Spanish Data Protection Agency identifies first reported data breach carried out by an AI agent.

September 16, 2026

The potential of AI to be used to effect a data breach has been well known for some time.  Now the Spanish data protection agency has identified a data breach caused by a large language model identifying vulnerabilities and then gaining access to a system.   When inside the AI agent modified personal data and acccess invoices.  This has been long expected.  It does not mean that cyber defences are now useless.  It does mean that care should be taken to look at vulnerabilities, patch as soon as advised that upgrades are required and have a multi layered defence.  AI is not a magic bullet.  It is a means by which vulnerabilities can be identified quickly and exploited.  It does create vulnerabilities.

The Reuters article on this development provides:

MADRID, Sept 15 (Reuters) – Spain’s data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case that suggests autonomous ?systems are beginning to play a direct role in cyberattacks.
The Spanish Data Protection Agency (AEPD) ?said on Monday in a blog on its website that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system and subsequently modify personal data and access ?invoices.

Read the rest of this entry »

SA Health data breach over employee accessing Tony Modra’s medical records. Highlights the generally poor record of the health sector in maintaining data security

September 15, 2026

The Health sector consistently tops the list of sectors that suffer the most data breaches.  Some of those data breaches have been very large and public, ransomware attacks affecting thousands of patients, and others more isolated, staff accessing records they are not authorised to view.  All data breaches are serious.  The ABC reports that a South Australian health employee has been reprimanded for accessing Tony Modra’s health records. Modra is a former South Australian AFL player.  In South Australia that is a very big deal.  So is accessing his data without lawful excuse.

The story was first reported on 24 July 2026. That story also highlighted SA Health’s previous problems with data security with staff accessing medical records in 2016 and 2024.  Both previous occasions the access related to notorious cases.

South Australia has no privacy legislation.  The only state without legislation.  it regulates through a Cabinet Administrative Instruction titled Information Privacy Principles Instruction, Premier and Cabinet Circular 12t.  That is binding on South Australian state government agencies and the public sector. Complaints have to be made to the Privacy Committee of South Australia.  It is a wholly ineffective process.  It has no enforcement powers.  

A reprimand for a breach of this nature is inadequate.

This is a case where Modra may have a claim under the Commonwealth’s statutory tort of serious invasion of privacy.  The act was a misuse of private information and it was intentional.  There was also a reasonable expectation of privacy.  There is a 12 month limitation period which must always be borne in mind in cases of this nature.

The article provides:

One SA Health employee has been reprimanded for accessing AFL legend Tony Modra’s private medical records after he was seriously injured in a truck crash, while two other employees remain under investigation, the health department says.

In a statement, SA Health said another six people were no longer being investigated.

“The number of employees under investigation for potentially accessing a patient’s medical record inappropriately has been revised from nine individuals, to three,” the statement said.

“Of these three, one individual has been reprimanded and two are still being investigated.

“Six individuals are no longer under investigation for this matter.”

Any sanction imposed becomes part of an employee’s permanent record. Read the rest of this entry »

Misuse of CCTV surveillance highlights privacy breach potential of the technology

September 14, 2026

The Victorian Police Force has a dreadful record when it comes to privacy.  Officers have misused the LEAP databases on multiple occasions (that we are aware of).  See my posts here.  They breached Dani Laidley’s privacy by taking pictures inside a police station.  See my posts here. It is a cultural problem that has not been properly, if at all, addressed over many years.

The latest privacy breach involving a member of the Victoria Police, Sam Hansen, using CCTV to monitor his partner, if that is the right descriptor.  Hansen received a diversion.  Given the nature of the offence and the breach of trust that is a good result for him but questionable as to whether it is the appropriate penalty.

There are also the civil issues.  Victoria Police use of surveillance, CCTV and personal data acquired from its use is covered by the Information Privacy Principles (IPPs) under the Privacy and Data Protection Act 2014.  There is an exemption  under Section 15 which permits non-compliance for legitimate law enforcement, criminal investigations, or covert surveillance functions. The Victorian Civil and Administrative Tribunal (VCAT) has jurisdiction regarding breach of the Act.  

It is very disappointing that VCAT’s decisions over the years have meant that recourse under the Privacy and Data Protection Act 2014 is difficult at the best of times.  VCAT has a very poor reputation in handling privacy cases and where claimants are successful, not often, the awards are miserly. Whenever possible it would be better to use Schedule 2 of the Privacy Act 1988, the statutory tort of serious invasion of privacy.

