Smart glasses not going to be banned or moritorium on their import.

August 31, 2026

The dystopian effects of using smart glasses have been grist for the political mill.  Smart glasses have been called pervert glasses by the Greens who want them banned.  The Government equivocated over the weekend and came out today, through the Attorney General Michelle Rowland, saying that there are no current plans to impose an import ban on smart glasses.  Presumably that means no ban on their use either.

The Government has introduced the ID Lock which will enable people to block or unblock the use of identify documents through the Document Verification Service.  The Attorney General’s media statement provides:

The Albanese Government is strengthening Australia’s identity protection framework with the introduction of IDLock, a new digital identity protection service designed to give Australians direct control over how their identity documents are used for verification.

The new service will be available securely through myGov next year and will enable Australians to block, unblock and monitor the use of eligible identity documents through the Document Verification Service at any time. This will help Australians protect themselves from identity crime, scams and the impacts of data breaches before harm occurs.

IDLock is being developed as a new way for people to access the protections of the Credential Protection Register. Established by the Commonwealth in 2022, the register helps prevent compromised identity documents from being used to fraudulently establish an individual’s identity.

Since late 2022, the register has blocked over 830,000 fraudulent identity verification attempts, averaging around 18,000 each month. This demonstrates the important role the register plays in protecting Australians when their identity credentials have been compromised.

IDLock will be released initially to a small cohort of users for early access and testing later this year, ahead of a broader national rollout in 2027.

Visit the IDMatch website for more information about identity verification services, or the IDCARE website for tailored support and assistance with regard to scams, identity theft and cyber threats.

Quotes attributable to the Attorney-General, Hon Michelle Rowland MP:

“Australians deserve to have control over how their personal identity information, such as their driver licence or passport, is used to verify their identity online. 

“As data breaches, scams and cyber-enabled crime continue to evolve, Australia’s approach must evolve with them.

“With the launch of IDLock, our Government is taking the next step towards a stronger, more robust identity verification framework that expands the focus from responding after identity credentials have been compromised, to enabling Australians to protect themselves before identity crime occurs.

“Whether their driver licence details have been exposed in a data breach or they are concerned about scams and identity theft, IDLock will give Australians an accessible and simple way to have greater visibility, control and confidence in how their identity documents are used.”

  The ABC report Read the rest of this entry »

Commonwealth Government releases 2nd tranche of reforms to the Privacy Act 1988

Today the Attorney General released an Exposure Draft of the Privacy Amendment (Personal Data Protection) bill 2026 and a Consultation Paper.  The Government has set a very narrow window for submissions, a little under 3 weeks.  Consultations close on 18 September 2026.

The Bill focuses on tightening definitions and providing more specific Australian Privacy Principles in certain areas, such as direct marketing and data security.  It also strengthens the obligations under the Data Breach Notification provisions which were not very effective.

The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying consultation paper contains around 40 proposals.  Some are taken from the Attorney General’s Privacy Act Review Report (2023). Other proposals are framed to to address emerging technologies.

Interestingly the consultation  seeks views on emerging technologies such as smart glasses and connected vehicles.

Under the proposed amendments the attempt is to:

  • increase accountability across the personal information lifecycle
  • impose stronger data security obligations
  • impose data minimisation
  • have a more effective data breach response structure including notifying the Privacy Commissioner within 72 hours
  • impose a simplified principles-based framework for handling personal information,
  • impose a more coherent consent obligations
  • impose stricter requirements for direct marketing regime.
  • a right to erasure for personal information held by large digital platforms

The Bill does not give individuals any greater rights to take action to protect their privacy.

It is a very technocratic Bill and a very small step in the long process of privacy reform.  In that regard it is disappointing.

There is a very long way to go.

