“The government, in effect, declared privacy privatised.” Ken Auletta
Under Australian financial services laws, Australian Financial Services (AFS) Licensees and financial advisers face stringent compliance obligations regarding the collection, use, and protection of Personal Information. Failure to comply can result in significant penalties of up to $2.22 million. Building client trust through responsible data practices is crucial in this industry. Participants need to understand the scope and application of the Australian Privacy Principles.
What is Personal Information?
In financial services, Personal Information refers to any information or opinion, whether true or not, that can reasonably identify an individual client. This includes names, contact information, financial data, tax file numbers, investment preferences, risk profiles and more. Sensitive information like health records is subject to even tighter controls. This definition might be narrower than it first appears. In a 2017 case, the Federal Court emphasised that the information itself must point to an individual and that merely having the potential to cross-reference other data to identify an individual does not automatically make the initial data “personal information.”
Defining Personal Information: Insights from the Telstra Case
The Telstra case provides crucial guidance on the nuanced definition of Personal Information under the Privacy Act. The Federal Court ruled that for information to be considered personal, there must be a reasonable likelihood of an individual being identified from that data. Merely having the potential to cross-reference other datasets does not automatically make the original data “personal.”
This clarification has significant implications for AFS Licensees. This means that they must assess whether the information they hold, on its own, can reasonably identify clients. Metadata like IP addresses or device information may not necessarily constitute Personal Information if it cannot directly point to an individual’s identity without combining it with other data sources.
However, the court also acknowledged that the capacity for data to identify individuals is context-dependent. Information that may seem innocuous could become identifiable when combined with other data points or environmental factors. AFS Licensees should adopt a cautious approach, treating any information that could potentially identify clients as Personal Information, even if it requires cross-referencing.
Collection, Use, and Disclosure
AFS Licensees cannot simply collect and use client Personal Information as they wish. The Australian Privacy Principles stipulate that information can only be processed on legitimate grounds:
- For the primary purpose, it was collected
- For permitted secondary purposes, if the client consented or would reasonably expect their information to be used for related purposes
There are limits to repurposing sensitive data like health records for secondary reasons that are not directly related to the original purpose of collection.
Credit information is separately regulated under the Privacy Act. Credit providers like banks can only collect, use and disclose this type of Personal Information in specified circumstances outlined in credit reporting policies.
Purpose Limitations Aside from the original reasons it was obtained, Personal Information can generally only be used or disclosed for related secondary purposes that clients would reasonably expect or have consented to.
Direct marketing has its own set of guidelines. There must be an easy opt-out mechanism, and the information can only be used with prior consent or if it is impracticable to obtain consent.
Navigating Purpose Limitations and Secondary Use While Personal Information can generally only be used for the original purpose it was collected, the Privacy Act allows for specific secondary uses without explicit consent. These include situations where the client would reasonably expect the information to be used for a related purpose or if the secondary use is directly related to the primary purpose (for sensitive information).
For example, an AFS Licensee collecting client data for investment advice could use that information for related purposes like portfolio management or tax planning services, as clients likely expect this overlap. However, using the same data for unrelated marketing would require explicit consent.
Conversely, sensitive health information collected for insurance purposes could only be used for directly related activities like underwriting or claims processing, not for broader financial planning purposes.
AFS Licensees should document intended primary and secondary purposes, seek consent where required, and establish robust data governance frameworks to ensure compliance.
Limited Exceptions and Best Practices The Privacy Act outlines limited exceptions allowing the use or disclosure of Personal Information without the usual grounds, such as legal requirements, public health and safety reasons, or specific law enforcement activities. However, these exceptions should be applied judiciously and with proper documentation by AFS Licensees.
Some examples of permitted exceptions include:
- Legal Requirements: AFS Licensees may use or disclose Personal Information if required or authorised by Australian law or a court/tribunal order. This could include complying with subpoenas, warrants, or other legally binding notices.
- Public Health and Safety: Personal Information can be used or disclosed if there is a serious threat to public health or public safety, and the use or disclosure is necessary to prevent or lessen that threat. For instance, client information may need to be shared with health authorities during a pandemic for contact tracing purposes.
- Law Enforcement and Corruption: Certain disclosures are permitted to law enforcement bodies for specific enforcement-related activities, such as investigating unlawful activity or locating missing persons.
- Emergencies and Aid: AFS Licensees can share relevant Personal Information to provide aid or services during an emergency or disaster.