While all the facts in this case are not known what is known indicate there is a basis for bringing an action under this new tort.  The acts of Hansen were intentional.  Just because the CCTV may have been used in a public place that does not negate a person’s reasonable expectation of privacy and the harm is serious.  It is hard to Read the rest of this entry »

Another Council looks to ban smart glasses on its premises. This time Yarra Council wants to ban smart glasses from pools, gyms, playgrounds and childcare centres. Big statement, enforcement will be interesting

September 9, 2026

Last night Yarra Council passed a motion to “investigate” banning smart glasses at Council leisure centres, childcare centres and playgrounds.

Such a broad ban with carve outs for people with low vision or other disabilities would be difficult to enforce. Ray ban style glasses are quite common and while smart glasses can be distinguished from other sun glasses that requires a council officer coming quite close.

The motion that was passed by Councillor Wade is that Council:

  1. Obtain a report before the end of this calendar year on: (a). Updating Council’s conditions of entry and other policies to ban the use of smart glasses” at Council’s leisure centres and all council – run childcare centres and playgrounds, subject to any necessary carve outs for deaf, law vision or disabled users; and 

    (b)   communicating this change in policy to users and relevant stakeholders, including installing signage as necessary.

  2. Advocate to the federal government for updates to the Privacy Act to ensure it is fit for purpose and able to respond to the risks of new wearable technology, and for a temporary ban on smart glasses imports, until Australia’s privacy and data collection laws are updated to better protect our communities.

While the Council motion is correct about the Privacy Act requiring more reform there is still scope to bring an action for the tort of serious invasion of privacy through the use of such glasses in certain situations.  Such glasses act in an indentical way as a camera or video, which can be misused.

The Yarra Council statement provides:

Last night, Council endorsed a motion to investigate banning smart glasses at Council leisure centres, childcare centres and playgrounds.

Yarra City Council Mayor Cr Stephen Jolly says smart glasses are a rapidly evolving technology, and it is council’s responsibility to protect the community’s privacy in all council-run spaces.

“Our spaces need to be safe and respectful – especially for the more vulnerable members of our community,” he says.

“This is about protecting people’s privacy, particularly in places where children and families come together,” the Mayor says.

Council resolved to investigate this further, with carve outs for people living with disability who may need this technology to go about their daily lives.

Council will also call on the federal government to bring in stronger privacy laws to further protect people from these new technologies.

The ABC report, Yarra council bans smart glasses from pools, gyms, playgrounds and childcare centres, exaggerates what the motion actually states.  There is no ban as such.  There will be an investigation into a ban.  The ABC sought quotes from participants Read the rest of this entry »

More than one million people affected by data breach of Mathspace in Australia and New Zealand. While the data breach is serious Mathspace announcement is excellent and provides real information to customers rather than the usual boilerplate organisations often adopt

Any online service needs to give priority to security.  That is all the more important for health and educational services.  Mathspace is an online service. Unfortunately   Mathspace has suffered a significant data breach.  More than a million people have been affected, including students and staff.   The source of the breach is a vulnerability in the system which was identified and a patch was issued on 6 August 2026   The hackers took advantage of the vulnerability on 10 August 2026.  Mathspace installed the patch on 29 August 2026 when prompted by the program’s creater.  Data was exfiltrated on 27 August 2026.

The key lesson here is that every patch and update an organisation receives needs to be installed as soon as possible after receiving it.  Sometimes that is automatically done, but it needs to be checked.  That is a process issue.

Yesterday the Mathspace announced the data breach on 3 September 2026. The announcement is very good.  It sets out what happened, how many people have been affected and what is being done.  It delves Read the rest of this entry »

Smart glasses not going to be banned or moritorium on their import.

August 31, 2026

The dystopian effects of using smart glasses have been grist for the political mill.  Smart glasses have been called pervert glasses by the Greens who want them banned.  The Government equivocated over the weekend and came out today, through the Attorney General Michelle Rowland, saying that there are no current plans to impose an import ban on smart glasses.  Presumably that means no ban on their use either.

The Government has introduced the ID Lock which will enable people to block or unblock the use of identify documents through the Document Verification Service.  The Attorney General’s media statement provides:

The Albanese Government is strengthening Australia’s identity protection framework with the introduction of IDLock, a new digital identity protection service designed to give Australians direct control over how their identity documents are used for verification.

The new service will be available securely through myGov next year and will enable Australians to block, unblock and monitor the use of eligible identity documents through the Document Verification Service at any time. This will help Australians protect themselves from identity crime, scams and the impacts of data breaches before harm occurs.

IDLock is being developed as a new way for people to access the protections of the Credential Protection Register. Established by the Commonwealth in 2022, the register helps prevent compromised identity documents from being used to fraudulently establish an individual’s identity.

