On 14 November 2023, the Australian Signals Directorate (ASD) published its 2022-2023 Annual Cyber Threat Report (Report). This Report reveals key trends to understand in cybercrime facing Australian governments, business and individuals.

This Report can help those in the education and for-purpose sectors to understand how the current state of cybercrime in Australia may affect their organisation.

The ASD runs the Australian Cyber Security Centre (ACSC), which is the Australian Government’s technical authority on cyber security and has a 24-hour hotline for advice about and reporting of cyber threats and incidents (1300 CYBER1, or 1300 292 371).

The top reporting sectors reporting cybercrime to the Australian Cyber Security Centre

Graph showing top 10 reporting sectors with educational and training highlighted

The graph above shows the top 10 sectors of reporting to the ACSC and the percentage the reporting represents of the entire financial year. Most relevant to the Moores community of value-align clients is that both education and training, and healthcare and social assistance were sectors in the top 5.

  • 6.7% of reports to the ACSC were from the Education and Training sector.
  • 5.9% of reports to the ACSC were from the Healthcare and Social Assistance sector.

While this shows a high risk of being a target of a cybercrime, it can also reveal strong awareness in these industries with high levels of reporting.

Recommendations from the ASD for all Australian organisations

The ASD recommends all Australian organisations:

  • only use reputable cloud service providers and managed service providers that implement appropriate cyber security measures;
  • review the cyber security posture of remote workers, including their use of communication, collaboration and business productivity software;
  • implement relevant guidance from ASD’s Essential Eight Maturity Model, Strategies to Mitigate Cyber Security Incidents and Information Security Manual;
  • regularly test cyber security detection, incident response, business continuity and disaster recovery plans;
  • train staff on cyber security matters, in particular how to recognise scams and phishing attempts; and
  • report cybercrime and cyber security incidents to ReportCyber.

Ransomware is the most destructive cybercrime threat

The 2022-2023 Annual Cyber Threat Report reveals the significant threat of ransomware.

Around 10% of all cyber security incidents in 2022-23 involved ransomware. The ASD advises against paying ransoms.

The report also reveals that 8.7% of reported ransomware-related cyber security incidents came from the healthcare and social assistance sector.

Pie graph showing 10% of attacks as ransomware

It is important to note that a quarter of the ransomware reports also involved confirmed data exfiltration where the actor extorts the victim for both data decryption and the non-publication of data.

Pie graph showing 25% of ransomware as data exfiltration

How we can help

Understanding the education and for-purpose sectors in which our clients operate, we can provide tailored cyber security and privacy advice and support. We can help you take practical steps to uplift your cyber security, looking to the human elements as well as the technical. We like to think about information management as an opportunity to grow your organisation.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.

In September 2023 TikTok was fined 345 million euros (the equivalent of $575 million AUD) by the Irish Data Protection Commission (DPC) under the European General Data Protection Regulation (GDPR) for breaches in its processes of children’s personal data. The basis for the fine is a lack of transparency through vague language explaining TikTok’s data handling processes and a failure to implement privacy-by-design in automatically making children’s accounts public. Another important part of the decision is consideration of age-verification measures.

We have written previously about children’s privacy, as it is an intersection of privacy and child safety similar to our annual eSafety campaigns for Safer Internet Day each February. More information on these topics is here:

This article considers three key aspects of the TikTok fine – transparency, privacy-by-design, and age-verification measures – in the context of Australian privacy regulation as it is relevant for charities and schools who work with children.

Transparency: a pillar of privacy regulation

Transparency is a pillar of privacy regulation, in both Europe and Australia. In the TikTok decision, the DPC took issue with certain vague words: the use of “public,” “everyone” and “anyone” to describe who could see a user’s account was not sufficiently clear as to whether that meant all registered TikTok users or anyone who could access the platform. Another transparency breach was the failure to provide information about TikTok’s information handling processes in a concise, transparent, intelligible and easily accessible form, using clear and plain language. We encourage all organisations to ensure their privacy policies and collection notices are clear, easy to understand and tailored to their particular audience.

