On 14 November 2023, the Australian Signals Directorate (ASD) published its 2022-2023 Annual Cyber Threat Report (Report). This Report reveals key trends to understand in cybercrime facing Australian governments, business and individuals.
This Report can help those in the education and for-purpose sectors to understand how the current state of cybercrime in Australia may affect their organisation.
The ASD runs the Australian Cyber Security Centre (ACSC), which is the Australian Government’s technical authority on cyber security and has a 24-hour hotline for advice about and reporting of cyber threats and incidents (1300 CYBER1, or 1300 292 371).
The graph above shows the top 10 sectors of reporting to the ACSC and the percentage the reporting represents of the entire financial year. Most relevant to the Moores community of value-align clients is that both education and training, and healthcare and social assistance were sectors in the top 5.
While this shows a high risk of being a target of a cybercrime, it can also reveal strong awareness in these industries with high levels of reporting.
The ASD recommends all Australian organisations:
The 2022-2023 Annual Cyber Threat Report reveals the significant threat of ransomware.
Around 10% of all cyber security incidents in 2022-23 involved ransomware. The ASD advises against paying ransoms.
The report also reveals that 8.7% of reported ransomware-related cyber security incidents came from the healthcare and social assistance sector.
It is important to note that a quarter of the ransomware reports also involved confirmed data exfiltration where the actor extorts the victim for both data decryption and the non-publication of data.
Understanding the education and for-purpose sectors in which our clients operate, we can provide tailored cyber security and privacy advice and support. We can help you take practical steps to uplift your cyber security, looking to the human elements as well as the technical. We like to think about information management as an opportunity to grow your organisation.
Please contact us for more detailed and tailored help.
Subscribe to our email updates and receive our articles directly in your inbox.
Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.
In September 2023 TikTok was fined 345 million euros (the equivalent of $575 million AUD) by the Irish Data Protection Commission (DPC) under the European General Data Protection Regulation (GDPR) for breaches in its processes of children’s personal data. The basis for the fine is a lack of transparency through vague language explaining TikTok’s data handling processes and a failure to implement privacy-by-design in automatically making children’s accounts public. Another important part of the decision is consideration of age-verification measures.
We have written previously about children’s privacy, as it is an intersection of privacy and child safety similar to our annual eSafety campaigns for Safer Internet Day each February. More information on these topics is here:
This article considers three key aspects of the TikTok fine – transparency, privacy-by-design, and age-verification measures – in the context of Australian privacy regulation as it is relevant for charities and schools who work with children.
Transparency is a pillar of privacy regulation, in both Europe and Australia. In the TikTok decision, the DPC took issue with certain vague words: the use of “public,” “everyone” and “anyone” to describe who could see a user’s account was not sufficiently clear as to whether that meant all registered TikTok users or anyone who could access the platform. Another transparency breach was the failure to provide information about TikTok’s information handling processes in a concise, transparent, intelligible and easily accessible form, using clear and plain language. We encourage all organisations to ensure their privacy policies and collection notices are clear, easy to understand and tailored to their particular audience.
In Australia, Australian Privacy Principle 1 enshrines openness and transparency as requirements for how organisations handle personal information. Specifically, openness and transparency means:
Further, improving transparency of organisations and control of individuals is a key aim of proposed amendments to the Privacy Act 1988 (Cth).1 The reforms propose to increase transparency and control with improved notice and consent mechanisms. This is, in part, in response to the 2023 Office of the Australian Information Commissioner (OAIC) Australian Community Attitudes to Privacy Survey which showed that 84% of Australians want more control over the collection and use of their personal information.
For charities and schools, ensuring you provide transparency and control is critical to maintaining a strong and healthy relationship of trust with your community members. Transparency is a pillar of privacy regulation because privacy recognises that handling over information about ourselves or our children can be personal; similar to handling over part of our identity. Privacy, and transparency, is inherently about trust.
