UK Information Commissioner’s Office fine Gloucester City Council 100,000 pounds for exposing personal information to cyber attack

June 14, 2017

It is a critical part of maintaining data security to address vulnerabilities on a website as and when they become known.  That is requirement is included in all guidances put out by privacy commissioners.  Usually it is fairly straightforward task, updating programs, installing patches when a vulnerability is identified and responding to notices about threats.  Organisations should, but rarely, organise penetration testing.  In the United States there is a culture of engaging white hat hackers to test the cyber defences of government and organisations.

But protecting from well known vulnerabilities has to be a necessary minimum.  As The Gloucester City Council will now realise having been fined £100,000 for failing to repair a vulnerability, the Heartbleed flaw in software, in the council’s website.  This failure Read the rest of this entry »

‘LP’ v The Westin Sydney (Privacy) [2017] AICmr (7 June 2017): APP 3.5 and 12, secret recording of telephone conversation by The Westin

The Privacy Commissioner handed down a decision finding that the The Westin Sydney interfered with the complainant’s privacy in LP’ and The Westin Sydney (Privacy) [2017] AICmr 53.  The Westin was found to have interfered with the privacy of LP by recording his telephone conversation without advising him beforehand.  It is a decision that has not been publicised.  That is a shame and quite different to the practice by the Information Commissioner in the United Kingdom and the Federal Trade Commission in the United States.  It is a practice failing by the Australian Privacy Commissioner.

FACTS

LP  booked a room at The Westin. On the afternoon of 17 January 2016, he arrived and checked in. The Westin employee who handled his check-in informed him that there would be a 10 to 20 minute delay until his room became available.  While LP was waiting in the hotel’s executive lounge he received a call on his mobile phone from a Westin employee who advised that the preferred room was not be available until later that afternoon. LP was then asked whether he wanted to wait for a similar room on a different floor, or if he would prefer an alternate smaller room on the same floor that was available immediately. LP agreed to accept the alternate room, but was unhappy [4].

LP subsequently complained to The Westin about his treatment, including the unavailability of his preferred room. While responding to this complaint, on 18 January 2016, the Executive Assistant Manager of The Westin referred to the recording of LP with a Westin employee. LP had been unaware that The Westin had recorded the call [5].

On 19 January 2016, LP emailed Read the rest of this entry »

Hong Kong Privacy Commissioner investigates loss of computer notebook containing names

June 12, 2017

The loss of computers containing personal information is an all too common event. I have previously written a post on the UK Information Commissioner’s Office taking action for loss of a lap top.  It is a serious problem because notebooks,  a common if not preferred form of computers for many workers, can be easily lost or stolen.  They can store large amounts of sensitive data.  While theft and loss is a problem the bigger problem for organisations is the lack of security in the storage of data.  Poor training results in more data being kept than is required, the data is not properly encrypted and computers are not properly password protected.

The Hong Kong Privacy Commissioner has conducted an investigation and today published a detailed report on the Loss of Notebook computers which contained personal data of election Committee Members and Electors.  The amount of data on 2 computers that were lost is significant, 1,200 Election Committee members and 3.78 million electors. Some of the data was Read the rest of this entry »

EU General Data Protection Regulation less than a year away. The Privacy Commissioner issues guidance

In slightly less than a year, from 25 May 2018 to be precise, the the General Data Protection Regulation (“GDPR”) will take effect throughout the European Union.  Australian businesses of any size may need to comply with the GDPR if they have an establishment in the European Union (EU), if they offer goods and services in the EU, or if they monitor the behaviours of individuals in the EU.  It is more a continuum of the existing data protection laws rather than a new system.  That said it is a Read the rest of this entry »

The United States Supreme Court to consider whether the police need warrants to obtain cellphone location data

June 11, 2017

The US Supreme Court has in recent times considered the use of new technologies and their privacy intrusive consequences and whether they constitute a constitutional breach.  In 2012 the Court in United States v Jones held that installing a GPS tracking device on a vehicle and using the device to monitor the vehicle’s movements constitutes a search under the Fourth Amendment. In Riley v California the Court unanimously held that the warrantless search and seizure of digital contents of a mobile phone during an arrest was unconstitutional.