In Australia, Australian Privacy Principle 1 enshrines openness and transparency as requirements for how organisations handle personal information. Specifically, openness and transparency means:

  • taking reasonable steps to implement practices, procedures and systems to ensure you comply with the APPs and can deal with related inquiries and complaints; and
  • you have a clearly expressed and up-to-date Privacy Policy publicly available that explains how you manage the personal information you hold.

Further, improving transparency of organisations and control of individuals is a key aim of proposed amendments to the Privacy Act 1988 (Cth).1 The reforms propose to increase transparency and control with improved notice and consent mechanisms. This is, in part, in response to the 2023 Office of the Australian Information Commissioner (OAIC) Australian Community Attitudes to Privacy Survey which showed that 84% of Australians want more control over the collection and use of their personal information.

For charities and schools, ensuring you provide transparency and control is critical to maintaining a strong and healthy relationship of trust with your community members. Transparency is a pillar of privacy regulation because privacy recognises that handling over information about ourselves or our children can be personal; similar to handling over part of our identity. Privacy, and transparency, is inherently about trust.

Privacy-by-design: your pro-active tool  

We previously discussed what we mean by privacy-by-design in a recent article. For TikTok, it was found that making children’s accounts public by default is inconsistent with the GDPR’s data protection by design and default obligations. This was partly because TikTok, through its web browser version, can be access by non-registered users; i.e., the public at large. An additional, specific setting was required to “Go private”.

In Australia, no obligation regarding privacy-be-design currently exists. The inclusion of a privacy-by-design requirement is possible in the proposed amendments. What the government has committed to is to implement “new organisational accountability requirements [that] will encourage entities to incorporate privacy-by-design into their operating processes.” Regardless of a compliance obligation, privacy-by-design is a strong risk mitigation step against the threat of data breaches because:

  • privacy-by-design shifts the focus from compliance to prevention.
  • privacy-by-design increases awareness of privacy in your organisation.
  • privacy-by-design addresses human error breaches (1/3 of all notifiable data breaches) through awareness and system design.

Privacy-by-design is particularly relevant to children’s privacy, as the Government agrees with the recommendation from the Attorney-General’s Department to introduce a Children’s Online Privacy code.2 The code would apply to online services that are likely to be accessed by children.

Age-verification: an emerging area

However, the decision is novel from a pan-European/EDPB (European Data Protection Board) perspective insofar as it is the first to examine age-verification measures against the backdrop of the GDPR. While the EDPB’s dispute resolution procedure, in an arguably rather odd way, directed the DPC to reach an inconclusive outcome, there are some important markers digital services with a mixed user population should note, as they may be indicators of future regulatory approaches to age verification. 

Other key takeaways of the Irish Data Protection Commission’s fine of TikTok

The decision reaffirms the major focus of European regulators — and moreover the DPC as the bloc leader in this area — on children’s data. This is a topic we expect to see increasingly more often in regulatory investigations and enforcement decisions.

The DPC’s findings regarding the risks to children from the processing of their data are informative of how the DPC will expect organisations to assess such risks in relation to their own processing operations.

Finally, the decision also signals the EDPB’s willingness to use the fairness principle to bolt on additional findings of infringement at the dispute resolution stage, even where the lead supervisory authority’s investigation did include such an issue within its scope.

Read our latest article more detail on how the DCP came to their decision against TikTok.

How we can help

With the growing focus from both Europe and Australia on children’s data, organisations that work with children must take careful consideration of how they handle personal information.

Our privacy and data security team work with organisations to create workable and compliant privacy frameworks, and implement information handling practices that are resilient to data security threats. Our deep understanding of the education and not-for-profit sectors means that we are well equipped to support organisation that work with children on privacy requirements.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.


1Australian Government, Government Response to the Privacy Act Review Report (28 September 2023).

2Australian Government, Government Response to the Privacy Act Review Report (28 September 2023), page 13; Attorney-General’s Department, Privacy Act Review: Final Report (23 February 2023) Proposal 16.5.

Children are particularly vulnerable to online harms. The increasing profile and powers of the eSafety Commissioner under the Online Safety Act 2021 (Cth) is partly designed to address this vulnerability, as are some of the possible amendments to the Privacy Act 1988 (Cth) (Privacy Act). Children increasingly rely on online platforms, social media, mobile applications and other internet connected devices in their everyday lives. While acknowledging the many benefits these services provide to children and young people, there is equally a concern that thousands of data points are being collected, including information about their activities, location, gender, interests, hobbies, moods, mental health and relationship status.

