<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Peter A Clarke</title>
	<atom:link href="http://www.peteraclarke.com.au/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.peteraclarke.com.au</link>
	<description></description>
	<lastBuildDate>Fri, 17 May 2013 00:41:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>The problems with de anonymisation of data as a privacy protection</title>
		<link>http://www.peteraclarke.com.au/2013/05/16/the-problems-with-de-anonymisation-of-data-as-a-privacy-protection/</link>
		<comments>http://www.peteraclarke.com.au/2013/05/16/the-problems-with-de-anonymisation-of-data-as-a-privacy-protection/#comments</comments>
		<pubDate>Thu, 16 May 2013 07:00:41 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Articles]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3271</guid>
		<description><![CDATA[In the UK the Open Rights Group (ORG) has  called for new EU data protection laws, currently being worked on by EU law makers, to require consent to anonymised data sharing. The ORG made the recommendation after it raised concerns with the practice of anonymisation. The genesis of the concern relates to the attempted sale [...]]]></description>
			<content:encoded><![CDATA[<div style="text-align: justify;">
<div>
<p>In the UK the Open Rights Group (ORG) has  <a href="http://www.openrightsgroup.org/blog/2013/ee-and-sale-of-user-data-does-anonymisation-work">called </a>for new EU data protection laws, currently being worked on by EU law makers, to require consent to anonymised data sharing. The ORG made the recommendation after it raised concerns with the practice of anonymisation. The genesis of the concern relates to the attempted sale of anonymised data by a mobile operator to the Metropolitan Police. See <a href="http://www.bbc.co.uk/news/technology-22510792">EE defends user-data selling scheme following police interest</a> which provides:</p>
<p>&nbsp;</p>
<p><span style="color: #ff0000;">Mobile operator EE has defended plans to sell its data, after a newspaper reported personal information was being offered to the Metropolitan Police.</span></p>
<p><span style="color: #ff0000;">Research company Ipsos Mori has an exclusive deal to sell on EE&#8217;s data, and has held talks with the force, <a href="http://www.thesundaytimes.co.uk/sto/news/uk_news/National/article1258476.ece"><span style="color: #ff0000;">according to the Sunday Times</span></a>.</span></p>
<p><span style="color: #ff0000;">EE told the BBC the article was &#8220;misleading to say the least&#8221;.</span></p>
<p><span style="color: #ff0000;">The company said <span id="more-3271"></span>Ipsos Mori had access only to anonymised data grouped in samples of 50 people or more.</span></p>
<p><span style="color: #ff0000;">&#8220;We would never breach the trust our customers place in us and we always act to comply fully with the Data Protection Act,&#8221; a statement from EE said.</span></p>
<p><span style="color: #ff0000;">&#8220;The information is anonymised and aggregated, and cannot be used to identify the personal information of individual customers.&#8221;</span></p>
<p><span style="color: #ff0000;">The newspaper&#8217;s report said information about 27 million of EE&#8217;s customers was on offer &#8211; including their gender, age, postcode, the websites they visited, the time of day they sent texts and their location when making calls.</span></p>
<p><span style="color: #ff0000;">The Met Police confirmed to the BBC that they had held an &#8220;initial meeting&#8221; with Ipsos Mori to discuss how the data could be used to tackle crime, but added it &#8220;has made no offer to purchase data from Ipsos Mori nor has any intention of doing so&#8221;.</span></p>
<p><span style="color: #ff0000;">The force would not comment on whether it had made similar enquiries with other mobile operators.</span></p>
<p><span style="color: #ff0000;">In response to the story, Ipsos Mori &#8211; which is yet to fully finalise the terms of the deal with EE &#8211; told the BBC the data set was &#8220;not about individuals &#8211; it&#8217;s about behaviour&#8221;.</span></p>
<p><span style="color: #ff0000;"><a href="http://www.ipsos-mori.com/newsevents/latestnews/1390/Ipsos-MORI-response-to-the-Sunday-Times.aspx"><span style="color: #ff0000;">On its website</span></a>, the research company outlined what powers it had:</span></p>
<ul>
<li><span style="color: #ff0000;">We can see the volume of people who have visited a website domain, but we cannot see the detail of individual visits, nor what information is entered on that domain</span></li>
<li><span style="color: #ff0000;">We only ever report on aggregated groups of 50 or more customers</span></li>
<li><span style="color: #ff0000;">Ipsos Mori only receives anonymised data without any personally identifiable information on an individual customer</span></li>
<li><span style="color: #ff0000;">We do not have access to any names, personal address information, nor postcodes or phone numbers</span></li>
</ul>
<p><span style="color: #ff0000;">Monetisation of mobile-data intelligence is a major new revenue source for operators.</span><span style="color: #ff0000;">Clues about a user&#8217;s location, and what they are interested in, are a potential goldmine for retailers looking to offer targeted advertising.</span></p>
<p><span style="color: #ff0000;">Other networks such as Vodafone and O2 also offer businesses the chance to capitalise on the personal information it holds on its customers.</span></p>
<p><span style="color: #ff0000;">&#8220;Aggregated, anonymised data based on analytics such as footfall and outdoor media tracking can enable an organisation to make informed decisions,&#8221; said Vodafone in <a href="http://enterprise.vodafone.com/insight_news/2013-05-10-unleashing-powerful-insights-with-mobile-analytics.jsp"><span style="color: #ff0000;">a recent press release about services it offers</span></a>.</span></p>
<p><span style="color: #ff0000;">Likewise, O2 offers &#8220;analytical insights&#8221; to retailers through parent company Telefonica, whose digital insights team &#8211; set up last year &#8211; promises &#8220;a digital headcount to help them understand the movement of crowds&#8221;.</span></p>
<div><span style="color: #ff0000;"> Telefonica hopes that selling analysis of customer data will provide valuable extra income</span></div>
<p><span style="color: #ff0000;">&#8220;Retailers are quite good at measuring footfall inside their stores,&#8221; the company said.</span></p>
<p><span style="color: #ff0000;">&#8220;But this data will tell them where people go once they are outside, as well as their age and gender.&#8221;</span></p>
<p><span style="color: #ff0000;">Such schemes have attracted the concern of privacy rights campaigners &#8211; particularly at a time when debate over what access the government should have to private data is under scrutiny.</span></p>
<p><span style="color: #ff0000;">Last week, proposals for the Communications Data Bill &#8211; referred to by some as the Snoopers&#8217; Charter &#8211; <a href="http://www.bbc.co.uk/news/uk-politics-22449209"><span style="color: #ff0000;">was left out of the Queen&#8217;s Speech</span></a>.</span></p>
<p><span style="color: #ff0000;">The bill called for greater powers to investigate crime in cyberspace &#8211; but was opposed by the Lib Dems who said the measures went too far.</span></p>
<p><span style="color: #ff0000;">On news the Met Police was in contact with Ipsos Mori about mobile data, one privacy group told the BBC it was &#8220;alarmed&#8221;.</span></p>
<p><span style="color: #ff0000;">&#8220;There is no point in the government announcing that they don&#8217;t want a Snoopers&#8217; Charter only to get a privatised one by the back door,&#8221; said Loz Kaye from the Pirate Party UK.</span></p>
<p><span style="color: #ff0000;">&#8220;Companies must start to realise that it is against their interests to treat their customers this way. Otherwise we just end up being commodities in a 21st Century data gold rush.&#8221;</span></p>
<p>The Data Protection Act requires that organisations  ensure that personal data is processed fairly and lawfully and  only collected for &#8220;one or more specified and lawful purposes and  not further processed in any manner incompatible with those purposes. The issue is whether data protection law applies to personal data that has been anonymised, and in the UK that it does not.</p>
<p>The UK&#8217;s Information Commissioner has issued a <a href="http://www.ico.org.uk/~/media/documents/library/Data_Protection/Practical_application/anonymisation_code.ashx">code of practice </a>(Anonymiation: managing data protection risk code of practice) which provide that data anonymisation techniques do not have to provide a 100% guarantee to individuals&#8217; privacy in order for it to be lawful for organisations to disclose the information. Anonymised personal data can be disclosed even if there is a &#8220;remote&#8221; chance that the data can be matched with other information and lead to individuals being identified, it said.  The Canadian Privacy Commissioner in <a href="http://www.ipc.on.ca/images/Resources/anonymization.pdf">Dispelling the Myths Surrounding De-identification: Anonymization Remains a Strong Tool for Protecting Privacy</a>, released in June 2011, argues that the issue of re identification is overblown and the concern is unnecessary. I think it is unduly optimistic.</p>
<p>The re identification of data is not a theoretical possibility.  It is an actuality.  The use of algorithms and other statistical and scientific means to de anonymise data has been the subject of significant research such as <a href="http://www.cs.utexas.edu/~shmat/shmat_oak09.pdf">De-anonymizing Social Networks,</a> <a href="http://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf">Robust De-anonymization of Large Sparse Datasets</a>, <a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2076397">The &#8216;Re-Identification&#8217; of Governor William Weld&#8217;s Medical Information: A Critical Re-Examination of Health Data Identification Risks and Privacy Protections, Then and Now</a> and  <a href="http://digital.law.washington.edu/dspace-law/bitstream/handle/1773.1/417/vol5_no1_art3.pdf">De identified data and third party data mining; the risk of re identification of personal information</a>.  I discussed this issue at my presentation &#8220;Managing Identify on Line&#8221; at <a href="http://web.mit.edu/comm-forum/mit8/subs/abstracts.html">MIT 8</a>.</p>
<p>There is too much faith placed in de identification of data as a definitive means of privacy protection.  Even an effective one.  Technology, in particular the use of advanced algorithms, are rendering this technique problematical.  Privacy watchdogs seem to want to steer a pragmatic, business friendly path through this issue.  The problem is that technology has showed up the UK Information Commissioner&#8217;s code of practice to be flawed as far as it relates to de anonymisation.</p>
<p>&nbsp;</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/05/16/the-problems-with-de-anonymisation-of-data-as-a-privacy-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Commissioner speech on amendments to the Privacy Act</title>
		<link>http://www.peteraclarke.com.au/2013/05/10/privacy-commissioner-speech/</link>
