Business Daily Media

Men's Weekly

.

After the Optus data breach, Australia needs mandatory disclosure laws

  • Written by Jane Andrew, Professor, University of Sydney Business School, University of Sydney
After the Optus data breach, Australia needs mandatory disclosure laws

The Optus data breach, which has affected close to 10 million Australians, has sparked calls for changes to Australia’s privacy laws, placing limits on what and for how long organisations can hold our personal data.

Equally important is to strengthen obligations for organisations to publicly disclose data breaches. Optus made a public announcement about its breach, but was not legally required to do so.

Read more: A class action against Optus could easily be Australia's biggest: here's what is involved[1]

In fact, beyond the aggregated data produced by the Office of the Australian Information Commissioner, the public is not made aware of the vast majority of data breaches that occur in Australia every year.

Australia has had a “Notifiable Data Breaches[2]” scheme since February 2018 that requires all organisation to notify affected individuals as well as the Office of the Australian Information Commissioner in the case a breach of personal information likely to result in serious harm.

However, no notification is required if the organisation takes remedial action to prevent harm. Most importantly, public disclosure is never required.

This gives a lot of discretion to organisations. They can make their own assessment about the risks and decide not to disclose a breach at all.

Companies listed on the Australian Securities Exchange (ASX) are also obliged to disclose any data breach expected to have a “material economic impact” on a company’s share price. But it is notoriously difficult to measure material economic impact. So these announcements are not a reliable source of information for the public.

Notified data breaches

While the Notifiable Data Breaches[3] scheme is a step in the right direction, it’s impossible to know if the disclosures made reflect the scale and scope of data breaches.

The most recent Notifiable Data Breaches Report[4], covering the six months from July to December 2021, lists 464 notifications (up 6% from the previous period).

Of these, 256 (55%) were attributed to malicious or criminal attacks, and 190 (41%) to human error, such as emailing personal information to the wrong recipient, publishing information by accident, or losing data storage devices or paperwork[5]. Another 18 (4%) were attributed to system errors.

The sectors that reported the most breaches were the health care service (83 notifications); finance (56); and legal, accounting and management services (51).

About 70% of all incidents reportedly affected fewer than 100 people. But one event affected at least a million people. Despite the scale, the public has not been provided details of these events, or the identities of the organisations responsible.

Regardless of the scale or reason, all data breaches have an impact on people and organisations. Despite this, we rarely learn about anything other than the most spectacular and most criminal of these events.

Without mandatory disclosure, there is insufficient public accountability.

How should minimum disclosure work?

A minimum disclosure framework should include[6] information about the type of data breached, the sensitivity of the data, the cause and size of the breach, and the risk-mitigation strategies the organisation has adopted.

The framework should require both a standardised public announcement when any significant data breach occurs, as well as a mandatory annual public report of data breaches. Reports and announcement should be published on the company’s website (just like an annual report) and filed with the Office of the Australian Information Commissioner.

Read more: Optus says it needed to keep identity data for six years. But did it really?[7]

This would ensure public access to a coherent historical record of breach-related events and organisational responses. The disclosures would allow community groups, regulators and interested parties to analyse breaches of our data and act accordingly.

At its simplest, a mandatory disclosure framework encourages annual disclosures that are comparable and publicly available. At the very least it creates opportunities for scrutiny and discussion.

Authors: Jane Andrew, Professor, University of Sydney Business School, University of Sydney

Read more https://theconversation.com/after-the-optus-data-breach-australia-needs-mandatory-disclosure-laws-192612

US landmark settlement protects SMEs, highlighting flaws in the RBA's proposed blanket card surcharging ban for Australia

Aussie SMEs warn RBA not to ignore global trends, with the current sledgehammer approach threatening business viability and increasing inflation ...

Thryv Australia named Employer of Choice for third consecutive year at Australian Business Awards

Thryv® (NASDAQ: THRY), Australia’s provider of the leading small business marketing and sales software platform, has been awarded the Employer of ...

RogersDigital.com Announces the Launch of TheBulletin.au, a Destination for Business, Policy and Financial Insight

RogersDigital.com has announced the launch of TheBulletin.au, a new national digital publication designed to deliver sharp, data-driven reporting ...