The 2023 Australian Community Attitudes to Privacy survey results showed:

  • protecting their child’s privacy is a major concern for 79% of Australian parents; and
  • the privacy of their children’s personal information is of high importance to 91% of parents when deciding to provide their child with access to digital devices and services.

The Government Response to the Privacy Act Review has provided more clarity on the likely changes to the Privacy Act to better protect children’s privacy.

Amendments we are likely to see to the Privacy Act

Amendments we are likely to see include:

  • that a child should be defined in the Act as an individual who has not reached 18 years of age;
  • a prohibition on targeting a child unless it is in their best interests;
  • a prohibition on trading in personal information of children;
  • a prohibition on direct marketing to children unless there was direct collection and the direct marketing is in the child’s best interests;
  • a requirement that organisations must have regard to a child’s best interest in considering if collection, use or disclosure is fair and reasonable in the circumstances
  • a Children’s Online Privacy Code to clarify how the best interests of children should be upheld in the design of online services; and
  • a requirement that valid consent must be given with capacity.

Whereas the Government Response adopts only 38 of the 116 recommendations from the Attorney-General’s Department’s February Report, the area of children’s privacy is one space where many of the recommendations are agreed to.

How we can help

Being committed to working with organisations on child safety and the safeguarding of other vulnerable Australians, Moores is well positioned to empower your organisation to implement these privacy changes for organisations who work with children and vulnerable Australians. It is most commonly individuals who are already vulnerable who face greater risks of harm from interference with their privacy. More details about how we can help with privacy and data security is here.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.

The Privacy Act Review has been a work in progress since 12 December 2019, initially in response to the Australian Competition and Consumer Commission’s Digital Platforms Inquiry. Throughout this journey we have endeavoured to keep our community up-to-date, through our article series:

Now we have the next step in the process: the Government Response to the Privacy Act Review which responds to the Attorney-General’s Department Report published in February 2023 and adopts 38 of the 116 recommendations. Other recommendations are agreed to “in principle”. The Government Response has narrowed proposed amendments into five categories:

  1. Bring the privacy act into the digital age;
  2. Uplift protections;
  3. Increase clarity and simplicity for entities and individuals;
  4. Improve transparency and control; and 
  5. Strengthen enforcement.

We explain these categories in more detail below.

Bring the privacy act into the digital age

This means changing the scope and application of the Privacy Act 1988 (Cth) (Privacy Act) to apply to a broader range of information and entities. For example:

The Government agrees in-principle that the small business exemption should be removed in light of the privacy risks applicable in the digital environment.1

However, the small business exemption will not be removed from the Privacy Act until further consultation has been undertaken and supports are afforded to small businesses to assist compliance.

Uplift protections

We’ve written previously about how privacy-by-design can help future-proof your operations for subsequent privacy breaches or data breaches. Now we have an official statement that:

The Government agrees in-principle that privacy settings for online services should reflect the ‘privacy-by-default’ framework of the Privacy Act.2

This is part of the possible amendments that collection, use and disclosure must be fair and reasonable in the circumstances, distinct from other requirements to collect or disclose such as consent. A fair and reasonable threshold for collection, use and disclosure is said to partly address “dark patterns” which are designs in systems and processes to nudge users towards consenting to more privacy intrusive practices.

An uplift in protections will likely also see more detail included in the Privacy Act as to what reasonable steps to secure personal information entail; that is, it entails both technical and organisational measures. Retention is another feature:

The Government agrees in-principle that entities should be required to establish their own maximum and minimum retention periods for personal information they hold and specify these retention periods in privacy policies.3

Some organisations will already have strict retention policies, such as schools in Victoria who are required to adhere to the Public Records Office Victoria Recordkeeping standards under Ministerial Order 1359. Another major possible change is the reduction in the notification period under the Notifiable Data Breach Scheme to 72 hours. Again, this is only agreed to “in principle” and further consultation is flagged as the next step.