While these exceptions exist, AFS Licensees should exercise caution and ensure they have robust processes for documenting and justifying any reliance on these exceptions. Proper legal advice should be sought in ambiguous cases.
Furthermore, the exceptions should be narrowly interpreted and applied only when strictly necessary – they do not provide a blanket exemption from Privacy Act requirements. Client trust and privacy expectations must still be carefully weighed against purported exceptions.
A key take-out is that responsible AFS Licensees should implement comprehensive data protection programs with robust access controls, encryption, secure storage and disposal methods, and detailed audit trails to ensure compliance. Regular privacy impact assessments, staff training, and robust incident response plans are also crucial.
Clear policies and procedures should outline the specific circumstances where exceptions may apply, the approval processes required, documentation standards, and any additional safeguards or limitations on use and disclosure. Senior management oversight and accountability are essential.
By proactively addressing privacy risks and implementing rigorous governance frameworks, AFS Licensees can uphold their legal obligations while maintaining client trust and confidence in their data practices.
Transparency Requirements
At or before collecting Personal Information from clients, AFS Licensees must provide detailed notification about their data practices. This includes reasons for collection, any third parties to whom the data may be disclosed, complaint handling processes, whether the data could be transferred overseas, and how clients can access/correct their records.
Maintaining Data Quality
Financial services compliance requires licensees to take reasonable steps to ensure client Personal Information remains accurate, up-to-date, complete and relevant. They should only collect the minimum necessary data for their lawful functions.
What is considered “reasonable” or “minimum necessary” depends on factors like the sensitivity of the information, the potential for client harm if data is inaccurate, and practical considerations.
Robust Data Security Controls
To prevent misuse or data breaches, AFS Licensees must implement robust cybersecurity controls aligned with best practice standards from the Australian Cyber Security Centre. Staff should receive comprehensive training.
Alignment with Industry Standards
While the Privacy Act is a core focus, AFS Licensees should also align with relevant industry standards and frameworks, such as the APRA Prudential Standard CPS 234 on information security, the Essential Eight mitigation strategies from the Australian Cyber Security Centre, and ISO 27001 on information security management systems.
Moreover, the increasing convergence of data protection, cybersecurity, and corporate governance obligations necessitates a holistic approach encompassing legal, technical, and operational safeguards.
What the Courts said
In Australia, the Privacy Act 1988 (Cth) is a crucial piece of legislation that regulates the handling of personal information by organisations, including those in the financial services sector. Australian Financial Services (AFS) licensees and advisers must comply with the Australian Privacy Principles (APPs) under this Act.
While few high-profile court cases are solely centred on the Privacy Act’s application to financial services, several cases and legal principles are highly relevant for AFS licensees and advisers.
Here are a few important considerations:
Australian Privacy Commissioner v Telstra Corporation Limited [2017] FCAFC 4:
Although not directly related to financial services, this decision by the Federal Court is significant for all entities covered by the Privacy Act. The case clarified the definition of “personal information” under the Privacy Act. The court held that for information to be considered personal information, there must be a reasonable likelihood of the individual being identified from that information. In this landmark decision, the Federal Court examined whether specific metadata held by Telstra, such as IP addresses and mobile network data related to communications, constituted “personal information” as defined by the Privacy Act.
The court ruled that for information to be considered “personal information,” there must be a connection or link between the data and an individual whose identity can reasonably be ascertained from that data. The court emphasised that the information itself must point to an individual, and merely having the potential to cross-reference other data to identify an individual does not automatically make the initial data “personal information.” This decision has significant implications for how organisations, including AFS licensees and advisers, handle and interpret data under the Privacy Act, particularly concerning data that might not explicitly identify an individual but could be used in conjunction with other data to do so.
This ruling helps clarify the scope of personal information and underscores the importance of assessing whether data can reasonably identify an individual in specific contexts. For AFS licensees and advisers, this ruling emphasises the need to assess and manage the data they collect carefully and hold, ensuring that any information that reasonably identifies an individual is protected according to the Privacy Act’s requirements. This includes implementing adequate security measures to prevent unauthorised access to or disclosure of personal information.
Giller v Procopets [2008] VSCA 236:
This case, while primarily a Victorian case about breach of confidence and privacy in the context of a domestic relationship, has implications for privacy breaches more broadly. It highlights the potential for damages to be awarded for distress caused by privacy breaches, an area of concern for AFS licensees who handle sensitive financial information.
