measures, including investments in cybersecurity infrastructure and secure disposal of personal information when no longer needed.
  2. Increased Regulatory Scrutiny

    • Higher Standards of Accountability: Expanded enforcement powers for the OAIC, including mid-tier and low-level penalties, will subject AFS licensees and advisers to greater scrutiny. Non-compliance could lead to significant financial penalties and reputational harm.
    • Audit and Monitoring: Enhanced investigative powers for the OAIC mean that licensees should prepare for more frequent and thorough audits. Regular internal reviews and compliance checks will be necessary to ensure adherence to new regulations.
  3. Operational Adjustments

    • Removal of Small Business Exemption: If the small business exemption is removed, businesses previously exempt from the Privacy Act will need to implement comprehensive privacy compliance programs, including appointing privacy officers, conducting privacy impact assessments, and establishing procedures for handling personal information.
    • Employee Data Privacy: Extending privacy protections to private sector employees will necessitate a review of how AFS licensees collect, use, and store employee data. This could involve updating employment contracts, staff training programs, and internal data handling policies.
  4. Employee Training and Awareness

    • Training Programs: Ensuring employees are aware of and comply with new privacy obligations will be essential. This includes training on updated consent requirements, handling personal information, and understanding the significance of fair and reasonable data practices.
    • Awareness Campaigns: Conducting regular awareness campaigns and updates on privacy policies and procedures will help maintain a culture of compliance within the organisation.
  5. Client Communication and Trust

    • Transparency with Clients: Clear communication regarding the use and protection of clients’ personal information is crucial. Updated privacy notices and regular updates on privacy practices can help build trust and demonstrate a commitment to data protection.
    • Handling Client Data: Licensees must ensure that the collection, use, and disclosure of client data are fair and reasonable, including obtaining clear and informed consent from clients and enabling them to access and correct their personal information.

Next Steps

The government plans to introduce legislative amendments in 2024, with further consultation to refine the agreed in-principle proposals. The OAIC has welcomed these reforms, emphasising their importance in strengthening Australia’s privacy framework.

According to Australian Information Commissioner and Privacy Commissioner Angelene Falk, “With the increasing use of high-impact technologies, it is critical that these reforms proceed as a priority alongside other key initiatives that rely on a strong privacy foundation, such as the Australian Cyber Security Strategy and Digital ID framework.”

Preparing for the Changes

AFS licensees and advisers should take proactive steps to prepare for the upcoming changes:

  1. Review and Update Privacy Policies

    • Ensure that privacy policies reflect the new requirements, particularly regarding automated decision-making and data destruction obligations.
  2. Implement Technical and Organisational Measures

    • Strengthen security measures to comply with the enhanced obligations and seek guidance from the OAIC as needed.
  3. Engage in Industry Consultation

    • Participate in ongoing consultations to provide feedback and stay informed about the final legislative amendments.
  4. Educate and Train Staff

    • Conduct training sessions for staff to understand and comply with the new privacy obligations.
  5. Monitor Regulatory Developments

    • Stay updated on further announcements and guidance from the OAIC and the government regarding implementing these reforms.

Conclusion

The government’s response to the Privacy Act Review Report represents a significant step toward modernising Australia’s privacy laws. For AFS licensees and advisers, these changes will necessitate a thorough review of existing practices and the implementation of new compliance measures. By staying informed and proactive, businesses can navigate these changes effectively and ensure they protect their clients’ and employees’ personal information.

As Commissioner Falk noted, “This is the most significant change to the Privacy Act in decades and will require organisations to ensure that their practices are fair and reasonable in the first place. This will assure the Australian community that, like a safety standard, privacy must be built into products and services from the start.”

For more information on the proposed reforms and how they may affect your business, refer to the government’s complete response and stay engaged with ongoing consultations to shape the future of privacy in Australia.

The Government’s response

The Australian Government’s response to the Privacy Act Review Report addresses various chapters comprehensively, agreeing to significant reforms. Below is a summary of the government responses concerning chapters 4, 6, 10, 11, 12, 13, 15, 17, 18, 21, 23 and 25:

Chapter 4: Personal Information, De-identification, and Sensitive Information

The government agrees in principle with several proposals to amend definitions and protections for personal and de-identified information:

  • Proposal 4.1: Amend the definition of personal information to clarify it includes technical and inferred information.
  • Proposal 4.2: Provide a non-exhaustive list of what constitutes personal information.
  • Proposal 4.3: Expand the definition of ‘collection’ to cover all methods and sources, including inferred information.
  • Proposal 4.4: Support the concept of ‘reasonably identifiable’ with a non-exhaustive list of circumstances.
  • Proposal 4.5: Define de-identification as a contextual process.
  • Proposal 4.7: Consult on introducing a criminal offence for malicious re-identification of de-identified information.
  • Proposal 4.9: Amend the definition of sensitive information to include genomic information and clarify it can be inferred from non-sensitive information.