		<comments>http://www.peteraclarke.com.au/2013/05/10/privacy-commissioner-speech/#comments</comments>
		<pubDate>Thu, 09 May 2013 17:19:02 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[Commonwealth Privacy Commissioner]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3261</guid>
		<description><![CDATA[The Privacy Commissioner has published the speech he gave last week. It can be found here. Below is a slightly edited transcript.  It relevantly provides: Privacy law reform—Get in on the Act &#8230;&#8230;&#8230;&#8230;.. Privacy law reform It should be no surprise that privacy law reform is a priority for business. It is fair to say [...]]]></description>
			<content:encoded><![CDATA[<p>The Privacy Commissioner has published the speech he gave last week. It can be found here.</p>
<p>Below is a slightly edited transcript.  It relevantly provides:</p>
<div id="w">
<div id="head_wrapper">
<div id="content_wrapper">
<div id="content_container">
<div id="main">
<h1 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Privacy law reform—Get in on the Act</span></h1>
<p style="padding-left: 30px;"><span style="color: #ff0000;">&#8230;&#8230;&#8230;&#8230;..</span></p>
<h2 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Privacy law reform</span></h2>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">It should be no surprise that privacy law reform is a priority for business. It is fair to say that the <cite><a href="http://www.austlii.edu.au/au/legis/cth/num_act/pappa2012466/"><span style="color: #ff0000;">Privacy Amendment (Enhancing Privacy Protection) Act 2012</span></a></cite> will bring about the most significant changes in privacy regulation and compliance for over two decades.  </span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">In the time I have with you today, I will set out some of the key changes to the Privacy Act. In particular, I will talk about the new Australian Privacy Principles (or APPs) and the enhanced powers that will be available to me to resolve investigations. I also want to let you know how we will assist you prepare for the changes.</span></p>
<h2 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The APPs</span></h2>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Thirteen new APPs will apply to<span id="more-3261"></span> both Commonwealth agencies and private sector organisations, or ‘APP entities’ as both will be referred to in the amended Act. These principles will replace the existing Information Privacy Principles (or IPPs) and National Privacy Principles (or NPPs) that apply to government agencies and businesses respectively.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The APPs are structured to more closely reflect the information lifecycle — from ensuring transparency in information collection, through to use and disclosure, quality and security, access and correction.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">To make the most of out time today, I am going to focus on the APPs that have some key changes and will be most relevant in your role as privacy professionals.</span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 1—Open and transparent management of personal information</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 1 seeks to ensure that agencies manage personal information in an open and transparent way and take a proactive approach to informing individuals about how their personal information will be handled.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">To that end APP 1 requires organisations to have a clearly expressed and up-to-date privacy policy outlining the way they handle personal information.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Of course, the requirement to have a privacy policy is not new. However, APP 1 expands on the existing requirements in NPP 5 by identifying the minimum information that must be contained in an APP privacy policy.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">While these changes will require you to review your privacy policy, there is no denying that greater openness and transparency can only improve customer service and build trust with your customers.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Evidence continues to suggest that few people read privacy policies. And here lies our shared challenge. We need to develop privacy policies that not only create greater transparency, but that also engage, and I commend organisations that are starting to meet this challenge (McAfee’s Privacy Ninja).</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Under APP 1 organisations must also take such steps as are reasonable to implement practices, procedures and systems to ensure compliance with the APPs or a registered APP code that binds the entity. Those practices, procedures and systems must also enable entities to deal with inquiries or complaints from individuals.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">What is considered ‘reasonable in the circumstances’ will always depend on the specific circumstances. However, some things your organisation could do to fulfil your obligations under APP 1 include:</span></p>
<blockquote>
<ul style="text-align: justify; padding-left: 30px;">
<li><span style="color: #ff0000;">training staff about the organisation’s policies and practices</span></li>
<li><span style="color: #ff0000;">establishing procedures to receive and respond to privacy complaints and inquiries, and to identify and manage privacy risks and compliance issues.</span></li>
</ul>
</blockquote>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 1 is a bedrock principle for all APP entities — by complying with this APP you will be establishing a culture and set of processes for your workplace that will assist you in complying with all the other APPs, right from the start.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Aside from this being a legal requirement, it should not be difficult to build a business case for this principle. The adage that prevention is better than the cure rings true, and is more compelling than the case for data breach insurance in my mind.</span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 7—Direct marketing</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The use and disclosure of personal information for direct marketing is now addressed in a privacy principle (rather than as an exception in NPP 2). This principle has created some concern and will be one we will spend some time consulting on and addressing in our detailed APP guidelines.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Generally, organisations may only use or disclose personal information for direct marketing purposes where the individual has either consented to their personal information being used for direct marketing, or has a reasonable expectation that their personal information will be used for this purpose, and conditions relating to opt-out mechanisms are met.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">A welcome reform is the clarification that APP 7 will be displaced where another Act specifically provides for a particular type of direct marketing, such as the Spam Act. But, APP 7 will still apply to organisations involved in direct marketing relating to electronic messages and other activities not covered by such instruments.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">We have heard the concerns about this APP. However, it is important to understand that direct marketing continues to be an area of increasing community concern, particularly in the online environment.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">In privacy research conducted by the University of Queensland last year, 56 per cent of respondents disapproved of having advertising targeted to them based on their personal information.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">There is also evidence that with the growing prevalence of tracking and aggregation, consumers are choosing not to use services due to privacy concerns.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Compliance with APP 7, including the requirement to provide a ‘simple means’ by which the individual can request not to receive any marketing, not only allows individuals to exercise choice, it potentially prevents loss of business. Customers care that you care about how you handle their personal information. They also care that you listen to how they want you to use their personal information.</span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 8—Cross-border disclosure of personal information</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 8 is an important new principle on the cross-border disclosure of personal information to an overseas recipient, replacing NPP 9. APP 8 requires an entity to take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information, subject to limited exceptions.  </span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 8 and the related s 16C create a framework under which a disclosing entity remains accountable for the subsequent handling of that personal information by the overseas recipient. In some circumstances, the disclosing entity will be liable for an act or practice of the overseas recipient that would breach the APPs.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">As I mentioned, this is subject to limited exception. One exception is when the organisation expressly informs the individual that if they consent to the disclosure overseas then the organisation will not be required to take reasonable steps to ensure that the overseas recipient does not breach the APPs, and the organisation will not remain accountable for what happens to that information.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Like direct marketing, the disclosure of personal information overseas remains a concern for much of the public and APP 8 reflects this concern.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">I understand that being held accountable for the mishandling of personal information by your overseas contractor is a concern. However, I imagine the cost of an overseas data breach (including the costs of remediation, loss of reputation and customer trust and, potentially, customers) is equally concerning. This APP is a compelling business case for you to protect your business when you are planning to send personal information overseas.   </span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 11—Security of personal information</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">APP 11 relates to an entity’s obligation to protect the personal information it holds. While the obligations largely remain the same as those under IPP 4 and NPP 4 there are some differences to note.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Under APP 11, an entity must take reasonable steps to protect personal information it holds from misuse, <strong>interference</strong> and loss, and from unauthorised access, modification or disclosure.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The inclusion of ‘interference’ is new and may require additional measures to be taken to protect against computer attacks and other interferences of this nature, but the requirement is conditional on steps being ‘reasonable in the circumstances’.</span><br />
