“Privacy on the internet? That’s an oxymoron”
— Catherine Butler

Feedback sought
In its response to the Australian Competition and Consumer Commission’s (ACCC) Digital Platforms Inquiry, the Government committed to undertake a review of the Privacy Act and to consult on options for implementing a number of privacy-specific recommendations to better empower consumers, protect their data and best serve the Australian economy.
The digital economy has brought with it immense benefits including new, faster and better products and services.
The ability of businesses to engage with consumers online is vital to economic growth and prosperity. As Australians spend more of their time online, and new technologies emerge, such as artificial intelligence, more personal information about individuals is being captured and processed raising questions as to whether Australian privacy law is fit for purpose.
We are generally supportive of the intent and scope of the Privacy Act and we lodged our submission on 29 November 2020, focusing on the significant impact of reforms and the need to harmonise requirements before advisers, and advice businesses, are overcome by regulatory fatigue and the increased costs of compliance.
Download Review Terms
Our Thoughts
Financial planning businesses are predominantly SME businesses whose compliance and operational costs steadily increase, year on year, commensurate with regulatory changes. Unlike institutional or governmental entities, many SME businesses find that these increased compliance and operational costs are not merely disruptive and inconvenient, but, instead, profoundly threaten the sustainability of their businesses.
Our initial observations are as follows:
- Although not explicit, we believe that the intent of the Act is neither to reconcile individual rights against commercial and operational imperatives nor to limit privacy rights to consumers. Instead, the Act aspires to balancing principles and pragmatism to facilitate arrangements, founded on consent and security, for the free flow of information.
- In addition to asking that privacy rights not be narrowly defined as consumer rights, we would ask that the Attorney Generals’ Office appropriately the impact of consider of s2A, and related compliance obligations, on small to medium entities. Given the fiduciary-like obligations of financial advisers, and the statutory duties imposed on Australian Financial Services Licensees, we submit that any proposed reforms need to ensure that the compliance obligations can be afforded by small to medium businesses.
- While s6DA principally defines a ‘small business’ in financial terms (ie an annual turnover of less than $3,000,000), small financial planning businesses are often subjected to the act as a consequence of the information that are required to obtain or the services they provide (s 6D(4)(b)(c) and (d)). We understand the review is contemplating amending the financial threshold, and suggest that it is necessary to hold technology and other service providers to the same standard to avoid creating an advantage for non-legacy advice services.
- We strongly believe that the objectives of the Privacy Act need to align with, and reflect, relevant cyber security legislation. In our opinion, the two are intertwined and should not be separated. Creating an obligation to secure personal information, without harmonising and cyber-security laws undermines the intent, and operational efficacy, of the privacy laws.
- We note that, according to the Office of the Australian Information Commissioner (“OAIC”), the majority of privacy complaints received by the OAIC related to issues dealing with security of personal information (APP 11); use of disclosure of personal information (APP6) and access to personal information (APP12). In our view, the 2019-2020 Annual Report provides compelling arguments for the need to ensure that Privacy and Cyber laws work hand in hand.
- The Government recently released exposure drafts of its Security legislation Amendment (Critical Infrastructure) Bill 2020 (Draft Bill) and accompanying Intelligence Services Regulations 2020. The extent to which the proposed obligations in the Draft Bill overlap, or conflict with, the results of the Privacy Act review and subsequent proposed amendments, needs to be anticipated and carefully considered.
- In financial services, there is an obvious and irreconcilable tension between a consumer’s right to be anonymous (or use a pseudonym) and the statutory client identification and record keeping requirements. This ‘right’, unless excepted for financial services providers, creates liabilities and inconsistent duties that profoundly undermine their ability to comply with the financial services laws including s961B, s961D, s961G, s961H, s961J and s961L. In addition, a right of anonymity may also frustrate advisers’ compliance with Anti Money Laundering and Counter Terrorism financing legislative requirements.
ReadN OAIC Report
Read Security Report
- As observed by a submission made to the Senate Judiciary Committee in the United States, the “cost prohibitive” GDPR regime has strengthened the largest players (i.e. Google, Facebook and Amazon) and weakened small and medium firms. There are multiple reasons for these outcomes including risk aversion and reduced competition, but key contributing factors are the larger budgets to pay for software upgrades and privacy professionals.
- Few financial planning businesses are entirely digitised and the information they do hold is often held on disparate and incompatible systems. It is important to appreciate that SME do not necessarily have the resources, either financial, technical or human, to implement additional changes.
- In our experience, reliance on single-point consents or notices, are ineffective and, in practice, disadvantage consumers.
- These conclusions were recently validated by an extensive joint publication prepared by the Australian Securities and Investments Commission (ASIC) and the Dutch Authority for Financial Markets (AFM). Their REP 632 “Disclosure: Why it shouldn’t be the default” focused on disclosure and warnings and how ineffective they are. In some cases, it showed disclosures and warnings can backfire, contributing to consumer harm.
- Omri Ben-Shahar and Carl Schneider in their book “More than you want to know, The Failure of Mandated Disclosure”, suggest most people find disclosures complex, obscure and dull, suggesting even the most educated in law, were unable to understand half of what the disclosure documents say. This presumes that the disclosure documents are read, but the research suggests that reading documents is not the norm.
- In the “Rethinking Regulation” report prepared by the Productivity Commission in 2006, , they suggested that ‘Rather than drowning consumers with vast amounts of disclosure, a far better alternative would be to ensure that fundamental protections are built into the legislation itself”.
- This is, in our view, the real opportunity provided by this review.
Read Our Submission