This case resulted in a significant legal outcome where the court awarded damages for breach of confidence and distress caused by the privacy breaches. The plaintiff, Ms. Giller, was awarded both compensatory and exemplary damages. The damages awarded included compensation for the distress suffered due to violating privacy and confidence. AFS licensees and advisers should note that mishandling personal information or failing to maintain confidentiality can lead to significant legal and financial repercussions. This case serves as a reminder to maintain strict confidentiality protocols, particularly when handling sensitive financial information.
Duffy v Google Inc [2015] SASC 170:
This South Australian Supreme Court case is notable for recognising internet search engines as publishers of defamatory content that they did not create but failed to remove upon notification. For AFS licensees, this case reminds them of the importance of monitoring and managing the information they publish or disseminate, including online. In this case, the South Australian Supreme Court found Google liable as a secondary publisher of defamatory content. Dr Duffy was awarded AUD 100,000 in damages.
The court’s decision underscored the responsibilities of internet platforms regarding content that they did not initially create but failed to remove upon notification. For AFS licensees and advisers, it highlights the importance of monitoring and managing the information they publish or disseminate, primarily online. Ensuring that all public communications are accurate and do not mislead or harm others is crucial to maintaining compliance and protecting the organisation’s reputation.
Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496.
This case is indeed highly relevant for AFS licensees and advisers, particularly concerning the obligations related to cybersecurity and data protection. In this Federal Court case, the Australian Securities and Investments Commission (ASIC) pursued RI Advice Group, an entity providing financial services, alleging that it failed to have adequate risk management systems to manage its cybersecurity risks. This was significant as it was one of the first cases where a financial services licensee was held accountable for breaches of obligations to act efficiently and fairly, partly due to failures in managing cybersecurity risks.
The court found that RI Advice had breached its obligations under the Corporations Act by failing to have adequate risk management systems in place. In this case, the Federal Court found RI Advice Group in breach of its obligations under the Corporations Act due to inadequate cybersecurity measures. The court ordered RI Advice Group to pay a penalty of $750,000 and engage an independent expert to review and implement effective risk management systems. The decision emphasised the financial and operational consequences of failing to maintain adequate cybersecurity practices.
This case highlights the increasing importance of cybersecurity within the governance frameworks of financial services providers and the potential legal and regulatory consequences of failing to secure client data and systems adequately. The Federal Court’s finding that RI Advice Group failed to have adequate risk management systems for cybersecurity highlights the necessity for AFS licensees to implement and maintain strong cybersecurity measures. This includes regular reviews and updates of cybersecurity policies, employee training on security practices, and proactive risk management strategies to effectively protect client data and systems.
Compliance is an Ongoing Process Privacy compliance for financial advisers, and AFS Licensees is not a set-and-forget obligation.
You should regularly review and update data practices, policies and procedures to account for changes in:
- The types of Personal Information they are collecting
- The reasons and methods for collection
- How the information flows internally and externally
- Introduction of new systems, processes or technologies
- Staff education and security awareness needs
- Regulatory updates to financial services laws
AFS Licensees should carefully analyse these obligations and the implications of the relevant cases. For instance, the Telstra case underscores the need for a contextual and risk-based approach to data classification and protection. These cases highlight the reputational and financial consequences of data breaches, while the Google case reminds licensees of their responsibilities as information publishers. End-to-end governance over the data lifecycle is critical for protecting client privacy and avoiding costly breaches.
In this context, senior management must drive and be accountable for sustaining a culture of privacy awareness.
AFS licensees and advisers should ensure they are familiar with these cases and the principles they establish, as they highlight the importance of managing personal information responsibly, the potential legal liabilities for privacy breaches, and the broader implications of data management practices. Additionally, staying updated with rulings from the Office of the Australian Information Commissioner (OAIC) and relevant court decisions is crucial for maintaining compliance with privacy obligations under the law.
By proactively addressing privacy risks and implementing rigorous governance frameworks, AFS Licensees can uphold their legal obligations while maintaining client trust and confidence in their data practices. To ensure your firm is fully compliant and has robust data protection measures, schedule a consultation with Assured Support’s team of experienced AFSL compliance consultants. Our experts can thoroughly review your policies, procedures, and systems, providing tailored recommendations and support to strengthen your privacy practices and mitigate risks effectively. Protect your business and safeguard client data – contact us today to take the first step towards a comprehensive compliance framework.
A modified version of this article was published by FS Advice.