<span style="color: #ff0000;"> APP 11 also sets out that an entity has obligations to destroy or de-identify personal information in certain circumstances.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">To assist organisations understand their information security requirements this week the Federal Attorney-General launched the <abbr title="Office of the Australian Information Commissioner">OAIC</abbr>’s new <em><a href="http://www.oaic.gov.au/publications/guidelines.html#other_privacy_guidance"><span style="color: #ff0000;">Guide to information security</span></a></em> at the <abbr title="Office of the Australian Information Commissioner">OAIC</abbr>’s business breakfast to launch PAW. The Guide clarifies what ‘reasonable steps’ should be taken under the Privacy Act. The guide isn’t binding but does send a clear message about my expectations in this area, so naturally we intend to refer to the guide when assessing compliance with the data security obligations in the Privacy Act.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">What I am seeing in the hacking related data breaches, both here and overseas, are cases of organisations that have not taken reasonable steps to protect the personal information they hold. Reasonable steps include regularly updating their security systems.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Compliance with the security requirements under Privacy Act will not only minimise the risk of the costs of a data breach as I have previously outlined, but potentially the loss of valuable customer information to your competitors.</span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Commissioner’s new powers</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Let’s now look at the Commissioner’s new powers.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">From March 2014 I will be able to conduct Performance Assessments of private sector organisations to determine whether they are handling personal information in accordance with the new APPs, the new credit reporting provisions and other rules and codes.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The power will consolidate the existing discretion to conduct audits of Australian Government Agencies, tax file number recipients, credit reporting agencies, credit providers and extend it to include organisations.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">These assessments may be conducted at any time, whether the organisation has had a previous Privacy breach or not. So I will be putting businesses on notice that they need to have their systems and processes in place to be ready at all times for a Performance Assessment.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">I also have enhanced code making powers that will allow me to approve and register enforceable codes which are developed by entities, on their own initiative or on request from the Commissioner, or by the Commissioner directly.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">From the first day of operation, the privacy reforms will provide me with enforcement powers and remedies in regards to own motion investigations – those that commence as a result of my own initiative rather than as a result of a complaint from an individual.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">I will be able to make a determination (as I can already with a complaint lodged by an individual), accept written undertakings that will be enforceable through the courts, or apply for civil penalty orders of up to $340,000 for individuals and up to $1.7 million for companies.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">I will not be taking a softly softly approach.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Let’s remember that the public sector have been working with the Act for nearly 25 years and the private sector for over 12 years, so these concepts are not new. Fundamentally the most of the principles remain the same.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Most of the requirements are not new requirements and in my view should already be happening so I will not shy away from taking action where it is appropriate to do so.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">However, before you get too excited, I would note that since I became Privacy Commissioner in mid-2010, I have been telling business and government that my focus will always be on resolving the majority of complaints via conciliation.</span></p>
<h3 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">How we will help</span></h3>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">I would now like to outline  the resources our office is developing for you to use in your work.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Our office has a role to educate all organisations and agencies, as well as the community more generally, about the changes that are coming. We are doing this on a very limited budget, having received no additional funding from Government, so it is encouraging to see that a number of you are already producing and disseminating helpful guidance on these important changes.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">There is guidance to assist agencies and businesses already available. To date, we have published:</span></p>
<blockquote>
<ul style="text-align: justify; padding-left: 30px;">
<li><span style="color: #ff0000;">a <a href="http://www.oaic.gov.au/privacy-portal/resources_privacy/Privacy_law_reform.html"><span style="color: #ff0000;">privacy law reform page on the <abbr title="Office of the Australian Information Commissioner">OAIC</abbr> website</span></a> to keep you up to date with privacy reform developments</span></li>
<li><span style="color: #ff0000;">a <a href="http://www.oaic.gov.au/publications/business_resources/privacy_business_resource2_privacy_act_reforms_checklist.html"><span style="color: #ff0000;">checklist</span></a> that sets out action you can take now to comply with the reforms</span></li>
<li><span style="color: #ff0000;"><a href="http://www.oaic.gov.au/publications/privacy_fact_sheets/Privacy-factsheet17_Australian_privacy_principles.pdf"><span style="color: #ff0000;">Fact Sheet 17</span></a> which sets out the APPs</span></li>
<li><span style="color: #ff0000;"><a href="http://www.oaic.gov.au/news-and-events/privacy-awareness-week-2013/resources/index.html"><span style="color: #ff0000;">posters, a quick references tool and training slides</span></a> to help you and your employees familiarise yourselves with the new APPs</span></li>
<li><span style="color: #ff0000;">a <a href="http://www.oaic.gov.au/news/consultations.html#code_guide"><span style="color: #ff0000;">consultation draft of guidelines for developing APP codes</span></a>.</span></li>
<li><span style="color: #ff0000;">All of these materials are available on the <a href="http://www.oaic.gov.au/index.html"><span style="color: #ff0000;"><abbr title="Office of the Australian Information Commissioner">OAIC</abbr> website</span></a>, and some are available here today. We acknowledge that the key guidance is yet to come and this will be start with the release of the Guidelines on the APPs for consultation in the next few months.</span></li>
</ul>
</blockquote>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">We will be conducting targeted public consultation processes to assist us in developing this guidance. I would encourage you to contribute to these consultations, so we can arrive at guidance that is practical and meets the needs of business.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">To keep across the latest guidance and other materials, if you haven’t already, I encourage you to sign up with the <a href="http://www.oaic.gov.au/news/networks/index.html#PCN"><span style="color: #ff0000;">Privacy Connections Network</span></a>, our network for private sector privacy professionals.</span></p>
<h2 style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Conclusion</span></h2>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">It is an exciting time to be working in the privacy field — the large scale of these reforms present interesting challenges and opportunities for all of us.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Be assured I will have the concerns of business in mind when administering the reformed Privacy Act. I will, though, always balance these concerns against the rights of individuals to control how their personal information is handled. These individuals value their personal information and they choose where they spend their money.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The business case is simply that good privacy practice is good business practice.</span></p>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/05/10/privacy-commissioner-speech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New York Times poll on camera surveillance after Boston Bombing</title>
		<link>http://www.peteraclarke.com.au/2013/05/04/new-york-times-poll-on-camera-surveillance-after-boston-bombing/</link>
		<comments>http://www.peteraclarke.com.au/2013/05/04/new-york-times-poll-on-camera-surveillance-after-boston-bombing/#comments</comments>
		<pubDate>Sat, 04 May 2013 10:12:21 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3256</guid>
		<description><![CDATA[The effect on Boston of the terrorist bombing has been profound.  I am currently in Boston at a conference at the MIT.  It dominates the news, it permeates discussions.  And it seems to be effecting American&#8217;s views on street surveillance.  The New York Times in Poll Finds Strong Acceptance for Public Surveillance  highlights a willingness [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The effect on Boston of the terrorist bombing has been profound.  I am currently in Boston at a conference at the MIT.  It dominates the news, it permeates discussions.  And it seems to be effecting American&#8217;s views on street surveillance.  The New York Times in P<a href="http://www.nytimes.com/2013/05/01/us/poll-finds-strong-acceptance-for-public-surveillance.html?_r=0&amp;adxnnl=1&amp;pagewanted=all&amp;adxnnlx=1367658027-soPJ87rsfdL6uxzw1Z23/Q">oll Finds Strong Acceptance for Public Surveillance </a> highlights a willingness of the public to allow for greater surveillance <span id="more-3256"></span>and reduce their privacy as a trade off.  The poll is found <a href="http://www.nytimes.com/interactive/2013/05/01/us/01poll-terror.html?ref=us">here</a>.</p>
<p style="text-align: justify;">The article provides:</p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">WASHINGTON — Americans overwhelmingly favor installing video surveillance cameras in public places, judging the infringement on their privacy as an acceptable trade-off for greater security from terrorist attacks, according to the latest New York Times/CBS News Poll.</span></p>
