Australia flags new corporate penalties for privacy breaches
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
Hey there, time traveller!
This article was published 21/10/2022 (1392 days ago), so information in it may no longer be current.
CANBERRA, Australia (AP) — Australia on Saturday proposed tougher penalties for companies that fail to protect customers’ personal data after two major cybersecurity breaches left millions vulnerable to criminals.
The penalties for serious breaches of the Privacy Act would increase from 2.2 million Australian dollars ($1.4 million) now to AU$50 million ($32 million) under amendments to be introduced to Parliament next week, Attorney-General Mark Dreyfus said.
A company could also be fined the value of 30% of its revenues over a defined period if that amount exceeded AU$50 million ($32 million).
Dreyfus said “big companies could face penalties up to hundreds of millions of dollars” under the new law.
“It is a very, very substantial increase in the penalties,” Dreyfus told reporters.
“It’s designed to make companies think. It’s designed to be a deterrent so that companies will protect the data of Australians,” he added.
Parliament resumes on Tuesday for the first time since mid-September.
Since Parliament last sat, unknown hackers stole personal data from 9.8 million customers of Optus, Australia’s second-largest wireless telecommunications carrier. The theft has left more than one-third of Australia’s population at heightened risk of identity theft and fraud.
Unknown cybercriminals this week demanded ransom from Australia’s largest health insurer, Medibank, after claiming to have stolen 200 gigabytes of customers’ data including medical diagnoses and treatments. Medibank has 3.7 million customers. The company said the hackers had proved they hold the personal records of at least 100.
The thieves have reportedly threatened to make public medical conditions of high-profile Medibank customers.
Dreyfus said both breaches had shown “existing safeguards are inadequate.”
As well as failing to protect personal information, the government is concerned that companies are unnecessarily holding too much customer data for too long in the hope of monetizing that information.
“We need to make sure that when a data breach occurs the penalty is large enough, that it’s a really serious penalty on the company and can’t just be disregarded or ignored or just paid as a part of a cost of doing business,” Dreyfus said.
Dreyfus hopes the proposed amendments will become law in the final four weeks that Parliament will sit this year.
Any new penalties will not be retroactive and will not effect Optus or Medibank.