Since late 2022, the register has blocked over 830,000 fraudulent identity verification attempts, averaging around 18,000 each month. This demonstrates the important role the register plays in protecting Australians when their identity credentials have been compromised.

IDLock will be released initially to a small cohort of users for early access and testing later this year, ahead of a broader national rollout in 2027.

Visit the IDMatch website for more information about identity verification services, or the IDCARE website for tailored support and assistance with regard to scams, identity theft and cyber threats.

Quotes attributable to the Attorney-General, Hon Michelle Rowland MP:

“Australians deserve to have control over how their personal identity information, such as their driver licence or passport, is used to verify their identity online. 

“As data breaches, scams and cyber-enabled crime continue to evolve, Australia’s approach must evolve with them.

“With the launch of IDLock, our Government is taking the next step towards a stronger, more robust identity verification framework that expands the focus from responding after identity credentials have been compromised, to enabling Australians to protect themselves before identity crime occurs.

“Whether their driver licence details have been exposed in a data breach or they are concerned about scams and identity theft, IDLock will give Australians an accessible and simple way to have greater visibility, control and confidence in how their identity documents are used.”

  The ABC report Read the rest of this entry »

Commonwealth Government releases 2nd tranche of reforms to the Privacy Act 1988

Today the Attorney General released an Exposure Draft of the Privacy Amendment (Personal Data Protection) bill 2026 and a Consultation Paper.  The Government has set a very narrow window for submissions, a little under 3 weeks.  Consultations close on 18 September 2026.

The Bill focuses on tightening definitions and providing more specific Australian Privacy Principles in certain areas, such as direct marketing and data security.  It also strengthens the obligations under the Data Breach Notification provisions which were not very effective.

The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying consultation paper contains around 40 proposals.  Some are taken from the Attorney General’s Privacy Act Review Report (2023). Other proposals are framed to to address emerging technologies.

Interestingly the consultation  seeks views on emerging technologies such as smart glasses and connected vehicles.

Under the proposed amendments the attempt is to:

  • increase accountability across the personal information lifecycle
  • impose stronger data security obligations
  • impose data minimisation
  • have a more effective data breach response structure including notifying the Privacy Commissioner within 72 hours
  • impose a simplified principles-based framework for handling personal information,
  • impose a more coherent consent obligations
  • impose stricter requirements for direct marketing regime.
  • a right to erasure for personal information held by large digital platforms

The Bill does not give individuals any greater rights to take action to protect their privacy.

It is a very technocratic Bill and a very small step in the long process of privacy reform.  In that regard it is disappointing.

There is a very long way to go.

The Attorney General’s media statement Read the rest of this entry »

Regulatory crackdown on smart glasses use at the Council level, lots of correspondence at the Federal Level. The situation is not satisfactory however there are already causes of action to deal with invasions of privacy

August 30, 2026

It is well established that individuals have actionable claims for breach of privacy, in the form of misuse of private information, for photographs or videos taken in public.  The two significant cases are Campbell v MGM Ltd [2004] UKHL 22 and Murray v Big Pictures [2008] EWCA 446. Campbell’s case involved MGN photographing Naomi Campbell on a street leaving a Narcotics Anonymous Meeting.  In Murray the young child of J K Rowlings was photographed in a pram in Edinburgh.  The leading New Zealand case of Hosking v Runting [2003] 3 NZLR 385 which formally recognised a stand alone tort of privacy involved publication of private information, involved Runting photographing the Hoskings’ 18-month-old twin daughters in a public shopping street in Auckland without the mother’s knowledge or consent.

The Victorian Court of Appeal decision of  Giller v Procopets (2008) 24 VR 1 recognised the equitable cause of action of misuse of private information and cited with approval the Campbell and others.  The Court also found that damages for emotional distress could be awarded for such a breach of confidence.

The Brisbane City Council has banned the “non consensual” use of AI smart glasses.  use of smart glasses.  Actually it is more expansive, being a blanket ban on all camera enabled devices including wearable technology, phones and action cameras.  Patrons can bring smart glasses into the pool.  They just can’t be used to film without permission.  This is a policy that will be quite difficult to effectively enforce.

On 7 August 2026 the Commonwealth Attorney General wrote to the Privacy Commissioner about the privacy implications of the use of smart glasses.  On 28 August The New Zealand Privacy Commissioner has already issued a statement, almost a guidance, on the use of smart glasses stating:

  • because the devices look like ordinary eyewear, people can covertly film others, making it harder for those being filmed to object.
  • the Commissioner’s concerns would grow if manufacturers integrate facial recognition technology into smart glasses in the future
  • there is uncertainty around how companies collect, use, and store the data these devices gather.
  • that people who use smart glasses in a personal capacity should tell people they are recording, even though most smart glasses flash a light while recording.
  • while the New Zealand Privacy Act permits individuals to collect and use personal information for personal or domestic purposes providing that use, or sharing does not become highly offensive. Factors relevant in determining whether the filming highly offensive, include:
    • how the information is filmed;

    • how sensitive it is; and

    • how vulnerable the person being filmed is.