<div style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;"> A week after the <a title="More articles about the Boston Marathon." href="http://topics.nytimes.com/top/reference/timestopics/subjects/b/boston_marathon/index.html?inline=nyt-classifier"><span style="color: #ff0000;">Boston Marathon</span></a> attack, which was unraveled after the release of video footage of the two suspects flushed them out of hiding, 78 percent of people said surveillance cameras were a good idea, the poll found.</span></div>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">The receptiveness to cameras on street corners reflects a public that regards terrorism as a fact of life in the United States — 9 out of 10 people polled said Americans would always have to live with the risk — but also a threat that many believe the government can combat effectively through rigorous law enforcement and proper regulation.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">For all that confidence, there are lingering questions about the role of the nation’s intelligence agencies before the attacks, with people divided about whether they had collected information that could have prevented them (41 percent said they had; 45 percent said they had not).</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">The murkiness of the case — the Tsarnaev brothers’ ties to the Caucasus; the warnings from Russian intelligence about potential extremist sympathies — has clearly left an impression on the public. A majority, 53 percent, said the suspects had links to a larger terrorist group, while 32 percent said they had acted alone.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">President Obama, in a White House news conference on Tuesday, defended the performance of the Federal Bureau of Investigation and the Department of Homeland Security, saying the agencies had done their job, while acknowledging, “This is hard stuff.”</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">The poll suggested that Americans are willing to tolerate further tough measures to foil future attacks. Sixty-six percent said information about how to make explosives should not be allowed on the Internet, where it would be available to aspiring terrorists, even if some would view that as a form of censorship. Thirty percent said it should be permitted in the interest of free expression.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">More broadly, only 20 percent of people said they believed the government had gone too far in restricting civil liberties in the fight against terrorism, while 26 percent said it had not gone far enough and 49 percent said the balance was about right. In 2011, the share of those worried about losing civil liberties (25 percent) was larger than that favoring more intrusive government approach (17 percent).</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">“I know some people are paranoid about the government intruding on their privacy,” Judith Richards, a retired teacher from New Paltz, N.Y., said in a follow-up interview. “But with all the horrible things that have been happening, I think you have to trust this as a way to protect our well-being.”</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Jennifer Lopez, 26, a saleswoman in Pembroke Pines, Fla., said: “There are cameras in stores and supermarkets. Our families would be safer and surveillance cameras would provide evidence to help agencies pursue people, like they just did in Boston.”</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">The nationwide poll of 965 adults was conducted on landlines and cellular phones from April 24 to April 28, five days after the manhunt for the surviving suspect in the Boston bombings, Dzhokhar Tsarnaev, ended with his capture in a backyard in Watertown, Mass. It has a margin of sampling error of plus or minus three percentage points.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Polls taken in the aftermath of terrorist attacks often show spikes in the public’s fears of another attack. In a CBS News poll a year ago, just 10 percent of people said another attack in the United States in the next few months was “very likely,” while 27 percent said it was “somewhat likely.” In the most recent survey, 24 percent said it was very likely and 42 percent somewhat likely.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">There is also evidence that fears about immigrants have increased modestly. Forty-nine percent said the risk of terrorism had risen in the United States because of legal <a title="More articles about immigration." href="http://topics.nytimes.com/top/reference/timestopics/subjects/i/immigration_and_refugees/index.html?inline=nyt-classifier"><span style="color: #ff0000;">immigration</span></a>. The last time that question was asked, in 2007, the percentage was 42 percent.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Still, other responses were unchanged since the Boston bombings: Twenty-three percent said they were very concerned about a terrorist attack in the area in which they live, about the same as said so in 2010. Fifty-six percent said they approved of Mr. Obama’s handling of terrorism, essentially unchanged from a CBS News poll in February.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Mr. Obama said the law enforcement system had functioned as it should in the days after the bombings. He also said the F.B.I. had properly handled the information it received from Russian intelligence agencies about the older of the two suspects, Tamerlan Tsarnaev, even as Mr. Obama conceded the difficulty of preventing attacks. “People, I think, understand that we’ve got to do everything we can to prevent these kinds of attacks from taking place,” Mr. Obama said. But he added, “We’re not going to stop living our lives because warped, twisted individuals try to intimidate us.”</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Underscoring the president’s point, a large majority of those polled, 72 percent, said they did not plan to avoid large public events to reduce their exposure to potential terrorist attacks. That confidence came even as people were divided about whether their state and local authorities were prepared to deal with such an attack (48 percent said they were prepared; 41 percent said they were not).</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Federal and local law enforcement agencies won high praise in the poll for their handling of the bombings — 84 percent approved — and some people in follow-up interviews seemed to regard the way the F.B.I. worked with the Boston and other police forces as a template for the future.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">“If we’re going to have to live with the threat of terrorism, I think it is incredibly important that it be controlled at the local level,” said Lynn Francis, 52, a retired insurance agent in Rowlett, Tex. “If there is national intelligence, it needs to be shared with local government as quickly as possible and followed up on. National and local authorities should work together.”</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">Kath Buffington, a retired teacher from Rochester, N.Y., said she was rattled by the images of a locked-down Boston, even if it was warranted in this case. But she said that in a country dealing with the threat of terrorism since the September 2001 attacks, the fight against it should not be a pretext for more pervasive forms of surveillance.</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">“I don’t have a problem with cameras as long as they are public,” Ms. Buffington said. “But wiretapping without a warrant goes too far, now that the immediate 9/11 crisis is over.”</span></p>
<p style="text-align: justify;">The effectiveness of CCTVs in preventing organised terrorist acts is at best arguable.  They are far more effective in investigating the crimes, that is after the event has taken place.  For example the London bombings on 7 July 2005 were not thwarted by the ubiquity of that city&#8217;s CCTV network. The sober reality is that the collection by human intelligence and traditional forms of investigation and policing are are more effective in preventing crimes.  The recent arrest of suspects in Al Quaeda conspiracy to derail a train in Canada was thwarted by human intelligence, not CCTV.  See article <a href="http://worldnews.nbcnews.com/_news/2013/04/23/17873250-muslims-helped-foil-alleged-canada-train-bomb-plot?lite">here</a>.</p>
<p style="text-align: justify;">The cost in establishing, manning and maintaining a CCTV network to the required standard is enormous.   Installing an extensive surveillance network and not funding it gives a misleading sense of security.  It is a recipe for failure.</p>
<p style="text-align: justify;">Major criminal or terrorist events are triggers for a, often temporary, re evaluation of individual rights.  Government action in that environment is often excessive and poorly targeted.  The US is still struggling with the poorly drafted Patriot Act.  The military commission structure to handle prosecutions of detainees in Guantanamo Bay is moribound.</p>
<p style="text-align: justify;">A pause is needed before any action is taken.  Benjamin Franklin, a Bostonian, said &#8220;Those who would sacrifice freedom for security deserve neither&#8221;.  Words to live by.</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/05/04/new-york-times-poll-on-camera-surveillance-after-boston-bombing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tweets last forever&#8230;&#8230;..here&#8217;s the proof</title>
		<link>http://www.peteraclarke.com.au/2013/04/26/tweets-last-forever-heres-the-proof/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/26/tweets-last-forever-heres-the-proof/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 07:09:22 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Practical issues]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3209</guid>
		<description><![CDATA[Recently the World Today the report UK youth commissioner under fire over foul tweets highlights the permanence of the cybersphere and what one in the full bloom of fiery youth may regret as the rules of polite society beckon.  Woad warriors could transform themselves into paragons of virtue pre internet.  Memories fade and plausible deniability [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Recently the World Today the report <a href="http://www.abc.net.au/worldtoday/content/2013/s3731935.htm">UK youth commissioner under fire over foul tweets</a> highlights the permanence of the cybersphere and what one in the full bloom of fiery youth may regret as the rules of polite society beckon.  Woad warriors could transform themselves into paragons of virtue pre internet.  Memories fade and plausible deniability is an active option. Now the the Net sets all matters in in cyber concrete.  This has had an impact lately on Paris Brown.</p>
