Von Hannover v Germany (no 3) in the European Court of Human Rights. Von Hannover loses her Article 8 complaint.

September 23, 2013

The European Court of Human Rights handed down its chamber judgment on 19 September 2013 regarding a complaint by Princess Caroline von Hannover under Article 8 of the European Convention on Human Rights. The Court found there was no breach of Article 8.

The decision is only available in French.  The press release is found here.

The photographs the subject of the dispute, taken in 2002, showed the Princess and her husband on holiday  of her holiday home  off the coast of Kenya. The Court essentially reiterated the criteria for balancing privacy and freedom of expression found  in Von Hannover (No 2) involving  consideration of:

  1.  The subject of the report and its contribution to a debate of general interest
  2. The content and form of publication
  3. The circumstances Read the rest of this entry »

New Zealand Privacy Commissioner case notes

The amendments to the Privacy Act 1988 (Cth) take effect on 12 March 2014.  The Privacy Commissioner will then have significant powers to conduct own motion investigations and institute civil penalty proceedings in the Federal Court.  The Guidelines being developed by the Privacy Commisioner’s office will no doubt be persuasive.   Guidelines are not binding rules (but with a few notable exceptions, see section 16B.  That has been made clear with the amendments (see section 6(3).   The Privacy Commissioner will develop guidelines which will establish the criteria on which a decision to pursue a civil penalty will be made.  But it will be the Federal Court which will be considering the meaning of words, the scope and operation of privacy policies and codes and the operation of the APPs.  The jurisprudence in Australia in the privacy law area is quite sparse.  Not surprising given the relative ineffectiveness of the legislation.  That may change with the new powers available to the Privacy Commissioner.  It will be prudent to consider how other jurisdictions have approached privacy issues and have developed their jurisprudence.  Obviously they may be of use and even persuasive but definitely not binding.

In that vein it is relevant to have regard to the case notes recently published by the New Zealand Privacy Commissioners.  They are found here.

Case Note 235239 [2013] NZ PrivCmr 1 : Dealing with child’s health information when parents are separated

FACTS

A mother  requested her child’s health information from a medical clinic.  The clinic  declined to provide it because Read the rest of this entry »

UK Ministry of Justice releases statistics on privacy injunctions January to June 2013

September 20, 2013

As the ALRC (further) inquiry proceeds on at a relatively relaxed pace on whether there should or should not be a statutory right to privacy and if so what form it should take the UK jurisprudence has developed to the point where there are established principles governing the grant of injunction on privacy related matters.  The grant of super injunctions caused considerable controversy and disquiet in the media.  More importantly there was concern about their efficacy and enforcement. The process has been amended signficiantly and the Court has been more restrained in its use.  The use of privacy injunctions are now  more effective and less controversial.

Notable featurs of the report are that there were

Annual report of the Victorian Privacy Commissioner 2012/13 tabled in Victorian Parliament

The 2-12/13 annual report of the Victorian Privacy Commissioner was been tabled in Parliament on 19 September 2013 .  It is found here.  It provides for interesting reading, if that takes and holds your attention (as it does for me).

Some of the interesting statistics are that during 2012-13:

? the total number of complaints handled remains consistent with previous years;
? by a significant margin, Victorian government departments have been the subject of the highest number of privacy breach investigations over the past five reporting periods;
? the amount of complaints referred to VCAT for determination remains consistent with previous years;
? 76% of complaints referred to conciliation Read the rest of this entry »

Draft Guidelines for APPs 6 – 11 released for consultation today

The Australian Privacy Commissioner has released its draft guidelines regarding APPs 6 – 11 for consultation.  Consultation is open until 21 October 2013.  They are found here.

I have extracted the draft guidelines below, absent indexes and footnotes.

 

Australian Privacy Principle 6 – use or disclosure of personal information

 Key points

  • APP 6 outlines when an APP entity may use or disclose personal information.
  • An APP entity can only use or disclose personal information for the particular purpose for which it was collected (known as the ‘primary purpose’), or for a secondary purpose if an exception applies.
  • The exceptions include where:
    • the individual has consented to a secondary use or disclosure
    • the individual would reasonably expect the APP entity to use or disclose their personal information for the secondary purpose, and that purpose is related to the primary purpose of collection, or, in the case of sensitive information, directly related to the primary purpose
    • the secondary use or disclosure is required or authorised by or under an Australian law or a court/tribunal order
    • a permitted general situation exists in relation to the secondary use or disclosure
    • the APP entity is an organisation and a permitted health situation exists in relation to the secondary use or disclosure
    • the APP entity reasonably believes that the secondary use or disclosure is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body, or
    • the APP entity is an agency (other than an enforcement body) and discloses biometric information or biometric templates to an enforcement body, and the disclosure is conducted in accordance with guidelines made by the Information Commissioner for the purposes of APP 6.3.

