Katherine Armytage
Katherine has a highly regarded and dynamic practice in information law, with a particular focus on privacy and data protection.
View profile
Much has already been written about the introduction of the first tranche of reforms to the Privacy Act 1988 (Cth) (Privacy Act) through the Privacy and Other Legislation Amendment Bill 2024 (Privacy Bill) (for example, see our recent e-alert here).
Even though many of the substantive reforms to the Privacy Act that were proposed have not yet been actioned, Australian Government agencies should take steps now to make sure that they are prepared for the reforms that are covered by the Privacy Bill, rather than waiting for its final form and passage through Parliament. Taking proactive preparatory steps now will demonstrate a robust approach to managing compliance with the introduced reforms.
This article sets out our top 3 tips for practical steps that agencies can take now to prepare.
If enacted, the Privacy Bill will:
All of this means that, now more than ever, your agency (and in particular your litigation team, if you have one) needs to really understand its current and future privacy obligations, so that it can effectively resolve privacy complaints, and manage disputes and litigation.
Things to check:
If enacted, the Privacy Bill will:
This means that now is the perfect time to have a careful look at your agency’s data breach response plan, and see if it is still fit for purpose. It’s also important to test the plan regularly (using scenario based activities) to see if it works in practice.
Things to check:
The Privacy Bill contains a range of other reforms that might have implications for some Australian Government agencies, depending on their particular activities.
Things to check:
If the answer to any of these questions is ‘yes’ (or even ‘maybe’), you will need to carefully consider the proposed reforms in the Privacy Bill. You might need to take a range of actions, including changing your agency’s collection notices, consents and privacy policy; updating contractual obligations; and/or changing particular processes used to handle personal information.
Even though some commentators have expressed disappointment that the Privacy Bill does not go far enough, it will still introduce some key reforms that will have ramifications for Australian Government agencies.
There should be enough time for agencies to make sure that they are ready to tackle the challenges associated with this first step in Australia’s privacy reform journey - but this process should start now!
The Maddocks Commonwealth Privacy, Data and Information Law team has a wealth of expertise and experience in assisting Australian Government agencies to meet not only their legal privacy obligations, but also the Australian community’s expectations for handling personal information. Please contact us for a confidential discussion about your agency’s activities, how it is likely to be impacted by the Privacy Bill, and the strategies that it might deploy to ensure preparedness.
Get in contact with our team
Katherine has a highly regarded and dynamic practice in information law, with a particular focus on privacy and data protection.
View profileIndi provides high‑quality privacy, FOI, probity and procurement advice to Australian Government clients, including PIAs for complex ICT systems and Privacy Act guidance.
View profileKeep up to date with our legal insights and events
Sign upPractical steps to strengthen procurement planning, improve market engagement and deliver competitive processes.
Service levels are a familiar feature of technology contracts, yet their practical application is not always clear.
The key risks, common reseller models, and what customers can do to protect themselves.
Partner
Canberra