<p>The story provides:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">ELEANOR HALL: Teenagers are often warned about what they say on social media sites: that they could come back to haunt them in later life.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">A young woman in the UK didn&#8217;t have to wait long.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">17-year-old Paris Brown&#8217;s position as the country&#8217;s first Youth Police and Crime Commissioner has been put in doubt <span id="more-3209"></span>by the publication of a string of offensive tweets from her account, as Europe correspondent Barbara Miller reports.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: Paris Brown was chosen from dozens of young applicants to be the UK&#8217;s first Youth Police and Crime Commissioner. Many no doubt were attracted in part by the more than $20,000 in salary on offer.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The role was to liaise between police and young people in the county of Kent in south-east England. Her apprenticeship was going well, until someone checked her Twitter account.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">There they found racist tweets, homophobic tweets, ones that made reference to sex and drug-taking. Paris Brown says she is sorry for any offence caused on the now-deleted account.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">PARIS BROWN: All teenagers make mistakes, all teenagers think at one point, oh I&#8217;m annoyed, write something stupid. If you look back at… I look back on our Facebook statuses or tweets that I wrote when I was, like, 13, and they&#8217;d just make you cringe. Not because they&#8217;re offensive, but because they&#8217;re just stupid.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">And it is. It&#8217;s an age thing. When you are a young person, you do have views that you don&#8217;t really agree with yourself.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: The 17-year-old says people her age sometimes tweet before thinking:</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">PARIS BROWN: Older generations haven&#8217;t grown around, grown up with Twitter, social media. They know how to sort of, maybe talk to other people about it, but for young people it&#8217;s different. We don&#8217;t want to bother people with your problems; you just think, oh I&#8217;m annoyed, tweet.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: Paris Brown is adamant that she doesn&#8217;t hold the views the tweets appeared to represent.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">PARIS BROWN: I&#8217;m not homophobic. (upset) I&#8217;m not racist. I don&#8217;t condone drug-taking. And I do not (upset)…I don&#8217;t want people judging me based on a few stupid things that I wrote which I didn&#8217;t mean, which were taken out of context, which were not meant as they are portrayed.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: Questions are being asked about whether Paris Brown really is the right person for the job.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Labour MP Keith Vaz is the chairman of the Commons Home Affairs Select Committee.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">KEITH VAZ: Of course it&#8217;s refreshing to have people in these posts, and I congratulate Ann Barnes for thinking of having the post of Youth and Crime Commissioner, but I just question whether she did proper scrutiny, asked the right questions. These kinds of statements ought to have been dealt with before the appointment.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: Kent&#8217;s independent police and crime commissioner Ann Barnes recruited Paris Brown.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">She says she has no regrets.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">ANN BARNES: I do not condone one single solitary word of these terrible tweets of Paris&#8217;. I&#8217;m as ashamed of them as she is and her parents are. But you know, she made them &#8211; a few out of 4,000 &#8211; horrible though they were, when she was 14, 15, 16-year-old. It would be awful for me to stop her having a life chance for something that was done when she was so young, and for which she is truly, truly sorry.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">And I hope she really thinks seriously about what she&#8217;s done &#8211; well, I know she&#8217;s going to. And I don&#8217;t regret making the appointment, no.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">BARBARA MILLER: Ann Barnes says it would be a sorry state of affairs if everyone&#8217;s future were determined by what they wrote in social networking sites between the ages of 14 and 16. She at least is prepared to give Paris Brown a second chance.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">On Twitter, some users are not nearly so forgiving.</span></p>
<p style="text-align: justify; padding-left: 30px;">
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/26/tweets-last-forever-heres-the-proof/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Violet Homes Loans Pty Ltd v Schmidt &amp; Anor [2013] VSCA 56 (25 March 2013): unconscionable conduct</title>
		<link>http://www.peteraclarke.com.au/2013/04/21/violet-homes-loans-pty-ltd-v-schmidt-anor-2013-vsca-56-25-march-2013-unconscionable-conduct/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/21/violet-homes-loans-pty-ltd-v-schmidt-anor-2013-vsca-56-25-march-2013-unconscionable-conduct/#comments</comments>
		<pubDate>Sun, 21 Apr 2013 10:08:15 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Victorian Court of Appeal]]></category>
		<category><![CDATA[equity]]></category>
		<category><![CDATA[unconscionable conduct]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3154</guid>
		<description><![CDATA[In Violet Homes Loans Pty Ltd v Schmidt &#38; Anor [2013] VSCA 56 the Court of Appeal unanimously upheld the trial judge&#8217;s decision that a mortgage originator FACTS In Perpetual Trustees Australia Limited v Schmidt &#38; Anor [2010] VSC 67 the trial judge, J Forrest J, found that Violet Homes Pty Ltd (&#8220;Violet&#8221;) had acted [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In <a href="http://www.austlii.edu.au/au/cases/vic/VSCA/2013/56.html">Violet Homes Loans Pty Ltd v Schmidt &amp; Anor [2013] VSCA 56</a> the Court of Appeal unanimously upheld the trial judge&#8217;s decision that a mortgage originator</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">FACTS</span></h1>
<p style="text-align: justify;">In <a href="http://www.austlii.edu.au/au/cases/vic/VSC/2010/67.html">Perpetual Trustees Australia Limited v Schmidt &amp; Anor [2010] VSC 67</a> the trial judge, J Forrest J, found that Violet Homes Pty Ltd (&#8220;Violet&#8221;) had acted unconscionably and in breach of the general law, section 51AC of the Trade Practices Act and section 12CB of the Australian Securities and Investment Commission Act 2001.</p>
<p style="text-align: justify;">In 2003 the Plaintiff (&#8220;Schmidt&#8221;) responded to an advertisement which claimed an investment of $40,000 in  syndicate would lead to a net return of $80,000 within 12 months.  Schmidt range the number given and spoke to a Mr Maddocks (&#8220;Maddocks&#8221;).  In next month he invested $80,000 in the syndicate.  obtained a line of credit from Perpetual Trustees Australia Ltd <span style="color: #008000;">[12]</span>.  In early 2004 Maddocks pursuaded Schmidt to make further investments.  Schmidt was unable to borrow from his bank, the Bank of Melbourne, because he was a pensioner who had no capacity to repay <span style="color: #008000;">[13]</span>.  Maddocks arranged a loan for Schmidt from Perpetual, preparing the loan application and income declaration.  The documents contained false information, as to Schmidt&#8217;s employment situation and his annual income.  Schmidt did not provide the false information but signed the documents without reading them <span style="color: #008000;">[14]</span>.  The documents were provided to a finance broker, Medallion Finance Concepts (&#8220;Medallion&#8221;) who onforwarded them to Violet <span style="color: #008000;">[16]</span>. Responding to querries by Ms Bonnici a credit officer at Violet, including a failure to provide an ABN, raised Maddocks prepared an amended the application and had Schmidt sign it <span style="color: #008000;">[20]</span>.  At no time did anyone from Violet deal with Schmidt directly.</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">DECISION</span></h1>
<h2 style="text-align: justify;"><span style="color: #3366ff;">Unconsionability</span></h2>
<p style="text-align: justify;">The Court found that &#8220;..recklessness, in the form of wilful blindness, may in some cases supply the necessary element of moral obloquy&#8221;<span style="color: #008000;">[58]</span>.  The court said<span id="more-3154"></span> that there was limited use in comparing facts of particular cases to determine whether the facts in question is unconscionable, by way of compare and contrast.  Rather, the court said &#8220;.. the task requires a more synthesised approach which takes into account all of the facts relevant to the impugned conduct and determines whether, in all the circumstances, that particular conduct is unconscionable&#8221; <span style="color: #008000;">[59]</span>. In this case:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;"> Here, the discrepancy in the figures in the loan application and income declaration, not just once, but twice and the absence of an ABN, which was requested but never provided, ought to have raised the suspicion of Violet that something may be amiss with the application. </span></p>
<p style="text-align: justify;">The fact that Violet did not comply with its own procedures told against it in light of its other failures with the court stating, at <span style="color: #008000;">[67]</span>:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">However, sometimes a risk eventuates and, depending on all the circumstances, the lender may be held responsible for the consequences, partly because the very system the lender has established facilitates the perpetration of frauds upon borrowers. No doubt lenders take this into account when pricing their products and determining that, overall, it is in their commercial interests to proceed with the simplified and, in some senses, automated, processing and outsourcing of lending functions.</span></p>
<p>In light of that the court said, at <span style="color: #008000;">[68]</span>, that:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">So it was that when the revised forms were submitted with a reduced figure for Mr Schmidt’s income and no ABN, Ms Bonnici did not question this nor examine nor question more closely the other matters that suggested all was not right (for example the payment of interest out of capital in the Assetbuilder Loan account and Mr Schmidt’s age) that ought to have been apparent from the other information provided. In those circumstances, and without a satisfactory explanation, the failure of Violet to conduct an interview (by telephone or in person) was reprehensible. Whilst a failure to conduct an interview and thus comply with the guidelines may not of itself constitute unconscionable conduct in the generality of cases, in the circumstances of this case, that failure strongly supports the proposition that Violet’s conduct was unconscionable.</span></p>
<h2><span style="color: #3366ff;">Section 12CB of ASIC Act<strong><em><br />
</em></strong></span></h2>
<p style="text-align: justify;">Section 12CB prohibits unconscionable conduct in relation to a consumer.  The appellant claimed that Schmidt&#8217;s application was for business credit, not &#8220;..were not of a kind ‘ordinarily acquired for personal, domestic or household use’ and therefore not subject of section 12CB.</p>
