Ooma Khurana
Ooma advises public and private sector clients in information technology, consumer markets and telecommunications sectors, particularly in relation to regulatory compliance and technology.
View profileIn this article we consider the proposed changes and highlight key impacts for public sector agencies.
Last month we highlighted the proposed introduction of a mandatory data breach notification scheme under the Privacy and Personal Information Protection Act 1988 (NSW) (PPIP Act). The draft Privacy and Personal Information Protection Amendment Bill 2021 (the PPIP Amendment Bill) has now been released for public consultation, together with an accompanying Factsheet. As expected, the PPIP Amendment Bill proposes key changes for New South Wales public sector agencies including the introduction of a mandatory data breach notification (MDBN) scheme. It also proposes extending the application of NSW privacy laws to state-owned corporations that are not already regulated by the Commonwealth Privacy Act 1988 (Cth).
The PPIP Amendment Bill proposes the following key changes to the PPIP Act:
Affected state-owned corporations may therefore need to implement internal processes to ensure they can comply with the PPIP Act as a whole, in addition to the MDBN scheme.
For the purpose of the MDBN scheme, personal information under the PPIP Act will expressly include ‘health information’ as defined in s6 of the Health Records and Information Privacy Act 2002 (NSW). Consequently, the MDBN scheme will extend to breaches involving health information.
The proposed MDBN scheme has the potential to require notification under both the NSW and the Commonwealth schemes in limited circumstances (for example if the data breach compromises tax file numbers).
The potential for overlap has been noted in the Fact Sheet, which states the MDBN scheme has been designed to adopt key features of the Commonwealth NDB scheme (i.e. in terms of timing and assessment thresholds) to limit the impact of this overlap.
However, in practice, we anticipate there may be occasions where a data breach gives rise to separate obligations to notify each of the affected individual, the NSW Privacy Commissioner, the Office of the Australian Information Commissioner and the Australian Taxation Office. This has the potential to impose a significant regulatory burden on public sector agencies.
As we have previously highlighted , the NSW model will also need to take into account the manner in which notification obligations interact with existing provisions of the PPIP Act, including the IPPs, to ensure that the process of notifying affected individuals is as straightforward as possible. This is particularly important given the timeframes involved.
The PPIP Amendment Bill addresses the interaction of the notification obligations under the MDBN scheme with existing provisions of the PPIP Act, including the IPPs to some degree, by proposing a public sector agency will not be required to comply with an IPP or a privacy code of practice for the purposes of sharing personal information within the agency or with an officer or employee of another public sector agency if this is reasonably necessary for the purposes of either:
The NSW government has invited feedback on the PPIP Amendment Bill by Friday 18 June 2021, with an expectation that the PPIP Amendment Bill will be introduced this year.
The PPIP Amendment Bill allows for a 12-month transition period. NSW government agencies (including state-owned corporations captured by the PPIP Act as a result of the changes) and the IPC will need to use the 12-month transition period to prepare and implement appropriate systems and processes to ensure they can comply with their new obligations.
The attached table sets out a high level summary of the proposed MDBN scheme.
Now is the time for public sector agencies in NSW to start considering their data handling practices in anticipation of these changes. In particular, we recommend that NSW Government agencies:
Contact us to discuss how your agency can start to prepare for the introduction of a mandatory data breach reporting scheme in NSW or if you would like us to support you in making a submission to the exposure draft of the PPIP Amendment Bill before 18 June 2021.
Ooma advises public and private sector clients in information technology, consumer markets and telecommunications sectors, particularly in relation to regulatory compliance and technology.
View profileKeep up to date with our legal insights and events
Sign upThe Security of Critical Infrastructure Act 2018 (Cth) is central to Australia’s critical infrastructure framework.
This case will have real consequences for how companies communicate product and pricing changes to Australian consumers.
The Commonwealth Government will establish a set of Australian Standards for AI.
The ACCC responds to the growing use and safety issues arising from the use of these products.
Partner
Sydney