Privacy Act Review Report – latest update

By Kristy McCluskey

In an increasingly digitised environment, the storage and access of data and associated privacy principles are now at the forefront for businesses and Australian regulators, not least due to high profile data breaches in 2022 involving Optus and Medibank. The Attorney General’s Department Privacy Act Review Report 2022 (Report) was released on 16 February 2023, providing the greatest indication yet that Australian privacy laws are likely to be updated, having far reaching effects on consumers and businesses alike.

The Report is the outcome of more than two years of consultation regarding proposed amendments to the Privacy Act (Act). The Report contains 116 proposals to strengthen and modernise Australian privacy law. In this article, we give an overview of the most pertinent changes, and the effect they may have on consumers and businesses.

Small business exemption

Arguably the most substantial recommendation in the Report is removing the small business exemption. Under the current legislation, most small businesses with an annual turnover of less than $3 million are not required to comply with the Act, unless they are engaged in exempt activities. Removing this exemption will require all non-exempt businesses to become fully compliant with Australian privacy laws. The government has acknowledged the impact this will have on businesses, particularly smaller entities, and has pledged to undertake a full impact analysis and industry consultation.

Notifiable breach

The last 18 months has demonstrated the commercial damage to a business a data breach can cause, along with society’s expectations around how those breaches are reported. The Report introduces an obligation for entities to provide an eligible data breach statement to the Office of the Australian Information Commissioner (OAIC) within 72 hours of becoming aware there are reasonable grounds to believe an information breach has occurred. An entity must also then notify individuals as soon as practicable and take reasonable steps to prevent adverse impacts to the individuals affected.

Civil penalties

Reforms in December 2022 increased the maximum penalties for serious or repeated privacy offences. Following this, the Report recommends that legislation introduce new low-tier and medium-tier civil penalty provisions to address the issue that any sanction for breaching the Act that is less than serious or repeated can only be dealt with via an OAIC determination. Whilst penalty amounts are yet to be determined, it is likely these new penalties will target minor privacy breaches and administrative breaches resulting in increased regulatory action and enforcement against businesses.

Right of erasure

The Report proposes individuals should be empowered to request deletion of their personal information by complying entities. Whilst this is practically an extension of the current obligation to delete personal information that is no longer needed, it is expanded in that individuals will be able to request the deletion of any category of personal information. However, the Report suggests these requests will not be accepted where there is a competing public interest, it is unauthorised by law, or is an abuse of process.

Personal information

Finally, the Report recommends altering the definition of ‘personal information’ to include information relating to a person. This expansion will allow businesses to capture a larger range of information and helpfully brings it into line with other existing Commonwealth legislation.

Where to now?

The consultation period for the review regarding the proposed amendments closed on 31 March 2023. Whilst it remains to be seen which amendments will be enacted, it is likely the increased regulation will impact more Australian businesses, greatly increasing compliance costs. Conversely, it is hoped the increased powers and changes will provide enhanced protections to consumers. However, some market commentators suggest the broader definition of personal information, and the increase in businesses having to maintain privacy policies, may lead to increased class actions, litigation risk, and insurance premiums within industry.

We will keep you up to date with further developments. If you need to understand more about these proposed reforms reach out to a member of our Investment Funds team.

Contact

Karl Rozenbergs

Partner and Co-Lead Health & Care

Emma Woolley

Partner & Head of Family Office Advisory

Oliver Jankowsky

Partner & Head of International Practice

Eugene Chen

Partner & Head of China Practice

Ben Hamilton

Partner & Technology and Digital Economy Co-Lead

John Bassilios

Partner & Fintech and Blockchain Lead

Graydon Dowd

Chief Executive Partner

Matthew Curll

Partner & Insurance National Practice Leader

Melanie Smith

Director – Business Development, Marketing and Communications

Natalie Bannister

Partner & Commercial National Practice Leader

Nathan Kennedy

Partner, Head of Pro Bono & Community and ESG Co-Lead

William Moore

Partner & Head of Private Clients Advisory

Mark Dessi

Partner & Energy Leader

James Bull

Special Counsel & Frank Lab Co-Lead

Melanie James

People & Culture Manager

Jacqui Barrett

Partner & Head of US Desk

Lauren Parrant

Senior People & Culture Advisor

Melinda Woledge

Marketing & Communications Manager

Jasmine Koh

Senior Associate & Frank Lab Co-Lead

Alison Choy Flannigan

Partner and Co-Lead Health & Care

Meg Lee

Partner & ESG Co-Lead

John Gray

Partner and NSW Government Co-Lead

Luke Denham

Lawyer

Billie Kerkez

Manager – Smarter Recovery Solutions

Sarah Khan

Lawyer

Audrey Leahy

Special Counsel & Head of Irish Desk

Nicole Tumiati

Partner & Retail & Consumer Goods Leader

Marie Mitilineos

Lawyer

Gloria Tam

Lawyer

Peter Jones

Senior Commercial Counsel

Eden Winokur

Partner & Head of Cyber

Jennifer Degotardi

Partner & NSW Government Co-Lead

Sheldon Fu

Lawyer

Silvana Brcina

Lawyer

Daphne Schilizzi

Lawyer

Andrew Banks

Lawyer

Isabella Urso

Lawyer

Jessica Liu

Lawyer

Amelia Spratt

Lawyer

Lisa Ziegert

Director – Client Solutions

Luke Raams

Lawyer

Emma McDonald

Lawyer

Maddison Reznik

Senior Associate & Trade Marks Attorney

Rebecca Dodd

Lawyer

Ruby Hunt

Pro Bono & Community Co-ordinator

Rachel Bonic

Lawyer

Samantha Frost

Lawyer

Emma Bechaz

Lawyer

Steve Johns

Partner & Technology and Digital Economy Co-Lead

Luke Hefferan

Lawyer

Michelle Harradine

Lawyer

Related industries

Related practices

You might be also interested in...

Uncategorised | 22 May 2023

ASIC pursues insurer for unfair contract terms

In our November 2022 edition of Fundamental, we flagged reforms to unfair contract laws aimed at providing greater protections for consumers and small businesses entering standard form contracts.

Uncategorised | 22 May 2023

Are directors and developers liable for defective construction work?

We discuss the potential risk of personal liability for directors and developers where economic loss results from defective construction works.