We previously discussed what we mean by privacy-by-design in a recent article. For TikTok, it was found that making children’s accounts public by default is inconsistent with the GDPR’s data protection by design and default obligations. This was partly because TikTok, through its web browser version, can be access by non-registered users; i.e., the public at large. An additional, specific setting was required to “Go private”.
In Australia, no obligation regarding privacy-be-design currently exists. The inclusion of a privacy-by-design requirement is possible in the proposed amendments. What the government has committed to is to implement “new organisational accountability requirements [that] will encourage entities to incorporate privacy-by-design into their operating processes.” Regardless of a compliance obligation, privacy-by-design is a strong risk mitigation step against the threat of data breaches because:
Privacy-by-design is particularly relevant to children’s privacy, as the Government agrees with the recommendation from the Attorney-General’s Department to introduce a Children’s Online Privacy code.2 The code would apply to online services that are likely to be accessed by children.
However, the decision is novel from a pan-European/EDPB (European Data Protection Board) perspective insofar as it is the first to examine age-verification measures against the backdrop of the GDPR. While the EDPB’s dispute resolution procedure, in an arguably rather odd way, directed the DPC to reach an inconclusive outcome, there are some important markers digital services with a mixed user population should note, as they may be indicators of future regulatory approaches to age verification.
The decision reaffirms the major focus of European regulators — and moreover the DPC as the bloc leader in this area — on children’s data. This is a topic we expect to see increasingly more often in regulatory investigations and enforcement decisions.
The DPC’s findings regarding the risks to children from the processing of their data are informative of how the DPC will expect organisations to assess such risks in relation to their own processing operations.
Finally, the decision also signals the EDPB’s willingness to use the fairness principle to bolt on additional findings of infringement at the dispute resolution stage, even where the lead supervisory authority’s investigation did include such an issue within its scope.
Read our latest article more detail on how the DCP came to their decision against TikTok.
With the growing focus from both Europe and Australia on children’s data, organisations that work with children must take careful consideration of how they handle personal information.
Our privacy and data security team work with organisations to create workable and compliant privacy frameworks, and implement information handling practices that are resilient to data security threats. Our deep understanding of the education and not-for-profit sectors means that we are well equipped to support organisation that work with children on privacy requirements.
1Australian Government, Government Response to the Privacy Act Review Report (28 September 2023).
2Australian Government, Government Response to the Privacy Act Review Report (28 September 2023), page 13; Attorney-General’s Department, Privacy Act Review: Final Report (23 February 2023) Proposal 16.5.
Children are particularly vulnerable to online harms. The increasing profile and powers of the eSafety Commissioner under the Online Safety Act 2021 (Cth) is partly designed to address this vulnerability, as are some of the possible amendments to the Privacy Act 1988 (Cth) (Privacy Act). Children increasingly rely on online platforms, social media, mobile applications and other internet connected devices in their everyday lives. While acknowledging the many benefits these services provide to children and young people, there is equally a concern that thousands of data points are being collected, including information about their activities, location, gender, interests, hobbies, moods, mental health and relationship status.
The 2023 Australian Community Attitudes to Privacy survey results showed:
The Government Response to the Privacy Act Review has provided more clarity on the likely changes to the Privacy Act to better protect children’s privacy.
Amendments we are likely to see include:
Whereas the Government Response adopts only 38 of the 116 recommendations from the Attorney-General’s Department’s February Report, the area of children’s privacy is one space where many of the recommendations are agreed to.
Being committed to working with organisations on child safety and the safeguarding of other vulnerable Australians, Moores is well positioned to empower your organisation to implement these privacy changes for organisations who work with children and vulnerable Australians. It is most commonly individuals who are already vulnerable who face greater risks of harm from interference with their privacy. More details about how we can help with privacy and data security is here.