On 5 June 2017 the Supreme Court  agreed to hear arguments in the October Term in Carpenter v United States as to whether police should obtain warrants to obtain location data of suspects.

The question presented to the Court is Read the rest of this entry »

McDonald v Dods [2017] VSCA 129 (2 June 2017): Defamation, inference of publication on the internet, damages

In McDonald v Dods [2017] VSCA 129 the Victorian Court of Appeal considered the issue of inference of publication to unknown individuals who may have read a blog post.

It is an appeal from judgments of Bell J inDods v McDonald (No 1) [2016] VSC 200 (6 May 2016) and Dods v McDonald (No 2) [2016] VSC 201 (6 May 2016).

FACTS

The applicant, McDonald, was the administrator and author of the website ‘www.justice4tylercassidyjust15.com’ (the “website”) from December 2008 to October 2012 where he discussed the death of Tyler Cassidy by police shooting [3]. The respondent Read the rest of this entry »

Data breach at Comestic Institute attracts the attention of the Privacy Commissioner

June 6, 2017

Personal information relating to medical matters is highly sensitive.  The Cosmestic Institute, based in Bondi,  specialised in providing cosmetic surgery, holds a particularly subset of that type of information; before and after photographs, photographs of a highly intimate nature and details which are almost invariably kept confidential

Naked photos and medical records of hundreds of women were published on line at least as late last Saturday.  Possibly earlier.  It appears that the publication of this highly sensitive information included patient names, Medicare numbers and naked images of 500 people.  The breach involved Read the rest of this entry »

Medussa Enterprises Pty Ltd v Nationwide Concrete Pumping Pty Ltd [2017] VSC 275 (24 May 2017): section 459G of the Corporations Act 2001, application to set aside a statutory demand, genuine dispute

June 5, 2017

In Medussa Enterprises Pty Ltd v Nationwide Concrete Pumping Pty Ltd [2017] VSC 275  the Victorian Supreme Court, per Gardiner AsJ, dismissed an application to set aside a staututory demand on the basis that there was no genuine dispute.

FACTS

Medusa claimed Read the rest of this entry »

Privacy Commissioner issues Draft guidelines and resources on Notifiable Data breaches

Australia’s mandatory data breach notification legislation, the Privacy Amendment (Notifiable Data Breaches) Act 2017,  takes effect on 22 February next year.  It has been a long time coming.

Last Friday the Privacy Commissioner released an exposure draft resources, whatever that means, for business and agencies on their obligations under the Act.  It is open for comment until 14 July 2017, Bastille Day (hopefully that symbolises nothing).

The broad overview Read the rest of this entry »

United Kingdom Information Commissioner’s Office fines Basildon Borough 150,000 poundsCouncil for publishing sensitive personal data on line

June 4, 2017

The United Kingdom’s Information Commissioner’s Office (the “ICO”) has imposed a severe fine of on Basildon Borough Council for publishing personal information on planning application documents. The argument run by the Council was that the planning laws prevented it from doing so even though it routinely redacted personal information on other applications.  In Victoria this has been an issue in the past where some councils have felt that they can not redact while others argue they can.  It appears that most do redact.

The ICO media release provides:

A council has been fined £150,000 by the Information Commissioner’s Office (ICO) for publishing sensitive personal information about a family.

Basildon Borough Council breached the Data Protection Act when it published the information in planning application documents which it made publicly available online.

The ICO’s investigation found that on 16 July 2015, the council received a written statement in support of a householder’s planning application for proposed works in a green belt. The statement contained sensitive personal data relating to a static traveller family who had been living on the site for many years. In particular, it referred to the family’s disability requirements, including mental health issues, the names of all the family members, their ages and the location of their home. Read the rest of this entry »