The Attorney General’s media statement Read the rest of this entry »

Regulatory crackdown on smart glasses use at the Council level, lots of correspondence at the Federal Level. The situation is not satisfactory however there are already causes of action to deal with invasions of privacy

August 30, 2026

It is well established that individuals have actionable claims for breach of privacy, in the form of misuse of private information, for photographs or videos taken in public.  The two significant cases are Campbell v MGM Ltd [2004] UKHL 22 and Murray v Big Pictures [2008] EWCA 446. Campbell’s case involved MGN photographing Naomi Campbell on a street leaving a Narcotics Anonymous Meeting.  In Murray the young child of J K Rowlings was photographed in a pram in Edinburgh.  The leading New Zealand case of Hosking v Runting [2003] 3 NZLR 385 which formally recognised a stand alone tort of privacy involved publication of private information, involved Runting photographing the Hoskings’ 18-month-old twin daughters in a public shopping street in Auckland without the mother’s knowledge or consent.

The Victorian Court of Appeal decision of  Giller v Procopets (2008) 24 VR 1 recognised the equitable cause of action of misuse of private information and cited with approval the Campbell and others.  The Court also found that damages for emotional distress could be awarded for such a breach of confidence.

The Brisbane City Council has banned the “non consensual” use of AI smart glasses.  use of smart glasses.  Actually it is more expansive, being a blanket ban on all camera enabled devices including wearable technology, phones and action cameras.  Patrons can bring smart glasses into the pool.  They just can’t be used to film without permission.  This is a policy that will be quite difficult to effectively enforce.

On 7 August 2026 the Commonwealth Attorney General wrote to the Privacy Commissioner about the privacy implications of the use of smart glasses.  On 28 August The New Zealand Privacy Commissioner has already issued a statement, almost a guidance, on the use of smart glasses stating:

  • because the devices look like ordinary eyewear, people can covertly film others, making it harder for those being filmed to object.
  • the Commissioner’s concerns would grow if manufacturers integrate facial recognition technology into smart glasses in the future
  • there is uncertainty around how companies collect, use, and store the data these devices gather.
  • that people who use smart glasses in a personal capacity should tell people they are recording, even though most smart glasses flash a light while recording.
  • while the New Zealand Privacy Act permits individuals to collect and use personal information for personal or domestic purposes providing that use, or sharing does not become highly offensive. Factors relevant in determining whether the filming highly offensive, include:
    • how the information is filmed;

    • how sensitive it is; and

    • how vulnerable the person being filmed is.

  •  filming children, or capturing someone’s health or mental state, calls for extra care, and disabling the warning light on smart glasses can make the filming more offensive.
  • regarding the filming with smart glasses without consent while someone can request that the filming cease, the act may not be illegal.  In some situations, this could lead to criminal offenses, particularly if shared online under the New Zealand Harmful Digital Communications Act
  • care should be taken against assuming that all smart glasses users are acting improperly.  There can be legitimate use in assisting the visually impaired.
  • organisations providing smart glasses must adhere to the Privacy Act.  Personal information must be collected only for lawful business purposes.
  • companies should adopt policies to prevent misuse and insisted on transparency in data collection in line with privacy principles.  Employers should establish workplace policies on appropriate use.

The Greens have called for banning “pervert glasses” in a hyperbolic reaction. That is not practical. Today Tanya Plibersek, a Government Minister, said the Federal Government is considering a moritorium on the import of smart glasses. That is a very short term problem to a larger problem of surveillance and protection of privacy.

On the same day the Commonwealth Attorney General writes to the Privacy Commissioner she posts a blog titled Surveillance wearables – are we through the looking glass(es)? It is a very general Read the rest of this entry »

Tik Tok settles with US Department of Justice for child privacy breaches in the sum of US $400 million (Aus $559 million).

August 26, 2026

There is a commonly held view that the United States has poor privacy protections.  As a bald statement that is not correct.  Better put, it is more complicated than that. It is more accurate to say that legal privacy protections are very good in certain sectors and for certain types of information and quite poor in more general environments.  Often the 4th amendment, protecting freedom of speech, restricts privacy protections.  But there are specific laws protecting health records and child privacy which are as strong as any commensurate laws in other jurisdictions. There is no dedicted children’s privacy protection legislation however there will be a Code that is currently being developed.

The Department of Justice has announced a settlement with Tik Tok and affiliated entities for breaching the Children’s Online Privacy Protection Act (“COPPA”).  The breaches relate to the collection of children’s personal information.   The ABC has covered the story in TikTok to pay $559m in ‘one of the largest’ child privacy settlements.