The Privacy Act Review has been a work in progress since 12 December 2019, initially in response to the Australian Competition and Consumer Commission’s Digital Platforms Inquiry. Throughout this journey we have endeavoured to keep our community up-to-date, through our article series:
Now we have the next step in the process: the Government Response to the Privacy Act Review which responds to the Attorney-General’s Department Report published in February 2023 and adopts 38 of the 116 recommendations. Other recommendations are agreed to “in principle”. The Government Response has narrowed proposed amendments into five categories:
We explain these categories in more detail below.
This means changing the scope and application of the Privacy Act 1988 (Cth) (Privacy Act) to apply to a broader range of information and entities. For example:
The Government agrees in-principle that the small business exemption should be removed in light of the privacy risks applicable in the digital environment.1
However, the small business exemption will not be removed from the Privacy Act until further consultation has been undertaken and supports are afforded to small businesses to assist compliance.
We’ve written previously about how privacy-by-design can help future-proof your operations for subsequent privacy breaches or data breaches. Now we have an official statement that:
The Government agrees in-principle that privacy settings for online services should reflect the ‘privacy-by-default’ framework of the Privacy Act.2
This is part of the possible amendments that collection, use and disclosure must be fair and reasonable in the circumstances, distinct from other requirements to collect or disclose such as consent. A fair and reasonable threshold for collection, use and disclosure is said to partly address “dark patterns” which are designs in systems and processes to nudge users towards consenting to more privacy intrusive practices.
An uplift in protections will likely also see more detail included in the Privacy Act as to what reasonable steps to secure personal information entail; that is, it entails both technical and organisational measures. Retention is another feature:
The Government agrees in-principle that entities should be required to establish their own maximum and minimum retention periods for personal information they hold and specify these retention periods in privacy policies.3
Some organisations will already have strict retention policies, such as schools in Victoria who are required to adhere to the Public Records Office Victoria Recordkeeping standards under Ministerial Order 1359. Another major possible change is the reduction in the notification period under the Notifiable Data Breach Scheme to 72 hours. Again, this is only agreed to “in principle” and further consultation is flagged as the next step.
This includes introducing definitions of key terms, such as collection, disclosure and consent. Another key change would be the introduction of a distinction between controllers and processors of personal information. These are terms found in the European Union’s General Data Protection Regulation (GDPR); generally considered the global gold standard in privacy protections for individuals. Aligning with the GDPR is acknowledged to “reflect the operational reality of modern business relationships, and reduce the compliance burden for entities acting as processors”.4
To further support international trade and business, the Government agrees a mechanism should be introduced to prescribe countries with substantially similar privacy laws. This replicates the function of adequacy decisions under the GDPR.
Australians overwhelmingly (84%) want more control over their data. While privacy policies and collection notices are intended to provide individuals with transparency, consultation revealed concerns that privacy policies and collection notices are often complex, lengthy, legalistic and vague. To address this, the Government agrees in-principle that:
We may also see the introduction of individual rights in addition to the existing rights of access and correction. These could include the right to an explanation of how information is used and the right to require deletion (i.e., similar to the GDPR’s right to erasure). Individuals could also be given the ability to bring legal action under a statutory tort for serious invasions of privacy, which would be based on a model proposed by the Australian Law Reform Commission in 2014.5
While we saw increased penalties for serious interference with privacy introduced in 2022, there is a possibility for:
There are a lot of proposed reforms, but no Bill before Parliament as yet. At this stage, we recommend organisations focus on getting their house in order to prepare for changes to the law. One place you can start is to reflect on what data you collect and where you store it. We can help with this first stage through a Privacy Audit, designed to map your information handling practices and identify areas for improvement. We can work with you to address any more specific concerns your may have to design a tailored product for your organisation. More details about how we can help with privacy and data security is here.
1 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 7.
2 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 9.
3 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 10.
4 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 17.
5 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 21; Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era (ALRC Report 123) 3 September 2014.
The statistics are in. The Office of the Australian Information Commissioner (OAIC) conducted a survey of Australians this year and the results show privacy is a growing concern and priority for Australians.