Increase clarity and simplicity for entities and individuals

This includes introducing definitions of key terms, such as collection, disclosure and consent. Another key change would be the introduction of a distinction between controllers and processors of personal information. These are terms found in the European Union’s General Data Protection Regulation (GDPR); generally considered the global gold standard in privacy protections for individuals. Aligning with the GDPR is acknowledged to “reflect the operational reality of modern business relationships, and reduce the compliance burden for entities acting as processors”.4

To further support international trade and business, the Government agrees a mechanism should be introduced to prescribe countries with substantially similar privacy laws. This replicates the function of adequacy decisions under the GDPR.

Improve transparency and control

Australians overwhelmingly (84%) want more control over their data. While privacy policies and collection notices are intended to provide individuals with transparency, consultation revealed concerns that privacy policies and collection notices are often complex, lengthy, legalistic and vague. To address this, the Government agrees in-principle that:

  • privacy notices should be clear, up-to-date, concise and understandable, with appropriate accessibility measures in place;
  • standardised templates for privacy policies and privacy notices should be developed for voluntary adoption by entities. This could include standardised icons, layouts and phrases to better support consumers to make quick and informed decisions.
  • collection notices should also specify if information is collected, used or disclosed for high privacy risk activities, how to exercise individual rights and the types of personal information that may be disclosed to overseas recipients. 

We may also see the introduction of individual rights in addition to the existing rights of access and correction. These could include the right to an explanation of how information is used and the right to require deletion (i.e., similar to the GDPR’s right to erasure). Individuals could also be given the ability to bring legal action under a statutory tort for serious invasions of privacy, which would be based on a model proposed by the Australian Law Reform Commission in 2014.5

Strengthen enforcement

While we saw increased penalties for serious interference with privacy introduced in 2022, there is a possibility for:

  • a mid-tier civil penalty provision to address interferences with privacy which do not meet the threshold of being ‘serious’; and
  • a low-level civil penalty provision for specific administrative breaches of the Privacy Act and Australian Privacy Principles. 

How we can help

There are a lot of proposed reforms, but no Bill before Parliament as yet. At this stage, we recommend organisations focus on getting their house in order to prepare for changes to the law. One place you can start is to reflect on what data you collect and where you store it. We can help with this first stage through a Privacy Audit, designed to map your information handling practices and identify areas for improvement. We can work with you to address any more specific concerns your may have to design a tailored product for your organisation. More details about how we can help with privacy and data security is here.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.


1 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 7.

2 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 9.

3 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 10.

4 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 17.

5 Australian Government, Government Response Privacy Act Review Report, (28 September 2023) page 21; Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era (ALRC Report 123) 3 September 2014.

The statistics are in. The Office of the Australian Information Commissioner (OAIC) conducted a survey of Australians this year and the results show privacy is a growing concern and priority for Australians.

  • 62% of Australians surveyed see the protection of their personal information as a major concern in their life;
  • 74% of Australians surveyed consider data breaches to be one of the biggest privacy risks they face today;
  • Only 32% of Australians surveyed feel in control of their data privacy; and
  • 84% of Australians surveyed want more control and choice over the collection and use of their personal information.1
OAIC Survey results

How to prioritise privacy and build trust with stakeholders

Privacy is inherently about trust and identity. By sharing personal information about themselves with your organisation, individuals are placing trust in your organisation that you will respect their identity – our information or data is an extension of self-expression and identity.

To grow this trust, we recommend organisations:

  • Review their privacy policy to ensure it reflects current information handling practices. The requirement to have a privacy policy is based on openness and transparency about information handling practices.
  • Implement tailored, clear and concise collection statements. This will address the desire for more control and choice over the collection of personal information.
  • Only collect the information you actually need. In addition to this being recommended to reduce risks of data breaches impacting greater swathes of data, and a requirement under certain privacy legislation2, it builds trust in your stakeholders. The OAIC’s survey found less than half of people trust organisations to only collect the information they need.

Where to start in making privacy a priority

As a starting point to take steps in making privacy a priority, you can:

  • Review the detailed legislative guidance published by the OAIC for information about privacy policies and collection notices;
  • Embed a culture of Privacy Impact Assessments and privacy-by-design; and
  • Map how and where your organisation collects and stores personal information.