The Department of Justice Statement  provides:

Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA). Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.” Read the rest of this entry »

Quest suffers data breach on 17 August 2026 and promptly advises customers. Sometimes businesses do the right thing.

August 25, 2026

Australian businesses are a long way behind their counterparts in the United States, the UK and the European Union in responding to data breaches.  Australian companies wait until the last possible moment to announce a data breach.  Often the announcement is made after the breach is publicised, by the hacker, the media or a customer.  When public statements are made they are commonly a series of boilerplate phrases cobbled together with very little information as to what happened and the potential exposure.  Statements like “working with the Australian Signals Directorate” and “notified in the Office of the Information Commissioner” and “contacted the Australian Federal Police”.  All designed the throw the proverbial blanket over the event.

But there are limited exceptions.  Quest suffered a data breach and was quite prompt in notifying customers by email.  It is reported by the ABC in Quest Apartment Hotels customers’ personal data exposed in security breach.  Quest couldn’t resist telling customers that it had contacted the Office of the Information Commissioner (as it is required to do by law so that is not an especially notable thing) and the Australian Cyber Security Centre.  It was shy about the scope of the attack, of which it probably has good knowledge.  Imperfect but a long way ahead of many Australian businesses.

The ABC article provides:

Quest Apartment Hotels says it is investigating a security breach that has affected customers’ personal data.

In an email to customers, seen by ABC News, Quest said the compromised data related to records from before June 2025 and included full names, email addresses and other contact details.

A small number of data entries also include customers’ date of birth.

“On Monday, 17 August 2026, we identified unauthorised access to a database system arising from a vulnerability through a third-party service provider,” a statement read.

“We immediately took steps to contain the incident and secure the affected systems. The incident has been contained.”

The company said it had notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.

“We are very sorry this has happened and for any concern it may cause. Protecting the privacy and security of our customers is extremely important to us,” David Mansfield, managing director for Australasia at The Ascott Limited, said in the email to customers.

“We will contact you if our investigation identifies any further information that is relevant to you or if there are any additional steps you need to take.”

The company warned people not to click on unexpected links or to open attachments, even if they came from the hotel.  Read the rest of this entry »

Quantum computing will soon be here and ubiquitous. It will have a huge impact on data security and privacy generally. Time to prepare now.

August 15, 2026

The Economist has a very timely article on quantum computers with It is past time to upgrade to post-quantum encryption.  Quantum computing will render much of modern encryption vulnerable.  Through quantum computing it would be possible to unlock encrypted data in minutes when current computers would take tens to hundreds of years.  Given that encryption is a key means of securing data when it is transferred and stored digitally that could render those protections obselete. Quantum computing can also  be used to test and breach cyber defences.  Coding errors and zero day vulnerabilities would be easier to detect.  The UK Information Commissioner’s office published a useful article on Quantum computing in 2024 and piece on Quantum computers in ICO tech futures.  I have written about quantum computing and its impact on data security, most recently on 16 July.

The Economist article sounds the alarm.  Whether businesses will respond is another question.  Businesses currently don’t do enough to protect their customers’ privacy.  Quantum computing will Read the rest of this entry »

Nick Scali hit by ransomware and reportedly engaging with hacker through an intermediary

August 14, 2026

In Australia, it is not illegal to pay a ransome to a hacker. It is illegal not to advise the Government that a ransom has been paid. The process of when and how to report is set out in the Cyber Security Act 2024 (the “CS Act”). Consistent with the Privacy Act 1988 the CS Act only commercial entities operating in Australia with an annual turnover of AUD $3 million or more are covered.  As with the Privacy Act there are specific inclusions, in this case critical infrastructure operators. 

Under the Act 

 
  • it must report the amount demanded, the amount paid, the type of malware used, and details of any communications with the hackers. 

Notwithstanding that payment of a ransom is not criminalised the Government has always maintained a “Never Pay” position.  It claims, with some justification that paying a ransom does not guarantee a return of data.  That is true.  There is a real possibility of hackers not returning the data, or only part of it.  Or they copy it before they return it.  What is more common is that in providing the key to unlock the ransomware data is often corrupted, to a greater or lesser degree. 