What does APP 6 say?

6.1              APP 6 outlines when an APP entity may use or disclose personal information. The intent Read the rest of this entry »

Medical photo privacy breaches

The Fairfax press and the ABC have reported on the disturbing practice of doctors and nurses using cameras to take photos of their handiwork without getting consent of their patients or properly protecting the photos.

The ABC report provides:

ELIZABETH JACKSON: For years doctors have taken photos of their patients’ ailments for their records, but now doctors are being warned against the use of smart phones for this purpose.

New Australian research has found doctors and nurses are increasingly using smart phones to take photos, but those digital photos are at risk of ending up in the wrong hands.

Samantha Donovan reports.

SAMANTHA DONOVAN: Most of us like to be looking our best in photos.

But doctors and nurses capture images of patients at their worst, mainly to keep on file or for teaching purposes.

The patient is often in surgery under anaesthetic.

Researchers at RMIT (Royal Melbourne Institute of Technology) University and the Menzies School of Health Research has just published a paper examining medical photography practices in 13 wards of one hospital.

The chief executive of the Australian Health Care and Hospitals Association, Alison Verhoeven, says hospitals are taking the emerging issue seriously.

ALISON VERHOEVEN: What they’ve found is that whereas in the past, a medical photographer might have been engaged to take clinical photos, now doctors and other clinicians are taking photos themselves, and they’re using their own mobile phones or digital cameras to do that.

SAMANTHA DONOVAN: The researchers found 48 per cent of medical staff took photos of their patient’s conditions when they thought it would be useful.

Most of them used hospital-owned cameras, Read the rest of this entry »

Verizon produces its 2013 Data Breach Investigations Report

September 15, 2013

Verizon has been producing a data breach report for the last 6 years.  It gives a good snapshot of the changing nature of breaches to data security and Read the rest of this entry »

Data breach involving personal data of Vodaphone Germany’s customers

September 13, 2013

It news reports in Vodafone Germany suffers server breach that a hacker has stolen personal data of about 2 million Vodafone customers.

It provides:

A hacker has stolen the names, addresses and bank account numbers of about 2 million Vodafone Germany customers who should beware that criminals may now try to elicit other information such as Read the rest of this entry »

Delays in dealing with complaints by Privacy Commissioner

The regulation and enforcement of privacy protection in Australia under the Privacy Act 1988 operates on a gatekeeper system.  But for applications for injunctive relief under section 98 the Privacy Commissioner controls all aspects of complaints to do with interferences with privacy, including whether he will consider a complaint.  An individual can not bring an action under the Privacy Act or any other legislation alleging an interference with his or her personal information or breach of privacy.  That is a severe faililng in the system.  But that is the system.  Given the system as it stands it is therefore incumbent upon either or both the Government to properly resource the Privacy Commissioner so that he may fulfill his statutory functions and the Act can have force or the Privacy Commissioner to become more efficient.  The Sydney Morning Herald in Long delays before privacy complaints assessed reports on the delay in dealing with complaints.

What is clear is that Read the rest of this entry »

Pharmacy in Canberra dumps the medical records

September 12, 2013

The Canberra Times reports in Pharmacy sorry after records found at recycling centre on the dumping of hundreds of private medical records at a recycling centre in the Australian Capital Territory. Just on the known and admitted facts it is an eggregiuos interference with individuals’s privacy.

The article provides:

A Jamison pharmacy has apologised for accidentally dumping hundreds of private medical records, including cancelled and out-of-date prescriptions, at a recycling depot earlier this week.

A Territory and Municipal Services officer was sent to the Belconnen Resource Management Centre on Monday night following a report that prescription medication had been found at the site.

The TAMS officer who inspected the centre’s recycling cage did not find any medication but discovered a box of medical records containing hundreds of private details.

A TAMS spokesperson said the officer left the box of papers in the recycling cage “with the understanding that it would be recycled with the rest of the paper”.

The recycling cage was emptied on Tuesday morning and the contents taken to the Mugga Lane Resource Management Centre.

The documents from the Amcal Pharmacy in Jamison were incorrectly disposed of, the Pharmacy Guild of Australia said.

“It appears that Read the rest of this entry »