Privacy is inherently about trust and identity. By sharing personal information about themselves with your organisation, individuals are placing trust in your organisation that you will respect their identity – our information or data is an extension of self-expression and identity.
To grow this trust, we recommend organisations:
As a starting point to take steps in making privacy a priority, you can:
We know you are busy. We know many of our clients include the role of Privacy Officer in a broader risk and compliance role. We can support you with directions of how to start through our online publications – such as our Privacy Toolkit – or we can take on these projects for you. This can be a full privacy audit that will start with mapping your data assets, reviewing your information handling practices and processes, and proposing changes to systems and policies. Alternatively, we can discuss what other projects may look like for your organisation and design a tailored offering to your needs. More details about how we can help with privacy and data security is here.
1 The 2023 Australian Community Attitudes to Privacy Survey
2 For example, the Health Records Act 2001 (Vic).
If you are a charity or for-purpose organisation, you may have been following news reports in the last month (August 2023) about a privacy breach affecting “thousands of donors to Australian charities”. This article looks into an emerging trend of third-party data breaches – data breaches by contractors or service providers – where the charity or victim organisation obtaining the services has the public-facing brand name which makes it into news reports. Then we give some recommendations for what you can do about it.
A third-party data breach occurs when a malicious or criminal actor compromises a supplier, service provider or contractor to gain access to sensitive information or systems at the victim organisation’s customers, clients or business partners. For example:
Third-party data breaches are increasing because of the increased uptake of contracted automation and efficiencies, the imperative for not-for-profits to optimise their support and contact databases and increased criminal activity via hacking. Many not-for-profit organisations may not know, or take responsibility, for where their data goes when working with other organisations. Often, they simply trust that the third party has adequate systems in place. Further, charities, schools and other for-purpose organisations may have many different service providers and contractors with whom different information is being shared. This means it is difficult to know where your data is.
Knowing where your data is was the principal recommendation of Victorian Privacy and Data Protection Commissioner, Rachel Dixon, during Privacy Awareness Week in May 2023.
“Know what data you hold, and where it is.”
In more technical terms, this is referred to as data mapping, or visualising your organisation’s data assets. Data mapping sets you up to take action to protect that data. It will also prepare your organisation to respond to pending amendments to the Privacy Act 1988 (Cth).
Another recommendation to mitigate the risks of third-party data breaches is to include privacy requirements in your contracts with these service providers. Your contracts should:
Incorporating privacy-by-design into your information systems can help reduce the risk of data breaches, by implementing systemic protections to avoid the circumstances that lead to a breach even arising. Privacy-by-design is the idea of building privacy protections into processes to make good privacy practices a part of normal, everyday practice – making them the “default setting”.
In this context, this would be systemic protocols or restrictions of the sharing of information with third parties, such as a restriction on the downloading and exporting of client, donor or student data so only certain staff can do this, or the data must be shared in a specific way that has been considered and approved by the Privacy Officer.
We can help you with data mapping, contracting with service providers and redesigning your information systems with privacy-by-design in mind. If you have unfortunately been affected by the data breach currently in the media, we can support you in your response and risk mitigation. Contact us to hear more about these services and our perennially popular privacy and data breach training.
If you operate in Victoria or New South Wales, these states’ health privacy laws apply directly to your organisation regarding health information. If you are starting to collect vaccination information from workers or stakeholders in Victoria and New South Wales, you need to think about health privacy and the Privacy Act. Victoria and New South Wales both have information privacy principles and health privacy principles that apply specifically to health information.
If you operate in other states or territories across Australia, those states’ privacy laws many apply though a funding contract. More information about the various privacy principles is in our recent article: Health privacy: are you prepared to collect vaccination status and meet privacy obligations?
State contracts for funding, grants or the provision of goods and services to government organisations can include requirements that your organisation must comply with the privacy laws of that State or Territory.
