Case note 229558 [2012] NZ PrivCmr 1 : Employer uses monitoring software to collect personal information

June 8, 2012

In Case note 229558 [2012] NZ PrivCmr 1 the Privacy Commissioner considered the collection of personal information on an employee’s computer.

FACTS

During an employment investigation an employer collected personal information from a man’s work computer. The information included emails sent to and from the work computer, as well as key stroke logs for the computer. The employer used information collected from key stroke logging to access the man’s personal web-based email account and copy several emails.

The man complained to us about the information his employer had collected.

DECISION

Two issues were identified; information collected directly from the work computer and information collected from the man’s personal email account.

Information collected directly from the work computer

This complied with Read the rest of this entry »

AW v Statutory Authority [2012] VPrivCmr 1: IPP 8, anonymity

June 6, 2012

In AW v Statutory Authority [2012] VPrivCmr 1 the Privacy Commissioner considered a complaint about anonymity.

FACTS

The Complainant had a problem with alleged delays and long waiting times at a particular service provider. He complained to the Statutory Authority who Read the rest of this entry »

Privacy issues involving de sal contractors

June 5, 2012

In Desal firm ‘sorry’ over secret files the Age reports on an ongoing Federal Court case involving allegations that Theiss Degremont gave applicant’s files to a third party.

The article provides:

THE builder of the Wonthaggi desalination plant has apologised to workers after it gave a strikebreaker files with confidential information on more than 15,000 people.

The files included medical records, bank account numbers, and salary details of many who applied for a job building the plant.

The plant’s builder, Thiess Degremont, in 2010 gave the files to self-proclaimed union buster Read the rest of this entry »

A and Financial Institution [2012] AICmrCN 1 (1 May 2012): National Privacy Principle 2.1

June 4, 2012

The Privacy Commissioner has released a  determination, A and Financial Institution [2012] AICmrCN 1. The NPPs considered were  NPP 2.1, an organisation must not use or disclose personal information about an individual for a purpose other than the primary purpose of collection, unless an exception applies.

Facts

The complainant was a customer of a financial institution. The financial institution required the complainant to provide a mobile phone number when it set up internet banking. It told the complainant that the mobile phone number would only be used in providing security identification for internet banking.

Five years later, a direct marketing company made several calls to the complainant to sell insurance products on behalf of the financial institution. The financial institution sent the complainant a letter about its insurance products a week before the telephone calls. A notice in fine print at the back of the letter stated that the financial institution would send the complainant’s mobile phone number to the financial institution’s contract company, to call the complainant, unless the complainant contacted a specified number to advise they wanted to be excluded from the calling program.

Decision

The financial institution relied on NPP 2.1(a) claiming that because the complainant had not  advised it did not want to participate in the calling program, it was entitled to assume that its disclosure of the complainant’s personal information, including the mobile phone number, was within the complainant’s reasonable expectations.

The Commissioner found that to satisfy NPP 2.1(a), the disclosure Read the rest of this entry »

Privacy Articles

June 1, 2012

There have been a range of privacy related articles in the week or so.

In Two cheers for privacy law reform? Let’s wait and see in hte Conversation Bruce Arnold provides a standard overview of the Act. He is mildly supportive and optimistic.  The problem is that the expanded powers given to the Privacy Commissioner mean little if the Commissioner does not use them sensibly.  The Privacy Commissioner’s office has not been the most pro active or determined protector of privacy.  Damages for breaches of privacy (based on determinations to date) have been at best modest.

In Gene test results to be passed on without consent the State Government is reported:

PEOPLE tested for predisposition to a genetic disease will no longer have a say in whether their results are given to their close relatives, under proposed changes to NSW laws.

The NSW Health Minister, Jillian Skinner, has introduced legislation to allow doctors to inform a patient’s blood relatives they are at risk of having or developing a serious illness. Such tests can be used to identify whether people are at increased risk of cancer or heart disease.

Professor Ron Trent, a genetics expert from the University of Sydney, said in most cases people were willing to share information with relatives, but some refused to disclose private information.

The Age’s article Hoarding privacy jewels does not expose an anomaly but merely highlights a long standing one that exists in the Priavcy Act; that it exempts political parties.  It also exempts the media.

In Trade war up in the clouds the Canberra Times looks at the privacy issues involved in storing data in the cloud.

Roberts v Investwell Pty Ltd (In liq) [2012] NSWCA 134 (25 May 2012): Winding up, payment to director when company insolvent, “Unfair preference”, ss 588FA, 588FC, 588FE, 588FF Corporations Act 2001

May 29, 2012

Last Friday, the New South Wales Court of Appeal in Roberts v Investwell Pty Ltd (In liq) [2012] NSWCA 134 considered the operation of equitable charges and mortgages in the context of unfair preferences.

