feedSubscribe to our news feeds
Archived Posts Lists

Australian Regulatory Compliance Review
Australian Technology and IP Business
Credit Union and Mutual Law
National Consumer Credit Reform
Personal Property Securities Australia
Longview Business Insights
Australian Private Health Insurers
Wills, Trusts, Super
Mutuals Resource Centre

Resources

Commonwealth legislation
Corporate Governance
Not-for-Profit links
Regulator Links

August 25, 2008

Privacy Commissioner issues voluntary data breach guide

The Australian Privacy Commissioner, Karen Curtis, has released a "Guide to Handling Personal Information Security Breaches" (pdf). It is a voluntary guide for use by businesses, agencies and non-government organisations in preventing and, if necessary, responding to a data breach.

The Guide includes four key steps to consider when responding to a breach:

Step 1: Contain the breach and do a preliminary assessment

Step 2: Evaluate the risks associated with the breach (risk analysis is on a case-by-case basis: not all breaches necessarily warrant notification).

Step 3: Consider notification

Step 4: Prevent future breaches.

With regard to Step 3, the Guide suggests that individuals affected by a breach should only be notified where a breach creates a real risk of serious harm to the individuals. This is consistent with the recent ALRC report recommendation

The Guide incorporates illustrative examples which will assist in circumstances, such as whether notification is an appropriate response. 

Print This Post Print This Post

Posted 25th August 2008 by David Jacobson in Privacy