How we can help

We know you are busy. We know many of our clients include the role of Privacy Officer in a broader risk and compliance role. We can support you with directions of how to start through our online publications – such as our Privacy Toolkit – or we can take on these projects for you. This can be a full privacy audit that will start with mapping your data assets, reviewing your information handling practices and processes, and proposing changes to systems and policies. Alternatively, we can discuss what other projects may look like for your organisation and design a tailored offering to your needs. More details about how we can help with privacy and data security is here.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.


1 The 2023 Australian Community Attitudes to Privacy Survey

2 For example, the Health Records Act 2001 (Vic).

If you are a charity or for-purpose organisation, you may have been following news reports in the last month (August 2023) about a privacy breach affecting “thousands of donors to Australian charities”. This article looks into an emerging trend of third-party data breaches – data breaches by contractors or service providers – where the charity or victim organisation obtaining the services has the public-facing brand name which makes it into news reports. Then we give some recommendations for what you can do about it.

Third-party data breaches

A third-party data breach occurs when a malicious or criminal actor compromises a supplier, service provider or contractor to gain access to sensitive information or systems at the victim organisation’s customers, clients or business partners. For example: 

  • A school gives health information to a camp provider;
  • The camp provider is subject to the data breach;
  • It is the school whose students are affected, and so it the school which is reported in the media as having a data breach and must respond to the fall out with stakeholders.

Third-party data breaches are increasing because of the increased uptake of contracted automation and efficiencies, the imperative for not-for-profits to optimise their support and contact databases and increased criminal activity via hacking. Many not-for-profit organisations may not know, or take responsibility, for where their data goes when working with other organisations. Often, they simply trust that the third party has adequate systems in place. Further, charities, schools and other for-purpose organisations may have many different service providers and contractors with whom different information is being shared. This means it is difficult to know where your data is.

How to mitigate the risks of a third-party data breach

Knowing where your data is was the principal recommendation of Victorian Privacy and Data Protection Commissioner, Rachel Dixon, during Privacy Awareness Week in May 2023.

“Know what data you hold, and where it is.”

In more technical terms, this is referred to as data mapping, or visualising your organisation’s data assets. Data mapping sets you up to take action to protect that data. It will also prepare your organisation to respond to pending amendments to the Privacy Act 1988 (Cth).

Another recommendation to mitigate the risks of third-party data breaches is to include privacy requirements in your contracts with these service providers. Your contracts should:

  • ensure the organisation is required to comply with the Privacy Act 1988 (Cth), because there are some exemptions in the law;
  • require both organisations to tell each other about potential data breaches;
  • set out minimum data security requirements expected of the service provider; and
  • provide clear rules around data retention and destruction once is it no longer needed.

The importance of privacy-by-design

Incorporating privacy-by-design into your information systems can help reduce the risk of data breaches, by implementing systemic protections to avoid the circumstances that lead to a breach even arising. Privacy-by-design is the idea of building privacy protections into processes to make good privacy practices a part of normal, everyday practice – making them the “default setting”.

In this context, this would be systemic protocols or restrictions of the sharing of information with third parties, such as a restriction on the downloading and exporting of client, donor or student data so only certain staff can do this, or the data must be shared in a specific way that has been considered and approved by the Privacy Officer.

How we can help

We can help you with data mapping, contracting with service providers and redesigning your information systems with privacy-by-design in mind. If you have unfortunately been affected by the data breach currently in the media, we can support you in your response and risk mitigation.  Contact us to hear more about these services and our perennially popular privacy and data breach training.

Contact us

Please contact us for more detailed and tailored help.

Subscribe to our email updates and receive our articles directly in your inbox.

Disclaimer: This article provides general information only and is not intended to constitute legal advice. You should seek legal advice regarding the application of the law to you or your organisation.

Most states and territories have privacy laws that can apply in addition to the Privacy Act 1988 (Cth) (“Privacy Act“).

Health information

If you operate in Victoria or New South Wales, these states’ health privacy laws apply directly to your organisation regarding health information. If you are starting to collect vaccination information from workers or stakeholders in Victoria and New South Wales, you need to think about health privacy and the Privacy Act. Victoria and New South Wales both have information privacy principles and health privacy principles that apply specifically to health information.