<p style="text-align: justify;">The Court undertook an anlaysis of the authorities (<span style="color: #008000;">[72]- [74]</span>) in particular Young J in <a href="http://www.austlii.edu.au/au/cases/cth/FCA/2006/682.html"><em>Bunnings Group Ltd v Laminex Group Lt</em></a><em>d</em> where the applicable principles were described as:</p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">(a) the word ‘ordinarily’ means ‘commonly’ or ‘regularly’, not ‘principally’, ‘exclusively’ or ‘predominantly;<sup><a name="fnB59" href="http://www.austlii.edu.au/au/cases/vic/VSCA/2013/56.html#fn59"></a></sup></span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">(b) it is preferable to ask whether the goods are of a kind ordinarily acquired for personal, domestic or household use or consumption as a single composite question. His Honour referred to a passage from <em>Clean Investments Pty Ltd v Commissioner of Taxation:</em></span></p>
<blockquote style="padding-left: 30px;">
<blockquote><p><span style="color: #ff0000;">For example, an architect’s stool, an office chair and a kitchen stool or chair may be described as ‘stools’ or ‘chairs’ and their purpose as being ‘to provide seating’. Yet it would be wrong to conclude that the architect’s stool or the office chair is of a kind ordinarily used for household purposes for no other reason than that, like the kitchen chair, it is ordinarily used for the purpose of providing seating<sup>.</sup></span></p></blockquote>
</blockquote>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">(c) depending on the precise statutory question and the circumstances of the particular case, it will be relevant to inquire as to the essential character of the goods in question;</span></p>
<p style="padding-left: 30px; text-align: justify;"><span style="color: #ff0000;">(d) the question is ultimately a question of fact and degree<sup>.</sup></span></p>
<p>and found, at <span style="color: #008000;">[75]</span> the financial services were of a kind ordinarily acquired for personal use <span style="color: #008000;">[75]</span> stating:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;.. it is now not uncommon for funds to be borrowed by retirees and used in investment projects, such as the project that Mr Schmidt thought he was investing in. Indeed, the advertisements to which Mr Schmidt responded were headed ‘Retirees/Investors/Superannuation’. Moreover, the type of ‘low doc loan’ obtained by Mr Schmidt was only available if the security property was residential with a loan to value ratio of 80 per cent. The maximum amount that could be borrowed was $600,000. Ordinarily, that type of loan is one that is used for personal investment, rather than for the operation of what might be described as an investment business. ..&#8221;</span></p>
<h2><span style="color: #3366ff;">Trade or Commerce</span></h2>
<p style="text-align: justify;"> While the Court was not required to consider whether there was a contravention of section 51AC of the Trade Practices Act they cited with approval the New South Wales Court of Appeal in <em>Kowalczuk v Accom Finance Pty Ltd</em> where the Court stated:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;..a transaction is entered <em>‘</em>for the purpose of trade or commerce’ when it is entered to enable some further activity, that has itself a trading or commercial character, to be engaged in. For a private individual, or a private individual’s company, to make an investment is not, in my view, to enter a transaction ‘for the purpose of trade or commerce<em>’</em> when it is not itself a part of a business of investing&#8230;&#8221;</span></p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">ISSUE</span></h1>
<p style="text-align: justify;">In this case the Court found the recklessness in the form of wilful blindness gave rise to a claim of unconscionable conduct. Unconscionable conduct is a developing area of equity and this case highlights the latest development in expanding the potential liability of financial service providers (and advisors). Here the court was critical of the creditor who breached its own protocols to effect the loan.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/21/violet-homes-loans-pty-ltd-v-schmidt-anor-2013-vsca-56-25-march-2013-unconscionable-conduct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McCracken v Phoenix Constructions (Queensland) Pty Ltd [2013] FCAFC 41 (18 April 2013): Bankruptcy, whether debt owing at time of bankruptcy, sections 44(1) and 52(1) of Bankruptcy Act</title>
		<link>http://www.peteraclarke.com.au/2013/04/21/mccracken-v-phoenix-constructions-queensland-pty-ltd-2013-fcafc-41-18-april-2013-bankruptcy-whether-debt-owing-at-time-of-bankruptcy-sections-441-and-521-of-bankruptcy-act/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/21/mccracken-v-phoenix-constructions-queensland-pty-ltd-2013-fcafc-41-18-april-2013-bankruptcy-whether-debt-owing-at-time-of-bankruptcy-sections-441-and-521-of-bankruptcy-act/#comments</comments>
		<pubDate>Sun, 21 Apr 2013 09:41:01 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[Bankruptcy Law]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3230</guid>
		<description><![CDATA[The Full bench of the Federal court in McCracken v Phoenix Constructions (Queensland) Pty Ltd [2013] FCAFC 41 by unanimous decision and per Lander J&#8217;s reasons, upheld an appeal against a sequestration order made by the Federal Magistrate&#8217;s Court.  The issue on appeal, at [34], is succinctly described as: &#8220;..first, whether if a debt is [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The Full bench of the Federal court in <a href="http://www.austlii.edu.au/au/cases/cth/FCAFC/2013/41.html">McCracken v Phoenix Constructions (Queensland) Pty Ltd [2013] FCAFC 41</a> by unanimous decision and per Lander J&#8217;s reasons, upheld an appeal against a sequestration order made by the Federal Magistrate&#8217;s Court.  The issue on appeal, at<span style="color: #008000;"> [34]</span>, is succinctly described as:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;..first, whether if a debt is relied upon for the issue of the bankruptcy notice and as an act of bankruptcy, that debt must continue to be owing at the time when the creditor’s petition is heard for the Court to make a sequestration order; secondly, if the debt is no longer owing at that time, whether the petitioning creditor can rely upon a later debt which first arose after the act of bankruptcy and after the filing of a creditor’s petition; and thirdly, if that debt can be relied upon at the hearing of the creditor’s petition and at the time of the making of the sequestration order, must that debt be for a liquidated sum.&#8221;</span></p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">Facts </span></h1>
<p style="text-align: justify;">The Appellant (&#8220;McCracken&#8221;) and the Respondent (&#8220;Phoenix&#8221;) were involved in a proceeding which culminated in judgement being entered for Phoenix in the sum of $2,025,212.17 on 15 June 2011. On 7 July 2011 the official receiver issued a bankruptcy notice directed to McCracken <span style="color: #008000;">[4]</span>. On 12 July 2011 McCracken filed a notice of appeal <span style="color: #008000;">[5]</span> and on 13 July the trial judge ordered McCracken to pay Phoenix&#8217;s cost of the proceedings <span style="color: #008000;">[6]</span>. Those costs were never assessed. On 10 August 2011 a bankruptcy notice was served on McCracken<span style="color: #008000;"> [12]</span> with Phoenix filing a creditor&#8217;s petition on 11 August 2011. The creditors petition relied on a number of acts of bankruptcy including McCracken absenting himself from Australia and his dwelling house to avoid service. It did not rely upon the appellants failure to pay the judgement sum <span style="color: #008000;">[13]</span>.  On 27 September 2011 in the Court of Appeal refused McCracken&#8217;s application for a stay of the judgement <span style="color: #008000;">[15]</span> and the Federal Magistrates Court refused his application for a stay of the bankruptcy proceeding <span style="color: #008000;">[16]</span>. On 18 October 2011 Phoenix filed an amended creditors petition relying upon McCracken&#8217;s failure to comply with the bankruptcy notice <span style="color: #008000;">[17]</span>.</p>
<p style="text-align: justify;">On 18 May 2012 the Court of Appeal allowed McCracken&#8217;s appeal and set aside the orders made by the trial judge <span style="color: #008000;">[19].</span> On 19 July 2012  the Federal Magistrates Court heard the petition and made a sequestration order against McCracken on 14 September 2012 <span style="color: #008000;">[22]</span>. Their Honours&#8217; noted that at the time the Federal Magistrates Court heard the creditor&#8217;s petition the debt which was relied on in both the bankruptcy notice and the creditor&#8217;s petition no longer existed, having been discharged by the Court of Appeal <span style="color: #008000;">[23]</span>. The Federal Magistrate concluded that even though the amount may have changed there was an ongoing debt that which was still doing due and owing <span style="color: #008000;">[31]</span> and that once an act of bankruptcy had been committed it remained available for the purposes of a sequestration order and did not rely on other acts of bankruptcy relied upon by Phoenix, such as the conduct of the appellants to avoid service <span style="color: #008000;">[33]</span>.</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">Decision</span></h1>
<p style="text-align: justify;">Where the debtor who has committed an act of bankruptcy is ordinarily resident in Australia the court may make a sequestration order against the estate of the debtor <span style="color: #008000;">[51]</span>.  The first requirement to found that jurisdiction is that the debtor has committed an act of bankruptcy <span style="color: #008000;">[52]</span>. The second necessary fact is that the debtor comes within one of the descriptions and section <a href="http://www.austlii.edu.au/au/legis/cth/consol_act/ba1966142/s43.html">43(1) (b)</a> of the <a href="http://www.austlii.edu.au/au/legis/cth/consol_act/ba1966142/">Bankruptcy Act 1966</a> (the &#8220;Act&#8221;).</p>
<p style="text-align: justify;">The Court found that whilst the debt need not be the same debt as was relied upon to the act of bankruptcy <em><strong>it must be a debt which existed at the time of the act of bankruptcy</strong></em> <span style="color: #008000;">[63]</span>. The debt must <span id="more-3230"></span>also be a debt for liquidated sum payable immediately or at a certain future time <span style="color: #008000;">[65]</span>.  <a href="http://www.austlii.edu.au/au/legis/cth/consol_act/ba1966142/s52.html">Section 52 (1) </a>requires the creditor by affidavit or <em>viva voce</em> evidence of the matters stated in the petition. That requires proof that an act of bankruptcy occurred as alleged in the proof of debts relied upon in the creditors petition and they can only be those that existed at the time of the act of bankruptcy occurred and when the creditors petition was presented <span style="color: #008000;">[77]</span>. The creditor must also prove that the debts on which the petitioning creditors rely is or are still owing <span style="color: #008000;">[79]</span>.</p>