Government departments often face a requirement that they impose the same standards on contractors.* This is to ensure that government information when disclosed from the government to your organisation for purposes under the contract, that information is handled according to the same standards applying to that government.
In addition to requiring your organisation to comply with certain privacy principles, the contract terms may also require training or breach reporting.
Charities with less than $3 million annual turnover are not bound by the Privacy Act, however, the same contractual obligations may be imposed by contracts with the Commonwealth government. This contracted service provider requirement overrides the small business exemption.**
This would mean the Australian Privacy Principles would apply, as well as the Notifiable Data Breach scheme.
While there are many different privacy principles across Australia, the foundational concepts have strong similarities.
You should always endeavour to meet the higher standard. Often, health privacy principles will have tighter restrictions on the handling of health information, again reflecting the intrusiveness and personal nature of someone’s health information.
If your organisation is preparing to collect vaccination information from employees, clients or other stakeholders, we recommend reflecting on what privacy laws apply to your organisation – including health privacy principles. Now is the time to implement strong collection and security measures for health information such as vaccination status.
Vaccination status is considered health information and therefore sensitive information in most jurisdictions across Australia. This means stricter requirements on how you collect, use, disclose and store that information.
The below mind map contains some ideas and concepts relevant to protecting vaccination information.
Our privacy team can help you identify gaps in your current information handling practices to ensure you are meeting all applicable requirements. We can help redesign information flows and storage through your organisation to ensure compliance and protection of your data assets at all times of the information lifecycle.
Please contact us.
* Information Privacy Act 2000 (Vic) s 17; Information Act 2002 (NT) s 149.** Privacy Act 1988 (Cth) s 6D(4)(e).
Victorian schools and education providers are now captured by the Child Information Sharing Scheme (CISS). This changes privacy, child safety and regulatory implications and risks. Schools should be aware of how CISS operates and its impact on other parts of school governance and compliance.
CISS facilitates the sharing of confidential information between organisations that work with children to promote the wellbeing and safety of those children. CISS aims to remove barriers to information sharing to best facilitate early identification and remediation of child abuse, neglect or other risks to child wellbeing and safety.
The CISS commenced on 3 September 2019. Schools and education providers are captured in phase 2 which commenced on 19 April 2021. (Phase 2 was delayed in 2020 due to COVID-19.)
With phase 2 now in force, the CISS has expanded to capture:
Information sharing can occur between any of these organisations. Organisations that are captured are referred to in the CISS as Information Sharing Entities (ISEs).
Under the CISS, an ISE can:
When an ISE receives an information request, it must assess the request against a three step test.
Schools – as ISEs – must respond to requests from other ISEs in a timely manner. If the sharing meets the three step threshold test, you must share the information. If the test is not met, you cannot share the information but you must respond to the request with an explanation in writing.
The CISS regime includes legislative principles to guide the collection, use or disclosure of confidential information. It is a principle of the CISS regime that ISEs give precedence to the wellbeing and safety of a child over the right to privacy.
The use or disclosure of confidential information under the CISS regime in good faith and with reasonable care does not constitute a contravention of any other Act.
For independent and catholic schools that also must comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), disclosure under the CISS is permitted by APP 6.2(b) where it is authorised by law.
This means that where a disclosure is made in compliance with the CISS, it is not a privacy breach. However, if schools do not meet the regulatory requirements of the CISS, the disclosure may also be a privacy breach.
You may need to review your privacy policy, privacy procedures, and data security protocols, confidentiality policies, and consent and release of information forms.
Moores has extensive experience in privacy, child safety and regulation and is well placed to assist schools and other organisations in preparing for and implementing the CISS. For more information, please do not hesitate to contact us.
Closure of the school gates may have brought relief from some concerns, but moving to online learning and keeping the school afloat bring continuing obligations.
School boards need to continue to meet and govern the school, even when students are not on campus.
These challenging times are also a test of the Board’s effectives. It’s easy to be a leader when everything is going well. But, in the words of a fellow cancer survivor, Mary Tyler Moore, You can’t be brave if you’ve only had wonderful things happen to you.