If you operate in other states or territories across Australia, those states’ privacy laws many apply though a funding contract. More information about the various privacy principles is in our recent article: Health privacy: are you prepared to collect vaccination status and meet privacy obligations?

Contracts imposing privacy compliance

State contracts for funding, grants or the provision of goods and services to government organisations can include requirements that your organisation must comply with the privacy laws of that State or Territory.

Government departments often face a requirement that they impose the same standards on contractors.* This is to ensure that government information when disclosed from the government to your organisation for purposes under the contract, that information is handled according to the same standards applying to that government.

In addition to requiring your organisation to comply with certain privacy principles, the contract terms may also require training or breach reporting.

Small charities with less than $3 million annual turnover

Charities with less than $3 million annual turnover are not bound by the Privacy Act, however, the same contractual obligations may be imposed by contracts with the Commonwealth government. This contracted service provider requirement overrides the small business exemption.**

This would mean the Australian Privacy Principles would apply, as well as the Notifiable Data Breach scheme.

How do I comply with multiple regimes?

While there are many different privacy principles across Australia, the foundational concepts have strong similarities.

  • Data minimisation: minimising the amount of personal information you collect is a privacy protection that reduces intrusion into someone’s privacy and reduces an organisation’s risk of serious data breaches.
  • Consent: it is common that sensitive and health information requires consent to collection, recognising that disclosing this information impacts more greatly on a person’s privacy.
  • Autonomy and transparency: privacy laws are designed to empower people with rights to control their identity as it is known by companies. The requirements to have a policy, explain uses and disclosures and inform individuals of collection are common themes in the various privacy principles.

You should always endeavour to meet the higher standard. Often, health privacy principles will have tighter restrictions on the handling of health information, again reflecting the intrusiveness and personal nature of someone’s health information.

Health privacy – vaccination information

If your organisation is preparing to collect vaccination information from employees, clients or other stakeholders, we recommend reflecting on what privacy laws apply to your organisation – including health privacy principles. Now is the time to implement strong collection and security measures for health information such as vaccination status.

Vaccination status is considered health information and therefore sensitive information in most jurisdictions across Australia. This means stricter requirements on how you collect, use, disclose and store that information.

The below mind map contains some ideas and concepts relevant to protecting vaccination information.

mind map containing ideas and concepts relevant to protecting vaccination information

How we can help

Our privacy team can help you identify gaps in your current information handling practices to ensure you are meeting all applicable requirements. We can help redesign information flows and storage through your organisation to ensure compliance and protection of your data assets at all times of the information lifecycle.

Please contact us.

* Information Privacy Act 2000 (Vic) s 17; Information Act 2002 (NT) s 149.
** Privacy Act 1988 (Cth) s 6D(4)(e).

Victorian schools and education providers are now captured by the Child Information Sharing Scheme (CISS). This changes privacy, child safety and regulatory implications and risks. Schools should be aware of how CISS operates and its impact on other parts of school governance and compliance.

What is the CISS?

CISS facilitates the sharing of confidential information between organisations that work with children to promote the wellbeing and safety of those children. CISS aims to remove barriers to information sharing to best facilitate early identification and remediation of child abuse, neglect or other risks to child wellbeing and safety.

The CISS commenced on 3 September 2019. Schools and education providers are captured in phase 2 which commenced on 19 April 2021. (Phase 2 was delayed in 2020 due to COVID-19.)

Which organisations are captured?

With phase 2 now in force, the CISS has expanded to capture:

  • Registered schools: independent, catholic and government
  • Doctors in Schools program
  • Enhancing Mental Health in Schools program
  • Kindergartens
  • Public health services and denominational hospitals
  • Regulators including the Victorian Registration and Qualifications Authority (VRQA), Victorian Curriculum and Assessment Authority and Victorian Institute of Teaching
  • Registered medical practitioners who practises in the medical profession as a general practitioner in Victoria
  • Registered community health centres

Information sharing can occur between any of these organisations. Organisations that are captured are referred to in the CISS as Information Sharing Entities (ISEs).

Key obligations under the CISS

Under the CISS, an ISE can:

  • Share information proactively to other ISEs
  • Make a request for information; and
  • Share information in response to a request from another ISE.

When an ISE receives an information request, it must assess the request against a three step test. 