<p style="text-align: justify;">The Court found that at the time a hearing of creditor&#8217;s petition the debt which was created by the judgement of the Supreme Court of Queensland and relied upon in the act of bankruptcy and in the petition no longer existed <span style="color: #008000;">[91]</span>. Phoenix could not rely upon it therefore could not satisfy section <a href="http://www.austlii.edu.au/au/legis/cth/consol_act/ba1966142/s52.html">52(1)(a)</a> of the Act. Phoenix could not have relied any judgement debt in the form of a costs order.  That order only came into existence on 18 May 2012. Further that order in any event was not a debt for liquidated sum <span style="color: #008000;">[94]</span> and the debt could not become a liquidated sum until the procedures had been finalised and the registrar had made an order in the assessors certificate <span style="color: #008000;">[94]</span>.</p>
<p style="text-align: justify;">The Court rejected Phoenix&#8217;s submission that it had not engaged a costs consultant because the McCracken was insolvent and it would not have recovered the costs of the assessment and McCracken could have required Phoenix to assess the costs. Their Honours also rejected Phoenix&#8217;s  submission that an approved costs assessor had provided opinion that the costs could have been assessed at about $400,000 which could be relied upon <span style="color: #008000;">[96]</span>.  As such no sequestration order could have been made because it is a prerequisite for the making of such an order that at the time of the orders made the creditor is able to provide a liquidated sum in excess of $5000 (<a href="http://www.austlii.edu.au/au/legis/cth/consol_act/ba1966142/s41.html">section 41 (1) (b) (i)</a>).</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">Issue</span></h1>
<p style="text-align: justify;">That bankruptcy notices and creditor petitions are technical documents which must comply with the Act is trite  This decision highlights the great care in determining what is the debt upon which a notice or petition applies and what act of bankruptcy is relied upon.  The fact situation in this case is unusual but highlights the need to always refer back to the legislation to determine whether the creditor&#8217;s position changed <em>vis a vis</em> the debtor.  Phoenix found itself without a judgement debt and while it had obtained a costs order its favour it had not assessed that order so that it could be calculated and a certificate issued for liquidated sum. Notwithstanding that, it pressed on with and the court found the fatal flaws in the petition.  Lander J&#8217;s decision will be quite influential as he  undertook a very detailed and useful analysis of the operation of bankruptcy notices and creditors petition.</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/21/mccracken-v-phoenix-constructions-queensland-pty-ltd-2013-fcafc-41-18-april-2013-bankruptcy-whether-debt-owing-at-time-of-bankruptcy-sections-441-and-521-of-bankruptcy-act/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google chief raises privacy issues about drones</title>
		<link>http://www.peteraclarke.com.au/2013/04/14/google-chief-raises-privacy-issues-about-drones/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/14/google-chief-raises-privacy-issues-about-drones/#comments</comments>
		<pubDate>Sun, 14 Apr 2013 03:48:55 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Articles]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3225</guid>
		<description><![CDATA[Who would have thought someone from Google would raise worries about privacy&#8230;&#8230;..about anything.  But it has happened.  In Google chief urges action to regulate mini-drones Eric Schmidt raises privacy and security concerns about drones. The article provides: The influential head of Google, Eric Schmidt, has called for civilian drone technology to be regulated, warning about [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Who would have thought someone from Google would raise worries about privacy&#8230;&#8230;..about anything.  But it has happened.  In <a href="http://www.bbc.co.uk/news/technology-22134898">Google chief urges action to regulate mini-drones</a> Eric Schmidt raises privacy and security concerns about drones.</p>
<p>The article provides:</p>
<p id="story_continues_1" style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The<span id="more-3225"></span> influential head of Google, Eric Schmidt, has called for civilian drone technology to be regulated, warning about privacy and security concerns.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Cheap miniature versions of the unmanned aircraft used by militaries could fall into the wrong hands, he told the UK&#8217;s Guardian newspaper.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Quarrelling neighbours, he suggested, might end up buzzing each other with private surveillance drones.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">He also warned of the risk of terrorists using the new technology.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Schmidt is believed to have close relations with US President Barack Obama, whom he advises on matters of science and technology.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;You&#8217;re having a dispute with your neighbour,&#8221; he told The Guardian in an interview printed on Saturday.</span></p>
<div style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;"> Eric Schmidt is one of the world&#8217;s leading figures in digital technology</span></div>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;How would you feel if your neighbour went over and bought a commercial observation drone that they can launch from their backyard. It just flies over your house all day. How would you feel about it?&#8221;</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Warning of mini-drones&#8217; potential as a terrorist weapon, he said: &#8220;I&#8217;m not going to pass judgment on whether armies should exist, but I would prefer to not spread and democratise the ability to fight war to every single human being.&#8221;</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8220;It&#8217;s got to be regulated&#8230; It&#8217;s one thing for governments, who have some legitimacy in what they&#8217;re doing, but have other people doing it&#8230; it&#8217;s not going to happen.&#8221;</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Small drones, such as flying cameras, are already available worldwide, and non-military surveillance were recently introduced to track poachers in the remote Indian state of Assam.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">The US and Israel have led the way in recent years in using drones as weapons of war as well as for surveillance.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">America&#8217;s Federal Aviation Administration is currently exploring how commercial drones, or <a href="http://www.faa.gov/news/fact_sheets/news_story.cfm?newsId=14153"><span style="color: #ff0000;">unmanned aircraft systems</span></a>, can be safely introduced into US airspace.</span></p>
<p style="text-align: justify;">Everything Schmidt says is absolutely correct.  Some form of regulation is required, both as to how they operate but also (and distinctly) the privacy protections.  In Australia CASA would regulate the nuts and bolts use of drones; high low they can fly, where they are not permitted to go (eg airports, near power lines etc) but such regulation generally does not work well in providing a coherent legal framework in protecting privacy.  It is possible for an operator to be properly licensed, to use a drone which complies with all specifications and fly within permitted areas and still egregiously interfere with someone&#8217;s privacy.  There needs to be civil penalties for interference with privacy which can be used by individuals and the Privacy Commissioner. Sometimes an individual  will prosecute a claim where the Privacy Commissioner will not because of resourcing or policy issues.  Other times the Privacy Commissioner will take action where individuals have no resources.  What is often forgotten in this discussion is the failure of State Governments to provide adequate privacy protections.  It is not a Commonwealth issues <em>per se</em>.  State laws could affect how drones are used in both public places and on or over private properties. The Victorian Government was provided with a report from its Law Reform Commission in 2010 recommending a statutory right or privacy.  It did nothing.  A failure to provide adequate privacy protections in Victorian is a shared failure of both the State Government and the Commonwealth.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/14/google-chief-raises-privacy-issues-about-drones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In May 2013 I will be delivering a paper at MIT8.</title>
		<link>http://www.peteraclarke.com.au/2013/04/13/in-may-2013-i-will-be-delivering-a-paper-at-mit8/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/13/in-may-2013-i-will-be-delivering-a-paper-at-mit8/#comments</comments>
		<pubDate>Sat, 13 Apr 2013 04:56:57 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3215</guid>
		<description><![CDATA[Massachusetts Institute of Technology (&#8220;MIT&#8221;) have accepted my proposal to publish a paper and make a presentation at MIT8; public media private media, media in transition international conference.  It will be held at Cambridge Massachusetts, USA. The homepage for the conference is found here. The tentative agenda is found here. I will be on a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><a href="http://www.mit.edu/">Massachusetts Institute of Technology</a> (&#8220;MIT&#8221;) have accepted my proposal to publish a paper and make a presentation at <em>MIT8; public media private media, media in transition</em> international conference.  It will be held at Cambridge Massachusetts, USA.</p>
<p style="text-align: justify;">The homepage for the conference is found <a href="http://web.mit.edu/comm-forum/mit8/">here</a>. The tentative agenda is found <a href="http://web.mit.edu/comm-forum/mit8/subs/agenda.html">here</a>.</p>
<p style="text-align: justify;">I will be on a panel on Sunday 5 May 2013 covering <strong>Reputation and Identity Online</strong>.  My presentation is titled <em><strong>Managing Online Identity</strong></em>.</p>
<p style="text-align: justify;">The agenda relevantly provides:</p>
<table width="95%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr valign="top">
<td align="left"><span style="font-family: Arial,Helvetica,sans-serif; font-size: x-small;"><br />
</span></td>
<td colspan="3" align="left">Reputation and Identity Online</p>
<ul>
<li>Peter Clarke, <a href="http://web.mit.edu/comm-forum/mit8/subs/abstracts.html#clarke" target="_blank">Managing Online Identity</a></li>
<li>Wayne Erik Rysavy, <a href="http://web.mit.edu/comm-forum/mit8/subs/abstracts.html#rysavy" target="_blank">Digitally Disembodied: Social Surveillance and the Rise of Crowdsourced Morality</a></li>
<li>Peter Walsh, <a href="http://web.mit.edu/comm-forum/mit8/subs/abstracts.html#walsh" target="_blank">Media and the Construction of Public Life</a></li>