FACTS

In June 2001 the Respondent (“Investwell”) purchased land in Marourabra to develop home units using its own funds, monies advanced from prospective purchasers and a loan from a credit union.  The Appellant (“Roberts”) was a director and shareholder of Investwell [3].  In April 2002 it became apparent that there was a shortfall in funding to complete the project. Roberts entered into an agreement whereby he agreed to use his best endeavours to provide further funds and security for the project [4].  On the sale of units the debt with the credit union was discharged leaving a balance of $164,306.83 which was paid to Roberts on the basis that he was a creditor ( not in issue) of the company in that amount.  It was not in issue that when the payment was made Investwell was insolvent  [6].

An order for the winding up of Investwell was made on 12 March 2007.  Investwell and the liquidator brought proceedings against Roberts claiming money he received was a voidable transaction [7].

The relevant provisions of the agreement are set out at  [9], the most relevant of which was Read the rest of this entry »

Article on privacy by the Attorney General

May 25, 2012

In today’s Australian the Attorney General, Nicola Roxan, wrote an opinion piece on the amendments to the Privacy Act.

It provides:

These days Read the rest of this entry »

The Privacy Amendment (Enhancing Privacy Protection) Bill 2012 introduced into Federal Parliament today

May 23, 2012

Today the Attorney General has introduced into the Federal Parliament the Privacy Amendment (Enhancing Privacy Protection) Bill 2012. It is the legislative implementation of the Government’s response to the Australian Law Reform Commission’s recommendations to the Privacy Act.

It is a substantial piece of legislation (text is found here on Parliament House web site, running to 236 pages on the Word Format (although it should be added there are many amendments to existing legislation).  The explanatory memorandum is also a significant document which will require careful study.

The Attorney General’s press release provides:

Changes to the Privacy Act that better protect people’s personal information, simplify credit reporting arrangements and give new enforcement powers to the Privacy Commissioner have been introduced into the Australian Parliament today.

Attorney-General Nicola Roxon said the changes represent the most significant developments in privacy reform since Labor introduced the Privacy Act in 1988.

“In an online world, we are sharing our personal information Read the rest of this entry »

An interesting issue on how secrecy laws tend to corrupt reportage

May 17, 2012

In an interesting story on PM last night Heather Brooke was interviewed on PM regarding the hacking scandal in the UK.  Her take was far from sympathetic of what News Limited (as well as other media outlets) did in hacking emails and phones but she did make the point that there is a mass of relevant information which should not be hidden behind secrecy as is the case in the UK.  She is the author of The Revolution will be Digitised: Dispatches from the Information War.

The transcript of the piece is found here.  It provides:

MARK COLVIN: The former editor of Rupert Murdoch’s News of the World Rebekah Brooks was one of six people charged last night in relation to Britain’s Operation Elveden. That’s the operation that’s looking into the bribery and suborning of public servants like police and tax officers. Many more charges are expected over time from Operation Weeting – that’s the one that’s looking into the hacking scandal more generally.

So it might seem a bad time to be arguing for journalists to get more access to public information. But that is exactly the argument of Heather Brooke, author of The Revolution Will be Digitised: Dispatches from the Information War.

British-born but American educated, she thinks that radical transparency is actually a way of preventing press abuse. Heather Brooke’s here for the Sydney Writers’ Festival: I put it to her that some would be sceptical of her argument when sections of the media – in Britain especially – had been shown to be so corrupt.

HEATHER BROOKE: (laughs) Well, I always thought that the press in Britain were so sensationalistic mostly because they couldn’t access information legitimately and so the only way they could get information was they either had to get it through favouritism or a kind of collusion with the powers that be, or illegitimately.

MARK COLVIN: By bribery as we now know.

HEATHER BROOKE: Well, and I always wondered, like how do journalists do their jobs in Britain? Because when I worked as a – I used to work as a crime reporter amongst my different jobs in America – and the way you could cover crime there is it was all through public records. You know you could get all the crime reports, you could get all the jail arrests, you could see all the fire reports, everything – you just went in and you looked at them.

In Britain all that stuff is secret. Even to this day Read the rest of this entry »

Office of Australian Information Commissioner releases Data Breach Notification

May 12, 2012

The Office of the Australian Information Commissioner has released a guide to handling personal information security breaches. It is found here.

It is a tome but a welcome one.

I have extracted it here (without footnotes and page numbering):

Key terms ALRC means the Australian Law Reform Commission
Agency has the meaning set out in s 6 of the Privacy Act and includes, amongst other things, a Minister, an Australian Government department, an ACT Government department, and a Norfolk Island agency.
Privacy Act means the Privacy Act 1988 (Cth).1 Personal information has the meaning as set out in s 6 of the Privacy Act:
… personal information means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.
Data breach means Read the rest of this entry »