  1. Would sharing the information promote the wellbeing and safety of the child or children concerned?
  2. Would sharing the information help the receiving ISE either:
    • make a decision, assessment or plan,
    • start or conduct an investigation,
    • provide a service, and/or
    • manage any risk?
  3. Is the information excluded information that cannot be shared under the CISS?

Schools – as ISEs – must respond to requests from other ISEs in a timely manner. If the sharing meets the three step threshold test, you must share the information. If the test is not met, you cannot share the information but you must respond to the request with an explanation in writing.

CISS and Privacy

The CISS regime includes legislative principles to guide the collection, use or disclosure of confidential information. It is a principle of the CISS regime that ISEs give precedence to the wellbeing and safety of a child over the right to privacy.

The use or disclosure of confidential information under the CISS regime in good faith and with reasonable care does not constitute a contravention of any other Act.

For independent and catholic schools that also must comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), disclosure under the CISS is permitted by APP 6.2(b) where it is authorised by law.

This means that where a disclosure is made in compliance with the CISS, it is not a privacy breach. However, if schools do not meet the regulatory requirements of the CISS, the disclosure may also be a privacy breach.

You may need to review your privacy policy, privacy procedures, and data security protocols, confidentiality policies, and consent and release of information forms.

We recommend that organisations:

  • Train your staff – The CISS needs to be administered by staff members who will need training to understand when to make a request for information and how to respond to requests. For organisations also caught by FVISS, training will be needed for employees on the interaction between the two schemes.
  • Review your policies and procedures – The CISS has significant implications for organisations, particularly in terms of privacy and child safety. These policies and procedures need to be reviewed and amended to align with the CISS, as well as other documents such as enrolment contracts and collection notices.
  • Communicate to your stakeholders – While the CISS assists organisations to better share information for the wellbeing of children, the increased sharing of information could concern children and their families. It is important organisations mitigate any relationship risks that could arise by clearly communicating when it will share information under the CISS and how this will impact confidentiality and privacy.
  • Seek strategic advice – For the organisations captured in the second phase of the CISS, this type of information sharing will likely be a substantial departure from previous practice. Organisations should carefully consider how they will roll out the CISS, embed it into their operations and comply with the complex legislative framework as well as their other obligations.

How we can help

Moores has extensive experience in privacy, child safety and regulation and is well placed to assist schools and other organisations in preparing for and implementing the CISS. For more information, please do not hesitate to contact us.

Closure of the school gates may have brought relief from some concerns, but moving to online learning and keeping the school afloat bring continuing obligations.

School boards need to continue to meet and govern the school, even when students are not on campus.

These challenging times are also a test of the Board’s effectives. It’s easy to be a leader when everything is going well. But, in the words of a fellow cancer survivor, Mary Tyler Moore, You can’t be brave if you’ve only had wonderful things happen to you.

Here are our top tips for Boards and the leadership team of key considerations to keep in mind as schools move online.

Child Safety

This does not stop. The requirements of Ministerial Order 870 include that the Board (or other governing authority) develop strategies for embedding a culture of child safety at the school. The Board needs to (among other things) develop risk management strategies pertinent to the online environment, and still vet teachers, still have reporting channels for reports of suspected child abuse and deliver education to children about standards of behaviour. 

Some immediate tips to consider:

  • Are teachers allowed to separately tutor students one-on-one?
  • Is there a protocol about students and staff creating chat rooms or study groups (potentially on unsecure platforms) and/or creating separate Zoom groups within a current Zoom virtual classroom?
  • Do your policies, procedures and codes of conduct need to be updated to reflect an online teaching environment?
  • Do your staff need training on how to maintain a child safe environment and their continuing obligations?

Privacy

Zoom-hosted and other virtual classrooms raise issues of privacy. Parents should not participate or conduct conversations in virtual classrooms, even if present to supervise. Similarly, educators should not refer to ill students or family members other than “they are away from school today”.

Risk Management

Groups of children online need to be reminded about cyber-bullying.  The usual rules need to be emphasised, as does parent control over devices.  They should be inaccessible at night, despite the changes. Consider if teachers are able to monitor conversations between students that occur on school sanctioned online platforms, recognising that it is likely that the school’s duty of care will extend to any cyber-bullying or inappropriate messaging that occurs on school platforms.