  •  filming children, or capturing someone’s health or mental state, calls for extra care, and disabling the warning light on smart glasses can make the filming more offensive.
  • regarding the filming with smart glasses without consent while someone can request that the filming cease, the act may not be illegal.  In some situations, this could lead to criminal offenses, particularly if shared online under the New Zealand Harmful Digital Communications Act
  • care should be taken against assuming that all smart glasses users are acting improperly.  There can be legitimate use in assisting the visually impaired.
  • organisations providing smart glasses must adhere to the Privacy Act.  Personal information must be collected only for lawful business purposes.
  • companies should adopt policies to prevent misuse and insisted on transparency in data collection in line with privacy principles.  Employers should establish workplace policies on appropriate use.

The Greens have called for banning “pervert glasses” in a hyperbolic reaction. That is not practical. Today Tanya Plibersek, a Government Minister, said the Federal Government is considering a moritorium on the import of smart glasses. That is a very short term problem to a larger problem of surveillance and protection of privacy.

On the same day the Commonwealth Attorney General writes to the Privacy Commissioner she posts a blog titled Surveillance wearables – are we through the looking glass(es)? It is a very general Read the rest of this entry »

Tik Tok settles with US Department of Justice for child privacy breaches in the sum of US $400 million (Aus $559 million).

August 26, 2026

There is a commonly held view that the United States has poor privacy protections.  As a bald statement that is not correct.  Better put, it is more complicated than that. It is more accurate to say that legal privacy protections are very good in certain sectors and for certain types of information and quite poor in more general environments.  Often the 4th amendment, protecting freedom of speech, restricts privacy protections.  But there are specific laws protecting health records and child privacy which are as strong as any commensurate laws in other jurisdictions. There is no dedicted children’s privacy protection legislation however there will be a Code that is currently being developed.

The Department of Justice has announced a settlement with Tik Tok and affiliated entities for breaching the Children’s Online Privacy Protection Act (“COPPA”).  The breaches relate to the collection of children’s personal information.   The ABC has covered the story in TikTok to pay $559m in ‘one of the largest’ child privacy settlements.

The Department of Justice Statement  provides:

Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA). Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.” Read the rest of this entry »

Quest suffers data breach on 17 August 2026 and promptly advises customers. Sometimes businesses do the right thing.

August 25, 2026

Australian businesses are a long way behind their counterparts in the United States, the UK and the European Union in responding to data breaches.  Australian companies wait until the last possible moment to announce a data breach.  Often the announcement is made after the breach is publicised, by the hacker, the media or a customer.  When public statements are made they are commonly a series of boilerplate phrases cobbled together with very little information as to what happened and the potential exposure.  Statements like “working with the Australian Signals Directorate” and “notified in the Office of the Information Commissioner” and “contacted the Australian Federal Police”.  All designed the throw the proverbial blanket over the event.

But there are limited exceptions.  Quest suffered a data breach and was quite prompt in notifying customers by email.  It is reported by the ABC in Quest Apartment Hotels customers’ personal data exposed in security breach.  Quest couldn’t resist telling customers that it had contacted the Office of the Information Commissioner (as it is required to do by law so that is not an especially notable thing) and the Australian Cyber Security Centre.  It was shy about the scope of the attack, of which it probably has good knowledge.  Imperfect but a long way ahead of many Australian businesses.

The ABC article provides:

Quest Apartment Hotels says it is investigating a security breach that has affected customers’ personal data.

In an email to customers, seen by ABC News, Quest said the compromised data related to records from before June 2025 and included full names, email addresses and other contact details.

A small number of data entries also include customers’ date of birth.

“On Monday, 17 August 2026, we identified unauthorised access to a database system arising from a vulnerability through a third-party service provider,” a statement read.

“We immediately took steps to contain the incident and secure the affected systems. The incident has been contained.”

The company said it had notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.

“We are very sorry this has happened and for any concern it may cause. Protecting the privacy and security of our customers is extremely important to us,” David Mansfield, managing director for Australasia at The Ascott Limited, said in the email to customers.

“We will contact you if our investigation identifies any further information that is relevant to you or if there are any additional steps you need to take.”

The company warned people not to click on unexpected links or to open attachments, even if they came from the hotel.  Read the rest of this entry »