Australia's Mandatory Data Breach Notification Bill Revealed
mask.of.sanity writes "Australia's plans for a data breach notification scheme have been revealed which will force organizations to report serious breaches to affected victims. The plans, which are still in a draft form, show that the country's privacy commissioner could force businesses to inform press if the breaches are bad enough, pursue fines of up to $1.7 million for organizations that are repeatedly breached and force businesses to adopt stronger security controls."
I know I am restating the obvious, but I find it interesting how no one is ever responsible for the security breach...
Just got a note from LivingSocial -- they inform me of the fact and tell me to reset my password. Almost like this is a force of nature event and not a screw up on their part for having been breached. Perhaps at least repeat offenders should be held responsible?
I know summaries are meant to be hyperbolic, but given you only have to take "reasonable steps" to secure customer data, there's not going to be too many $1.7 million repeat-offender fines meted out.
The most surprising thing is that Australia has a Privacy Commissioner.
From what I read in the press that is the exact opposite of what I would expect from that government.
Sig Battery depleted. Reverting to safe mode.
It appears to take a conservative approach in its demand for data breaches to be reported, with only classifications of serious data breaches considered
Australian privacy regulations are a total joke. The privacy commissioner is a bureaucrat with no power. Businesses take, steal, trade, share, sell and harvest personal details willy nilly and there's no oversight or punishment whatsoever. How do they accomplish this? They set up shell companies which they use to harvest, trade and purchase personal data then shut down the companies after they've 'purchased' the data from them. "No Mr privacy commissioner, it wasn't us. It was company ABC which unfortunately .. is now a defunct corporation so there's no way to know how they got those private details. But before they closed up business in the floor below us, they assured us that everything was perfectly legal. Honest to goodness sir, there's simply nothing we can do!"
.. 'ties' to large marketing companies. Banks track purchases for the police (with no oversite or warrant), personal details are sold straight out of ATO records, supermarkets track every single purchase a person makes throughout their lives trading this to whomever they consider a 'business partner' and the consumer (if they manage to discover a company has their details) doesn't even have the right to have those details removed from the company's database.
.. the content in this post is not assumption or guess work, I've personally experienced everything listed here.
Privacy isn't even a remotely important priority. Anything that's raised as a bill is going to be full of loopholes like swiss cheese, because the political representatives in Australia include people with (how shall I put this gently)
BTW
I'm not sure what black-magic software companies and webservice providers incanted to manage to exempt themselves from traditional product-liability law. If you sell a widget and your design was shit in a way that causes monetary damages, traditionally you are liable. If you sell a widget and your design sucks so bad that it doesn't even work (even without causing real damages), then people are at least entitled to a refund. But software somehow avoids this: your design can be buggy as hell and somehow you are not liable for shipping a shit product that didn't fulfill its advertised purpose and may have actually actively harmed people.
This bill seems to just take one small step towards restoring some minimal degree of responsibility for your product.
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
I misread the title. The meaning is quite different with the word "Bill" removed.
fines of up to $1.7 million
or all change in the CEO's pocket, whatever is greater?
Contrary to the popular belief, there indeed is no God.
Parent has been modded troll? It wasn't OT, it wasn't a "frist post" although it did lack meaningful content... but most jokes or attempts at them do. I'm surprised by the modding on this occasion.
Is this bill PR to divert attention? The government has given itself permission to breach privacy anyways: http://www.news.com.au/technology/nicola-roxon-backflip-gives-green-light-for-online-spying/story-e6frfro0-1226464553027 http://www.theaustralian.com.au/australian-it/government/data-retention-laws-risky-canberra-told/story-fn4htb9o-1226465841909