iTnews
  • Home
  • News
  • Technology
  • Security

Local industry keen to mirror UK’s data breach fines

By Liz Tay
Mar 26 2010 12:41AM
Follow google news

£500,000 fines could help secure society.

Australia should follow Britain's lead in heavily fining organisations for serious data losses, according to security industry figures discussing the development with iTnews.

Local industry keen to mirror UK’s data breach fines

The recommendation followed the recent introduction of British legislation that would raise the fine for a serious data breach from £5,000 (AUD$8190) to £500,000 (AUD$819 000) from 6 April.

"The UK has shown a strong lead in allowing the Information Commissioner's Office to levy hefty fines under the Data Protection Act (DPA)," said Amichai Shulman, CTO of security vendor Imperva.

"Clearly it would benefit the rest of the world to follow this lead," he said.

British legislation imposed penalties for data breaches if a data controller was found to seriously contravene data protection principles in a way that would likely cause substantial damage.

But because the legislation was worded in a way that required the controller to know that contravention may occur, Shulman said the legislation relied on organisations being honest upon discovery of a breach.

Australia has been reviewing its privacy laws in recent years and is expected to introduce some form of mandatory disclosure regulations.

According to Australian Privacy Commissioner Karen Curtis, the Government has "agreed in principle" with Australian Law Reform Commission (ALRC) recommendations that organisations be penalised for serious privacy breaches.

The ALRC recommended that the Privacy Commissioner be given the power to seek a civil penalty in a Court for a serious or repeated breach of privacy, and that reporting of serious data breaches be mandatory.

"The Government, in its first stage response to the ALRC report, has already agreed in principle to the application of civil penalties for serious privacy breaches where other compliance orientated enforcement methods are not sufficient," Curtis told iTnews.

"The Government is still considering the issue of data breach notification."

But although the Attorney-General's department currently has the authority to investigate and penalise companies for data breaches, this power was rarely enforced, local security expert Chris Gatford told iTnews.

"There's no policy that enforces data loss disclosure," said Gatford, the director of Australian penetration testing company HackLabs.

"We've got to have something [to promote data protection] in Australia; the sooner Australia has regulations about data loss, the sooner society as a whole will potentially be better secured."

Gatford recommended "bad press and hefty fines" to keep organisations wary of data loss, which ultimately would fall to IT security and risk management teams to prevent.

Meanwhile, Imperva's Shulman warned that legislation should focus on keeping data secure, rather than disclosure, lest organisations focus on protecting themselves instead of their data.

"Penalties may be necessary, but governments should try to be constructive and focus regulations on the protection side rather than on the disclosure side," he said.

The Office of the Privacy Commissioner has received 24 data breach notifications this financial year. Curtis said each notification was taken seriously, and her office often worked with the organisations involved to minimise damage and limit the possibilities of future breaches.

"My Office believes that constructive engagement with businesses and government agencies to learn lessons and build strong and robust systems and practices is the primary means of ensuring good privacy outcomes," she told iTnews.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
actbreachbritishdatadssimpervalegislationlosspciprotectionsecurityuk

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
AI is delivering business value today
Partner Content AI is delivering business value today
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.