• Contact
  • Feedback
Banking Day
  • News
  • Topics
    • All Topics
    • Briefs
    • Major Banks
    • Authorised deposit-taking institutions
    • Insurance, funds and super
    • Payments, mobile & wallets
    • Consumer lending
    • Mortgages
    • Business lending
    • Finance regulation
    • Debt capital markets
    • Ratings agencies
    • Equity capital markets
    • Professional services
    • Work & career
    • Foreign news
    • Other topics
  • Free Trial
  • Subscribe
  • Resources
    • Industry events
  • About us
    • About Banking Day
    • Advertise
    • Feedback
    • Contact Banking Day
  • Search
  • Login
  • My account
    • Account settings
    • User Admin
    • Logout

Login or request a free trial

Mandatory breach notification bill released

08 December 2015 4:30PM
The Government has released draft legislation that will introduce mandatory breach notifications.The Privacy Amendment (Notification of Serious Data Breaches) Bill 2015 makes it compulsory for organisations regulated by the Privacy Act to notify the Office of the Australian Information Commissioner and affected individuals when certain types of security incidents compromise confidential information.The law would cover credit providers and credit reporting bodies.A data breach occurs where there has been unauthorised access of data, or unauthorised disclosure of personal information about one or more individuals, or where such information is lost in circumstances that are likely to give rise to unauthorised access.Examples include a malicious breach of secure information, accidental loss of IT equipment or hard copy files, and negligent or improper disclosure of information.The amendment will cover serious breaches, where the data breach causes "a real risk of serious harm."Serious harm includes "physical, psychological, emotional, economic and financial harm, as well as harm to reputation."Notification will be compulsory unless it would affect a law enforcement investigation or is deemed by the regulator to be contrary to the public interest.Organisations reporting breaches will be required to assist affected individuals take remedial steps, such as issuing new passwords.The OAIC will have the power to issue directions to organisation to issue breach notifications in situations where it judges that a serious breach has occurred and no notification has been made.The government is taking submissions on the draft until March next year.

I'm a returning subscriber

*
Password reset *
Login

Request a free trial

  • Emailing you the news at 7am.
  • Covering core lending and funding issues, strategy, payments, regulation, risk management, IT, marketing and more.
  • Original news and summaries of major stories from other media – ditch your newspaper subscriptions.
  • Focused on banking and finance, saving you the time spent wading through newspapers and other services.
  • With reporting from former editors and senior writers from the AFR and The Australian.
  • Configured for your phone, laptop and PC.
Free trial Banking Day

Consumer lending

  • Latitude, Harvey Norman liable for interest free GO card con

Copyright © WorkDay Media 2003-2025.

Banking Day is a WorkDay Media publication

WorkDay Media Unit Trust

  • Privacy policy
  • Terms of access and use