Royal Free London NHS Foundation Trust enters into undertaking because of the breach of the Data Protection Act in turning over sensitive medical data of around 1.6million patients to DeepMind

July 15, 2017

The UK Information Commissioner’s Office (the “ICO”) has its detractors however as a regulator it has been by far more energetic than its Australian equivalent.  The legislative structure is different as is the resourcing.  The UK Data Protection Act provides more scope for enforcement action and the penalties can be swingeing.  That said the approach taken by the ICO in both adopting an educational approach, the carrot, but also high profile and tough regulatory action, monetary penalty notices, highlights a difference with the Office of the Information Commissioner, which has been all about the education and very little about the enforcement. That has had a deleterious effect on privacy and data protection compliance in Australia.

The ICO took action against the Royal Free London NHS Foundation Trust for failing to Read the rest of this entry »

US National Institute of Standards and Technology releases draft Application Container Security Guide

The National Institute of Standards and Technology (“NIST”) has released a draft of is Application Container Security Guide.  While the NIST is an American agency its guides have Read the rest of this entry »

Data breaches at Flight Centre and elsewhere…the excuse “Human Error” seems to be more acceptable than system faults..really?

The passport details of Flight Centre customers have been released to third parties who were working with Flight Centre in developing business products.  The extent of the breach, in terms of numbers of passport holders personal information being leaked and what exactly was released to the unauthorised party, has not been disclosed.  That level of opaqueness in notification tends to be typical in Australia but much less so in the United Kingdom and the United States. Curiously the Flight Centre stresses that human error, rather than a systems failure, was the cause of the breach.  As if that makes it better or less serious.  The Privacy Act Read the rest of this entry »

Sheales v The Age & Ors [2017] VSC 380 (29 June 2017): defamation, damages where reputation not put in issue, mitigating and aggravating factors

July 6, 2017

After a 6 day trial a jury found for the plaintiff in the defamation proceeding of Sheales v The Age & Ors [2017] VSC 380.  The Court awarded damages in the sum of $175,000.  The current maximum amount awardable for non-economic loss is $381,000.

FACTS

The Plaintiff, Sheales, is a Victorian barrister practicing mainly in criminal law and sports law. The Third Defendant, Patrick Bartley, was a journalist who wrote an article about the Plaintiff’s appearance before a Racing Victoria stewards hearing on 2 August 2015. An issue before the steward’s hearing that day concerned the alleged use of the chemical element cobalt by the plaintiff’s clients [1]. Fairfax Digital Australia and New Zealand Pty Ltd, the second defendant, published the article online. The first defendant, The Age Company Pty Ltd, the owner and publisher of The Age newspaper, published the article, with some small differences on 3 August 2015 [2].

The Plaintiff alleged that he had suffered injury to his professional reputation and feelings, had been humiliated, embarrassed or Read the rest of this entry »

Medicare numbers available on the dark web

July 4, 2017

The theft of personal information and subsequent sale on the internet, the “darknet” to be more dramatic, is common, lucrative and, because poor privacy and cyber security policies and protections by many organisations, an increasingly attractive way for criminals to make money. It is not necessary to obtain credit card or bank details.  Getting official identifiers like social security numbers have intrinsic value.  Which is why the report of Medicare numbers being sold on line is Read the rest of this entry »

Anthem Inc, America’s largest health insurance company settles litigation over hack of 79 million people’s accounts for $115 million

June 24, 2017

Reuters reports in Anthem to pay record $115 million to settle U.S. lawsuits over data breach a resolution of a class action arsing out of a massive data breach of 79 million individuals’ personal information.

The Plaintiffs’ website announced that the court will consider the settlement on Read the rest of this entry »

Ponemon Institute releases 2017 Cost of Data Breach around the world

June 22, 2017

The cost of data breaches can be catastrophic.  The BBC reports that a South Korean web hosting firm, Nayana, has paid $1 million that had been the subject to a ransomware attack.  The hackers initially wanted $4.4 million payable in Bitcoin.  The orthodox advice is not to pay the ransom.  The reality is more mixed.

Ponemon has released another very useful report, this time on the cost of data breaches.  It is titled 2017 Cost of Data Breach Study Global Overview.

Some interesting findings include Read the rest of this entry »

The Australian Competition and Consumer Commission sends warning about phishing

June 20, 2017

The Australian Competition and Consumer Commission (ACCC) has issued an alert about phishing scams stating that so far this eyar there have been 11,000 reports and a loss of $260,000.  Given under reporting is the norm it is likely that the losses are much greater.

The media release provides:

The ACCC is warning people to stay alert to ‘phishing’ scammers pretending to be from well-known businesses and government departments trying to con unsuspecting victims out of their personal information and money. Read the rest of this entry »

Personal information of nearly 200 million US citizens exposed on line in massive data breach…courtesy of third party provider’s lax cyber security system. Familiar story.

Data breaches by third party providers, usually contractors, is becoming a chronic problem. Weaknesses in the cyber security of smaller contractors have allowed hackers to access large corporations sites, such as with Target in 2014, or access large companies personal information and information property, such as the theft of a season of Orange is the new Black.  With the maturation of the data analytics industry and the increasing sophistication of algorithms the processing of data is increasingly Read the rest of this entry »

Australian Law Reform Commission releases long awaited report on elder abuse

June 15, 2017

The Australian Law Reform Commission has released a comprehensive report on Elder Abuse – A National Legal Response.  For legal practitioners the relevant recommendations  include Read the rest of this entry »