May 7, 2018
The overhaul/replacement of the UK’s Data Protection Act so as to be compliant with the incoming General Data Protection Regulation (GDPR) will result in increased powers of the Information Commissioner designed to deal quickly with urgent situations, known as urgent information notices from 7 days to 24 hours and empower the information commissioner to obtain a court order to require disclosure of the information referred to in the notice where there has been a failure to comply. There will also be a new offence which would criminalise the destruction, disposal, concealment, blocking or falsification of information and documents the subject of a formal request by the information commissioner.
When enacted the new look Data Protection Act will be an even more superior piece of regulation to the Australian Privacy Act 1988. More to the point the UK Information Commissioner has proven to be an effective regulator, using the powers available to her. In Australia the Information Commissioner has been careful not to use his enforcement powers and Read the rest of this entry »
Posted in Privacy
|
Post a comment »
May 6, 2018
As is the way of it big data breaches there has been a ripple effect with the Commonwealth Bank’s data breach of losing track of records affecting 12 million customers and 20 million accounts. The banks initial “not much to see here” explanation on its home page has morphed into a sort of acceptance, via comment to the media, that it should have come clean earlier. Which is in and of itself a misrepresentation. It never actually came clean with the public. The breach was exposed and only then did it state that it had advised the Information Commissioner. That is not coming clean. The CBA is now notifying affected customers. Two years after the event.
The CBA’s explanation has been the rightly subject of criticism. Typical of that criticism, and that of the regulators, is the Read the rest of this entry »
Posted in Privacy
|
Post a comment »
The UK Information Commissioner’s Office (the ICO) produces excellent guides relating to UK and EU laws. They are much clearer, specific and, therefore, useful than the guidances produced by the Australian Information Commissioner. Given the legislation and regulations in this area of the law is principles based having good guidances is critical.
The ICO has produces its Guide to the General Data Protection Regulation (GDPR). A 171 page tome on all matters relating to compliance with the GDPR. The GDPR is about to take effect in Europe, on 25 May 2018 to be precise. It’s impact will range farther than the borders of the European Union. Even Mark Zuckerberg in his much vaunted testimony to Congress in April said Facebook would, eventually, comply with the GDPR.
The GDPR differs from the Australian Privacy Principles. It is much more comprehensive. However that does not mean that they are not relevant for Australian practitioners. Companies with a significant presence in the EU will need to be aware of the GDPR requirements. At the local level Read the rest of this entry »
Posted in Privacy, UK Information Commissioner's Office
|
Post a comment »
May 4, 2018
Today’s story in the Age of a video footage of Dane Swan, former AFL player, being circulated on line highlights the total inadequacy of Australia’s privacy protections. Governments have been keen to criminalise the acts of distributing intimate videos and pictures on line without the consent of the subject of those images but have been totally unwilling to give individuals a civil right to take action of their own volition for such breaches. In short, it comes down to the police having to carry the load totally when an individual may wish to also exercise their right. Governments have been virtue signallers at best. Yes criminalise the conduct but provide proper privacy protection through a statutory tort of invasion of privacy.
The problem with the half measure that exists is Read the rest of this entry »
Posted in Privacy
|
Post a comment »
May 3, 2018
The Commonwealth Bank of Australia has suffered a major data breach involving the records of 20 million customers. In 2016. It has only made this public now after media reports. The CBA only made a statement after the media reports. That is a dreadful approach to data breaches. Conceal until you can’t. Then obfuscate. The CBA is not an outlier in its reaction to this data breach. Unfortunately it is all too common in Australia. Perhaps that will change with the mandatory data breach notification scheme but proper enforcement is required. Incredibly the Information Commissioner was notified in 2016. And took no enforcement action. No enforceable undertakings even. That was, and remains, a dreadful mistake. The Australian Prudential Regulation Authority that has been more active and transparent than the Information Commissioner’s Office in dealing with privacy breaches. If that is not an indictment on the Information Commissioner Read the rest of this entry »
Posted in Commonwealth Privacy Commissioner, Privacy
|
Post a comment »
May 2, 2018
Law firms are a key target of hackers. That has been known for some time. Lawyers hold sensitive client information which has value to competitors and criminals. They also hold personal information which can be used for identity theft. Finally they control bank accounts that hold signfiicant sums, such as proceeds of sales and purchases, client money held in trust and payments made to the lawyers but not distributed. Law firms are also key targets because they are generally inept at data security.
The consequences can be catastrophic as the closure of the Panamanian firm Mossack Fonseca on 15 March 2018 after the release of the Panama Papers. A leading offshore Bermuda based law firm, Appleby suffered a data breach in October last year. In April last year a Providence law firm was hit with a ransomware attack which resulted in lost billings of $700,000. The American Bar Association noted that in 2015, approximately one quarter of all U.S. law firms with 100 or more lawyers had experienced a data breach through hacker or website attacks, break-ins, or lost or stolen computers or phones and 15 percent of all law firms overall, regardless of size, had reported an unauthorized intrusion into the firm’s computer files, up from 10 percent in 2012. In a report last year LogicForce found that law firms were in the main woefully unprepared with Read the rest of this entry »
Posted in Privacy
|
Post a comment »
Justice Kennedy in In the Matter of Innovateq Pty Ltd [2018] VSC 124 considered an application under section 237 of the Corporations Act for leave to commence proceedings in a derivative action. Judgments regarding leave applications are relatively uncommon.
FACTS
The proceeding involved two applications:
- leave to the plaintiff pursuant to s 237 of the Corporations Act 2001 (Cth) (Act) to commence court proceedings in the name of Innovateq Pty Ltd (ACN 132 372 242) (Company) against Mr Daniel Phillips (a former employee) and two companies associated with him, Certeq Pty Ltd and Certeq NZ Pty Ltd (Certeq) (Leave Application); and
- for an order that the Company be wound up (Winding Up Application).
The Company, in its capacity as trustee for the Read the rest of this entry »
Posted in Commonwealth Legislation, Corporations Law, Insolvency, Supreme Court of Victoria
|
Post a comment »