Chapter 6: Small Business Exemption

The government agrees in-principle with proposals to remove the small business exemption:

  • Proposal 6.1: Remove the small business exemption after analysis and consultation.

Chapter 10: Privacy Policies and Collection Notices

The government agrees in principle to improve the clarity and accessibility of privacy policies and collection notices:

  • Proposal 10.1: Ensure privacy notices are clear, concise, and understandable.
  • Proposal 10.2: Include specific information about high-privacy risk activities and overseas disclosures in collection notices.
  • Proposal 10.3: Develop standardised templates for privacy policies and notices.

Chapter 11: Consent

The government agrees in principle with clarifying and improving consent requirements:

  • Proposal 11.1: Clarify that consent must be voluntary, informed, current, specific, and unambiguous.
  • Proposal 11.3: Recognise the ability of individuals to withdraw consent easily.

Chapter 12: Fair and Reasonable Handling of Personal Information

The government agrees in principle with proposals ensuring fair and reasonable handling of personal information:

  • Proposal 12.3: Require that personal information collection, use, and disclosure be fair and reasonable, irrespective of consent.

Chapter 13: High Privacy Risk Activities

The government agrees in principle with proposals addressing high privacy risk activities:

  • Proposal 13.1: Require Privacy Impact Assessments (PIAs) for high-risk activities and develop guidance on high-risk activities and the necessity of PIAs.
  • Proposal 13.3: Develop specific guidance on high-risk activities.

Chapter 15: Organisational Accountability

The government agrees in principle with enhancing organisational accountability:

  • Proposal 15.1: Require entities to determine and record the purposes for collecting, using, and disclosing personal information.
  • Proposal 15.2: Require entities to appoint a senior employee responsible for privacy.

Chapter 16 and 17: Additional Protections for Children and Vulnerable Individuals

The government agrees with enhancing privacy protections for children and vulnerable individuals:

  • Proposal 16.5: Introduce a Children’s Online Privacy Code.
  • Proposal 16.2: Define a child as an individual under 18.
  • Proposal 17.1: Introduce a non-exhaustive list of vulnerability indicators.

The government agrees in-principle to:

  • Proposal 17.3: Clarify issues and options to ensure that financial institutions can act appropriately in the interests of vulnerable clients.

Chapter 21: Security and Destruction of Personal Information

The government agrees with proposals aimed at strengthening security and data destruction obligations:

  • Proposal 21.3 and 21.5: Enhance obligations for securing and destroying personal information, including guidance on ‘reasonable steps’ from the OAIC.

Chapter 23: Overseas data flows

The government agrees in principle with proposals aimed at facilitating cross-border data flows and ensuring adequate protections:

  • Proposal 23.3: Develop standard contractual clauses for overseas data transfers.
  • Proposal 23.4: Strengthen consent requirements for overseas disclosures.

Chapter 25: Enforcement

The government agrees to strengthen enforcement mechanisms:

  • Proposal 25.1: Create tiers of civil penalty provisions for better regulatory responses.
  • Proposal 25.2: Amend the Act to clarify what constitutes a serious interference with privacy.
  • Proposal 25.3: Apply Regulatory Powers (Standard Provisions) Act powers to investigations of civil penalty provisions.
  • Proposal 25.4: Grant the Information Commissioner the power to undertake public inquiries.
  • Proposal 25.5: Require entities to mitigate and redress foreseeable loss from privacy breaches.
  • Proposal 25.6: Empower the Federal Court to make any order deemed fit in civil penalty proceedings.
  • Proposal 25.7: Investigate the feasibility of an industry funding model for the OAIC.
  • Proposal 25.8: Consider establishing a contingency litigation fund and an enforcement particular account.
  • Proposal 25.9: Increase transparency in annual reporting requirements.
  • Proposal 25.10: Conduct a strategic review of the OAIC’s structure to enhance enforcement focus.
  • Proposal 25.11: Give the Information Commissioner discretion not to investigate complaints already handled by an external dispute resolution scheme.

 

This article was modified and republished by Money Management

Keep exploring

Navigating the Proposed Privacy Act Reforms: What AFS Licensees and Advisers Need to Know

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?