Controlling business spend is helping finance leaders to forecast with confidence

Forecasting has always been central to financial planning; however, traditional methods based on historical trends are no longer enough. Economic ...

From correction to resilience: making the most of Australia’s evolving insurance landscape

Australia is benefiting from one of the most favourable insurance market environments seen in years. However, it’s important to recognise that these...

AI is Changing Trademarking Forever

The launch of ChatGPT in 2022 marked a turning point for AI. In three short years, AI has been integrated into everything from our phone cameras to ...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์betsmovejojobetvozol türkiyePusulabet Girişสล็อตเว็บตรงgamdom girişpadişahbetMostbetbetofficejojobetcarros usadospin upMostbetdizipalmatbet girişnn888pradabetsahabetpusulabet girişcasibomvdcasino girişultrabetbetofficeBets10jojobetjojobetjojobetMavibet色情 film izlecasibomnakitbahisholiganbet 1177holiganbetholiganbetmatbetmarsbahis girişYakabet1xbet girişjojobetGrandpashabetFİXBETgobahistrendbetbetofficemeritkingjojobet girişgiftcardmall/mygiftultrabet girişjojobetbets10betebetmamibetmeritkingcasibommeritroyalbetbetcioslot spacemansekabetjojobetcasibomJojobetmeritkingmeritbetcasibom girişdeneme bonusukingroyaljokerbetcasibomcasibomyakabetyakabetmeritkingSekabetCasibommadridbetBetnanoDinamobetrinabetVdcasinoSekabetMarsbahismeritkingultrabet girişprimebahismadridbetprimebahiskingroyalbetciomeritkingmeritkingmeritkingçanakkale tırnakwbahisgalabetsahabetmr pachocasibomcasibomcolor pickermatbetvbetultrabetmeritbet girişkralbet girişultrabet girişultrabet girişultrabet girişbetnano girişcratosslot girişคลิปหลุดไทยCasibomcasibomHoliganbetdeneme bonusu veren sitelermeritbetonwindiyarbakır escorttimebetantalya escortgrandbettingbahsegelgrandbettingqueenbetqueenbetbahiscasinobahiscasinoultrabetbets10matbetRoyal Reelsroyal reelsnorabahiskolaybet girişKayseri Escortjojobetgrandpashabet girişNişantaşı EscortmatbetmatbetbettiltStreameastpusulabetKalebetHoliganbetfixbetaviator gameÜsküdar Evden Eve Nakliyatbetsmovetimebettimebettimebetbahislionistanbul escort telegramcasibomcasibompantheraproject.netcasibompusulabetoslobetbetplaymatbet girişmarsbahisholiganbetbetparkstreameast한국야동meritkingหวยออนไลน์jojobet girişholiganbet girişpornopadişahbetBetigmacasibomBetigmaBetlora girişgiftcardmall/mygiftgaziantep escorteb7png pokiesbest online casino australiabest online pokies australiareal money pokies online australiabcgame96 casinocrown155 hk casinohb88kh casinoHoliganbet girişmarsbahismarsbahisgalabetholiganbet girişjojobetcasibombets10 girişbets10gamdomholiganbetolimposcasinocasinomegaholiganbet 1177holiganbet 1177jojobet girişbetgramblooketasyabahis girişpinbahis girişzbahisdumanbet girişjojobetStreameastmostbetdaftar situs judi slot gacor hb88 indonesiajojobet 1110mostbetmostbetmostbetbetliketeosbetrbetmatbetcasinowon girişmarsbahisjojobetgiftcardmall/mygift check balance visajojobetmarsbahisซื้อหวยออนไลน์grandpashabetcasibomretcasinoasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdmadridbet girişjojobetzlotgrandpashabet girişpin up uzbekistanjojobet girişSlot Heart Casinomamibet logincasinomedklarna.sebetworld96 online casino cambodiaHoliganbet 1177www.giftcardmall.com/mygiftwww.giftcardmall.com/mygiftcasibomtm menards loginbetasusgrandpashabet