</ul>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/13/in-may-2013-i-will-be-delivering-a-paper-at-mit8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Complainant AY v Public Sector Employer [2013] VPrivCmr 02</title>
		<link>http://www.peteraclarke.com.au/2013/04/12/complainant-ay-v-public-sector-employer-2013-vprivcmr-02/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/12/complainant-ay-v-public-sector-employer-2013-vprivcmr-02/#comments</comments>
		<pubDate>Fri, 12 Apr 2013 12:56:42 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy US case Law]]></category>
		<category><![CDATA[Victorian law]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3203</guid>
		<description><![CDATA[In Complainant AY v Public Sector Employer [2013] VPrivCmr 02 the Victorian Privacy Commissioner considered a serious complaint about a breach of privacy by a public sector employer. FACTS In approximately 2006, the Complainant forwarded an unsolicited email application to an employee of the Respondent for a job. This application contained a covering letter and [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In Complainant <a href="https://www.privacy.vic.gov.au/domino/privacyvic/web2.nsf/files/complainant-ay-v-public-sector-employer-2013">AY v Public Sector Employer [2013] VPrivCmr 02</a> the Victorian Privacy Commissioner considered a serious complaint about a breach of privacy by a public sector employer.</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">FACTS</span></h1>
<p style="text-align: justify;">In approximately 2006<span id="more-3203"></span>, the Complainant forwarded an unsolicited email application to an employee of the Respondent for a job. This application contained a covering letter and details about the Complainant’s qualifications.</p>
<p>Subsequently, this application was uploaded to a personal blog website by an employee of the Respondent. The uploaded information contained extracts of the Complainant’s application together with  unfavourable remarks about the Complainant’s qualifications and the application.</p>
<p style="text-align: justify;">The website was available online and without any restrictions as to who could view it. Additionally, other unidentified individuals had made further negative statements in the ‘comments’ section of the website about the Complainant’s application and qualifications.  In June 2012, the Complainant became aware of the website when he was directed to it by a friend.</p>
<p style="text-align: justify;">The Respondent conceded that a breach of the Complainant’s privacy had occurred. It  provided a written apology to the Complainant, instructed the employee to remove the material from the website and that employee was directed to attend privacy training. The Respondent argued that the organisation was unaware of the employee’s actions until the complaint was raised and was therefore unable to take reasonable steps to protect or secure the Complainant’s personal information. The Respondent argued that it had adequately dealt with the complaint under section 29(1)(h)(i) of the Act and requested the Acting Commissioner exercise his discretion to decline the complaint.</p>
<h1 style="text-align: justify;"><span style="color: #0000ff;">DECISION</span></h1>
<p style="text-align: justify;">The Acting Commissioner found the Respondent had not taken reasonable steps to protect the personal information it held from misuse and disclosure (IPP 4.1) or inaccuracy (IPP 3.1). There also appeared no grounds under IPP 2 that supported the disclosure.</p>
<p style="text-align: justify;">The Commissioner also found that actions of an employee are generally attributable to an organisation (here, the Respondent) and that the Respondent had not provided evidence to support what steps the Respondent had taken to educate the employee on their responsibilities under the <em>Information Privacy Act. </em></p>
<p style="text-align: justify;">The Commissioner considered that there was merit in referring the complaint to conciliation to resolve the matter.</p>
<h1><span style="color: #0000ff;">ISSUE</span></h1>
<p style="text-align: justify;">The Privacy Commissioner was correct to reject the Respondent&#8217;s claim that it could not be responsible for the breach as it was not aware of the posting.  Once the application came into the possession of the employee of the Respondent it was the Respondent&#8217;s responsibility to maintain proper record of the document and ensure it was secured adequately.  That an employee could take it and upload it onto a web site and have other members of the public comment on it is a very serious breach of privacy.</p>
<p style="text-align: justify;">It is an indictment on the structure of reportage that the department or agency is not named.  That is the best way of rectifying poor management and poor insight.  That the respondent agency/department could somewhat argue that it was not ultimately responsible for the breach is indicative of arrogance, a lack of understanding of the Information Privacy Act or breathtakingly incompetent legal representation.  Or a combination of all three factors.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/12/complainant-ay-v-public-sector-employer-2013-vprivcmr-02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defamation claim involving private moments reported in the Age</title>
		<link>http://www.peteraclarke.com.au/2013/04/12/defamation-claim-involving-private-moments-reported-in-the-age/</link>
		<comments>http://www.peteraclarke.com.au/2013/04/12/defamation-claim-involving-private-moments-reported-in-the-age/#comments</comments>
		<pubDate>Fri, 12 Apr 2013 00:18:55 +0000</pubDate>
		<dc:creator>Peter Clarke</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.peteraclarke.com.au/?p=3204</guid>
		<description><![CDATA[The Age in Liquidator claims in writ that stripper photos led to dismissal reports on an allegedly surreptituous photograph of the Plaintiff in a compromising position with an exotic dancer (stripper in the general vernacular). It provides: Strip club operator Maxine Fensom is being sued for defamation by liquidator Glenn Crisp over photographs of him [...]]]></description>
			<content:encoded><![CDATA[<p>The Age in <a href="http://www.theage.com.au/business/liquidator-claims-in-writ-that-stripper-photos-led-to-dismissal-20130411-2hokq.html">Liquidator claims in writ that stripper photos led to dismissal</a> reports on an allegedly surreptituous photograph of the Plaintiff in a compromising position with an exotic dancer (stripper in the general vernacular).</p>
<p>It provides:</p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Strip club operator<span id="more-3204"></span> Maxine Fensom is being sued for defamation by liquidator Glenn Crisp over photographs of him in &#8221;compromising positions with strippers&#8221; that were passed on to a man with alleged links to outlaw motorcycle gangs.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Crisp alleges Ms Fensom took photographs without his knowledge on a Yarra River boat cruise in 2012, which he claims cost him his $600,000 a year job and portrayed him as &#8221;a person of disrepute&#8221;.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Ms Fensom allegedly copied the photos on to a disk, which was found in the office of Steve Iliopoulos, the director of trucking company Viking Group. Mr Crisp was in charge of liquidating Viking Group.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Iliopoulos, who is fighting fraud charges totalling $33 million over the collapse of Viking Group, has been linked in evidence to the Victorian president of the Comancheros outlaw motorcycle gang, Amad &#8221;Jay&#8221; Malkoun.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">In a writ filed with the Supreme Court of Victoria, Mr Crisp claims he was invited on to the cruise where &#8221;Ms Fensom attended together with a number of waitresses and erotic dancers&#8221;. &#8221;During the course of the boat cruise, without Mr Crisp&#8217;s knowledge or consent, Ms Fensom took photographs of Mr Crisp in the company of strippers as they performed,&#8221; the writ claims.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Forensic examination confirmed the photos were taken &#8221;on Ms Fensom&#8217;s Apple iPhone 3GS mobile phones during the course of the boat cruise&#8221;, according to the writ.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Crisp said on Thursday: &#8221;I am after damages for whatever has happened to me.&#8221;</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Ms Fensom said she did not know Mr Crisp or Mr Iliopoulos and was unaware of the writ.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">&#8221;I take photos all the time. Everyone knows I video a lot of my events. I had no complaints from this person or any other person in regard to functions and taking photos,&#8221; she told Fairfax Media.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Crisp&#8217;s writ claims the explicit photos were discovered on a disk two weeks later following a search of Mr Iliopoulos&#8217; office by security staff hired by his then-employer RSM Bird Cameron.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">On April 5 the security staff allegedly passed the photos on to RSM executive Andrew Beck.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Crisp claims that because of the photographs he was stripped of a $200,000 share in RSM&#8217;s profits and fired from his job on April 16. The defamation occurred when photos taken by Ms Fensom were viewed by other people.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">Mr Crisp is claiming general damages and loss of income of $2.6 million.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">This includes the difference between what he could have earned at RSM over the next 13 years and the $400,000 a year job he holds at Jirsch Sutherland.</span></p>
<p style="text-align: justify; padding-left: 30px;"><span style="color: #ff0000;">In separate County Court proceedings, RSM last year alleged Mr Crisp transferred $500,000 in fees earned from an insolvency job into a personal bank account.</span></p>
<div style="text-align: justify;">As this matter is <em>sub judice</em> care must be taken not to stray into speculation on how a case is pleaded, strengths and weaknesses etc.. That said it is interesting to see it pleaded in defamation.  It has been done in the past where there are privacy related issues in play.  In the UK such circumstances may very well be brought in equity with reliance on Article 8 of the Human Rights Act, the right to privacy.  In the UK the equitable action of misuse of private information has developed and become a more established cause of action and has dealt with the very personal situations such as is described in the article.  Even more useful would be a tort of privacy.  The law as it stands now involves stretching and straining existing causes of action to cover changes in technology, greater expectations of privacy and, to use the old fashoned but apt term, the justice in a situation.  With Giller v Procopets a claim of misuse of private information is available</div>
]]></content:encoded>
			<wfw:commentRss>http://www.peteraclarke.com.au/2013/04/12/defamation-claim-involving-private-moments-reported-in-the-age/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