Cancellation Fees & Refunds

Check all provider contracts and their cancellation clauses. Do not assume a refund is available.  Earlier termination may be considered better, but beware fixed term contracts – you may have to pay them out in full, unless you can point to “frustration” or external factors.

Building Projects

Many contracts will allow the builders to walk offsite and make this the school’s problem. Check the force majeure clause to see whether the school has rights to terminate and/or receive back deposits paid.

Leases

Check lease terms to understand the implications of non-payment of rent. Re-negotiate rent holidays early.

Enrolments, behaviour and payment terms

Consider what you will do if an enrolment agreement allows the school to terminate, particularly around behaviour. Will the duty of care mean you have to find another school for any students that the school terminates? If terminating for non-payment, what is the school’s credit policy? Does this need to be reviewed? Will the school prefer to keep enrolments, and the funding? Note you will need a sufficient number of non-parent board members to vote on any changes to fee or credit policies, because parent board members will need to declare a conflict of interest.

Holding board meetings electronically

Does your constitution actually allow this? Many are too old and were drafted before emails and telemeetings existed. You may need to amend the constitution to ensure your resolutions are valid in online meetings (query if you can hold a members’ meeting). Furthermore, given the need for fast decision making during these critical times, consider if your constitution allows resolutions to be made by circulation and ensure you are complying with the requisite notice requirements before voting on resolutions.

Solvency and Deeds of Indemnity

Directors must ensure the school is solvent – this is a directors’ duty. Even though the law has been temporarily changed to allow insolvent trading in the ordinary course of business for a period of 6 months, the usual rules of good decision making apply. The laws have been relaxed, not repealed, so directors are still required to exercise sound judgment and not breach other directors’ duties. For example, causing school insolvency by entering into a prohibited arrangement would still be an issue. Entering into a modelled temporary insolvency to pay staff who are still working and who will be needed after the crisis, in the context of considered and suitable cost cutting, would be much less problematic.

Workplace Relations

Flexibility and workforce restructuring need to be considered.

What measures do you need to ensure wellbeing and connectedness? Will children be in uniform/complying with dress code? (Some schools say uniform only required on the visible top half). How will distressed students access school counsellors?

How we can help

Moores is still working and available 24/7 to support you. For more information or guidance, please do not hesitate contact us.

The Office of the Australian Information Commissioner (OAIC) just released the following latest notifiable data breach statistics from 1 July to December 2019:

  • 537 notifications (increased from 460 between 1 January and 30 June 2019)
  • 32% of these due to human error (down from 34% in the last reporting period)
  • 64% of these due to malicious or criminal attacks – this remains the leading cause of data breaches across Australia.
  • 4% of these are system faults.

Whilst not the largest reporting sector, private education providers were responsible for 9% of all breaches, which is arguably an over-representation from the sector. Of these breaches, 61% were due to a malicious or criminal attack. Four percent of all breaches were committed by entities in the “personal services” sector, which includes community services and childcare centres. The highest reporting sector was the health sector, notifying 22% of all breaches.

What is an eligible data breach?

Under the Notifiable Data Breach Scheme, a data breach is ‘eligible’ where:

  1. there is unauthorised access or an unauthorised disclosure of personal information;
  2. a reasonable person would conclude that it is likely to result in serious harm to any of the individuals whose personal information is involved in the data breach; and
  3. the entity has not been able to prevent the likelihood of serious harm through remedial action.

Where do organisations need to be the most careful?

  • The report emphasised that there is a huge risk relating to the transmission of sensitive data via email, including the risk of harm to individuals whose personal information is emailed to the wrong recipient. The OAIC has therefore recommended that organisations consider additional security controls when emailing sensitive and other personal information, for example, putting password protection on these files.
  • Organisations should be careful to ensure that their privacy, information handling and security practices are watertight, up to date and consistent with relevant regulations and best practice.
  • Policies should be clear on what kind of information should be stored and shared via email, including how this information will be protected. in an attempt to ensure that information is contained.

How Moores can help

Moores can assist with drafting or reviewing current policies and procedures to ensure that they are tailored to your organisation’s needs and consistent with best practice to minimise risk and liability. For more information, please do not hesitate to contact us.