Some businesses do pay ransoms and do not notify the Government.  How many is not known for obvious reasons.  But it does happen. 

The Australian reports in Nick Scali hires intermediary to deal with hacker, ransom threat that the company has suffered a ransomware attack that has disrupted its warehouse and dispatching functions.  It has engaged a middleman to negotiate with the hacker to “defuse the attack.”  That generally means, “how much”, “by what crypto coin” and “where to be delivered”.  It is also is

Interestingly customer names and financial details were not accessed, only delivery details.  Which is bad enough.  That is unusual in the normal course.  Unless the security of credit card and personal information was properly protected.  Or that the delivery system is a separate system, possibly run by a third party or a subsidiary of Nick Scalli.  It is often hard to find out exactly what happened because Australian entities are notoriously unforthcoming about the circumstances of an attack.    

The article provides:

An organised gang of cyber criminals have obtained customer details from furniture chain Nick Scali, including residential addresses, after the retailer confessed to being the victim of a security breach.

The cyber criminals, believed to be based offshore, have also sent a ransom request to Nick Scali, but at this stage, it is unknown the precise financial demand.

The cyber security incident has thrown the warehouse and dispatching functions of the $1.43bn Nick Scali network into mayhem with the delivery of furniture orders to customers now delayed. The shutdown of the Nick Scali IT system has meant orders must be processed manually.

Nick Scali has employed an unknown firm, or middleman, to directly communicate with the hackers to defuse the attack. While it is believed sensitive customer data such as credit cards were not obtained by the hackers, they are believed to have gained access to the property addresses where furniture was to be sent, according to a company insider’s account on Thursday morning.

Late on Thursday, Nick Scali confessed to the ASX it is currently investigating a “security incident”. “In light of the security incident, the company elected to take certain systems offline. While we appreciate that this may have caused some delays for, and uncertainty with, customers, we are now in the process of bringing those systems back online,” its ASX statement read.

“We note that the company is continuing to complete sales orders and deliveries. However, our response times to customers are currently slower than normal.”

Nick Scali, whose executive chairman and major shareholder is Anthony Scali, said at this time, the retailer did not have any evidence of unauthorised access using the customer data.

“Our customers remain our key priority.”

Nick Scali has notified the Australian Cyber Security Centre and the Australian Federal Police. “The company will provide further updates as appropriate.”

 

Origin now admits to cyber breach affect 900,000 after “initial review”. The dreadful response to this data breach continues

July 28, 2026

In my experience organisations that do not have a data breach response plan, which they test and rehearse, suffer for it when there is a data breach.  Those organisations  commonly resist engaging with the community, media or even government.  That may suit some businesses but does not help when dealing with a data breach, where controlled transparency is a positive trait.  If Origin had a data breach response plan it probably has it locked away in a safe and the board of directors have forgotten the combination.

A good data breach response plan has a list of tasks that need to be attended to and a a specified group of people who have specific tasks to do.  It should also have contact details of experts to contact; technical, media, legal, human resources.  There needs to be as much done in the first 24 hours as possible to set up a coherent response.

Origin’s response to this data breach has been uniformly dreadful.  It’s initial response came when it was told there was a data breach.  Then it was incredibly cagey and defensive.  Then it was vague.  Then there was a partial admission without identifying how many customers were affected.  And today it provides an initial review, whatever that means, which identifies 900,000 customers, and former customers, affected.  Could be as high as 20% of the customers.  That is bound to be an understatement.  What is difficult to square is why it is taking so long to get a good idea of the scope of the attack. As Origin says, it was aware of a “potential security threat” since early July and then on 22 July some new information indicated a “potential security incident“.   It is so vague as to be meaningless.  So there was no breach in early July? Or was there?  If the threat was identified what was done so as to avoid an incident?  Sometimes organisations think it is clever by to use vague terminology to say nothing but claim they are saying something.  It rarely works as well as they think it might.  Here it falls at the first hurdle.  It makes little sense and begs more questions than it answers.  Origin’s problems have been compounded by the fact that the hacker has engaged with the media, specifically the Australian.  That happens occasionally but can be managed as well.  Origin has not managed that side of things well either.

Something very odd is going on at Origin.