Here are our top tips for Boards and the leadership team of key considerations to keep in mind as schools move online.
This does not stop. The requirements of Ministerial Order 870 include that the Board (or other governing authority) develop strategies for embedding a culture of child safety at the school. The Board needs to (among other things) develop risk management strategies pertinent to the online environment, and still vet teachers, still have reporting channels for reports of suspected child abuse and deliver education to children about standards of behaviour.
Some immediate tips to consider:
Zoom-hosted and other virtual classrooms raise issues of privacy. Parents should not participate or conduct conversations in virtual classrooms, even if present to supervise. Similarly, educators should not refer to ill students or family members other than “they are away from school today”.
Groups of children online need to be reminded about cyber-bullying. The usual rules need to be emphasised, as does parent control over devices. They should be inaccessible at night, despite the changes. Consider if teachers are able to monitor conversations between students that occur on school sanctioned online platforms, recognising that it is likely that the school’s duty of care will extend to any cyber-bullying or inappropriate messaging that occurs on school platforms.
Check all provider contracts and their cancellation clauses. Do not assume a refund is available. Earlier termination may be considered better, but beware fixed term contracts – you may have to pay them out in full, unless you can point to “frustration” or external factors.
Many contracts will allow the builders to walk offsite and make this the school’s problem. Check the force majeure clause to see whether the school has rights to terminate and/or receive back deposits paid.
Check lease terms to understand the implications of non-payment of rent. Re-negotiate rent holidays early.
Consider what you will do if an enrolment agreement allows the school to terminate, particularly around behaviour. Will the duty of care mean you have to find another school for any students that the school terminates? If terminating for non-payment, what is the school’s credit policy? Does this need to be reviewed? Will the school prefer to keep enrolments, and the funding? Note you will need a sufficient number of non-parent board members to vote on any changes to fee or credit policies, because parent board members will need to declare a conflict of interest.
Does your constitution actually allow this? Many are too old and were drafted before emails and telemeetings existed. You may need to amend the constitution to ensure your resolutions are valid in online meetings (query if you can hold a members’ meeting). Furthermore, given the need for fast decision making during these critical times, consider if your constitution allows resolutions to be made by circulation and ensure you are complying with the requisite notice requirements before voting on resolutions.
Directors must ensure the school is solvent – this is a directors’ duty. Even though the law has been temporarily changed to allow insolvent trading in the ordinary course of business for a period of 6 months, the usual rules of good decision making apply. The laws have been relaxed, not repealed, so directors are still required to exercise sound judgment and not breach other directors’ duties. For example, causing school insolvency by entering into a prohibited arrangement would still be an issue. Entering into a modelled temporary insolvency to pay staff who are still working and who will be needed after the crisis, in the context of considered and suitable cost cutting, would be much less problematic.
Flexibility and workforce restructuring need to be considered.
What measures do you need to ensure wellbeing and connectedness? Will children be in uniform/complying with dress code? (Some schools say uniform only required on the visible top half). How will distressed students access school counsellors?
Moores is still working and available 24/7 to support you. For more information or guidance, please do not hesitate contact us.
The Office of the Australian Information Commissioner (OAIC) just released the following latest notifiable data breach statistics from 1 July to December 2019:
Whilst not the largest reporting sector, private education providers were responsible for 9% of all breaches, which is arguably an over-representation from the sector. Of these breaches, 61% were due to a malicious or criminal attack. Four percent of all breaches were committed by entities in the “personal services” sector, which includes community services and childcare centres. The highest reporting sector was the health sector, notifying 22% of all breaches.
Under the Notifiable Data Breach Scheme, a data breach is ‘eligible’ where:
Moores can assist with drafting or reviewing current policies and procedures to ensure that they are tailored to your organisation’s needs and consistent with best practice to minimise risk and liability. For more information, please do not hesitate to contact us.