Today’s Origin statement Read the rest of this entry »

Origin energy data breach…a salutory lesson ofwhat happens when you don’t respond quickly, candidly and coherently from the outset

July 27, 2026

The Origin energy data breach has been handled very badly by Origin to date.  That is not to say it has not been trying harder.  Often how an organisation responds in the first few days of a data breach sets the tone. That is certainly the experience in the United States.  Here the culture is less attuned to having a data breach recovery plan and there is less effort in wargaming what would happen if there is a data breach.

Origin put out a statement on Thursday which said not much of anything:

Origin Energy Limited (Origin) provides the following update on its data security incident.  

Origin can confirm there has been unauthorised access and disclosure of some customers’ data. 

We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.  

For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts. 

Origin CEO Frank Calabria said, “I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause. 

“We are contacting affected customers, offering support and have set up a dedicated contact number and additional resources to help manage our response to this incident. 

“One of our key priorities is taking action to secure our systems and ensure no further unauthorised access. We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities,” Mr Calabria said. 

Origin continues to engage with Australian Government agencies, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. 

It now admits there was a data breach rather than a “potential security incident” and says names, addresses, dates of birth, contact phone numbers and account information being leaked and the incomplete portions of credit cards and bank details were affected.  The rest is a word salad of platitudes and the usual boilerplate of working with government agencies. It is a sub par statement.

Meanwhile the media has filled in the gaps Origin can’t or won’t and speculates.  Cyber security Insiders reports with Origin Energy Sector Data Breach Widens to 5 Million Customers the flaws in Read the rest of this entry »

Origin cyber attack, hugely embarrassing and poorly managed

July 23, 2026

Utilities and telcos are prime targets of cyber attack.  The number of unsuccessful attacks are rarely publicised.  The successful attacks which involve access to large amounts of data are well publicised.  As the recent attack on Origin energy proves.  Not surprising given the hacker claims to have accessed records of 2 million customers.  It has been reported by the ABCNineNews.com, cyber daily and others.  Origin has sort of confirmed there was a data breach and has released a wholly inadequate statement which it describes as a potential customer data breach.  A dreadful approach.  Saying less than very little and leaving customers wondering. if not anxious, about what happened to their personal information.  Its attempt at minimising concern is to say that it didn’t believe bank records or credit card details were stolen.  Even then it was very qualified.  Even if it did not know the full scope of the data breach it could have provided a better response.  There is now a skill on how to respond.  Which Origin does not possess.

What is very disappointing, more than its non statement statement, is that Origin Energy was made aware of the cyber attack almost three weeks ago.  By the hacker.  And to make matters worse the hacker contacted the Australian 2 days ago.  Origin gave the impression then that no data had been stolen.  So the next day the hacker provided a sample of 50 customer records to the Australian.  The immediate reaction from Origin was dreadful.  The fact that Origin contacted the ASX after being notified by the media bespeaks a serious problem with Origin’s data breach response plan.  If such a plan existed.  If it existed then the likely explanation was that Origin adopted a low profile and hoped it would all go away.  An attitude some companies still take and a product of long standing poor regulation in the past and even worse enforcement until recently. The situation got worse for Origin today when the hacker told the Australian that Origin sacked an employee after accusing him or her of being behind the data breach (even though the hacker used his credentials), that the hacker had contacted Origin two weeks ago and that the means of ingress was through an employee’s authorisation. In other words the hacker has taken control of the story.  The worst place Origin could be.  And totally avoidable if it had been on top of the facts from the start.  The Australian has skewered Origin’s earlier claims to have a dedicated cyber risk team and various levels of governance such as The Board Audit and the Risk Committee. As the facts tumble out, to the media via a well motivated hacker Origin’s claims are being made to look very foolish.

Large corporations which hold vast amounts of personal information, such as Origin, should have a multi layered cyber defence.  That includes programs that detect unusual activity, such as the exfiltration of data.  They should also have rigorous third party access controls and monitoring of the use of authorisations.

The ABC article provides:

Origin Energy says it is investigating a security breach that “may have” affected customer data.

“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data,” it said in a statement.

“We do not believe the impacted data includes customer credit card or bank details.

“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.

“Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate.” Read the rest of this entry »