Greg Palumbo
Greg has broad expertise advising on technology, media, intellectual property, hospitality, travel, privacy, sports law and general commercial matters.
View profileWe outline the key proposed changes to the Privacy Act that may impact the Ad Tech industry and what steps you can take to best prepare.
The term Ad Tech is short for ‘advertising technology’. While relatively broad, the term as it is used today refers to the technology, software and tools that help marketers and brands target, deliver, manage and analyse the performance of their digital advertising efforts.
One of the most impactful developments for this industry has been the ability to use data about an individual to better target advertising to that individual based on their preferences and past behaviours (which can be done using, for example, various online behavioural advertising technologies such as cookies, pixels, ad tags and web beacons).
Ad Tech also helps brands to make the most of their digital advertising budget and maximise their return on investment by delivering content to an engaged audience that is likely to be interested in their products and services.
Between 2017 and 2019, the Australian Competition and Consumer Commission (ACCC) conducted the Digital Platforms Inquiry, which looked into the effect that digital search engines, social media platforms and other digital content aggregation platforms have on competition in the media and advertising services markets.
The Digital Platforms Inquiry made a number of recommendations in relation to a range of competition, consumer and privacy issues, which led to:
In summary, if enacted, the Online Privacy Bill would:
Some of the key proposed changes to the Privacy Act that may impact the Ad Tech industry include the following proposals.
1. Changes to the definition of personal information
One proposal in the Privacy Act Review is to broaden the definition of personal information, including to incorporate identifiers, location data, online identifiers and other technical information (such as IP addresses, device IDs, account names and social media handles), which are commonly used in digital advertising programs.
2. Increases to obligations on collecting, using and disclosing personal information for the purposes of direct marketing, targeted advertising and profiling
There are various proposals in the Privacy Act Review that deal with direct marketing and targeted advertising, including:
3. Increases to fines and enforcement powers
The proposals would significantly increase the Office of the Australian Information Commissioner’s (OAIC) enforcement and regulatory powers, which would include, for example, an increase to the maximum civil penalty available for a serious or repeated interference with an individual’s privacy. Noting the current is limit is $2.22 million for serious or repeated interference with the privacy of an individual, the maximum penalty would increase to the greater of:
While it is not clear if (or when) the Online Privacy Bill may be passed or which (if any) of the proposals in the Privacy Act Review will be enacted, there are a number of steps we recommend you begin considering (and if appropriate, taking) in order to prepare for any changes that may be implemented as a result of the proposed changes to the Privacy Act mentioned above.
With respect to any important existing contracts or any contracts that you may enter into in the future, we recommend that you consider whether there is anything that you can do now to ensure that these contracts provide the rights and protections that may be needed in the future to address the proposed changes to the Privacy Act, particularly for contracts where you may be sharing, licensing or procuring large amounts of personal information.
There are a number of impactful contractual rights and positions that you can include now that will provide you with:
In addition to any contractual arrangements (including where you may be sharing, licensing or procuring any third party data), we also recommend that you review your data collection practices. We recommend that you consider what types of data you collect (including various types of technical information), from where you are getting your data (especially any personal information) and think about whether there is a need to update your collection notices and privacy policy to more clearly outline the types of data being collected (including any data that may, in the future, be considered to be personal information), from where you are sourcing the data (if not directly from the individual) and how this information is being used and disclosed, especially with respect to any targeted advertising that you may be undertaking.
We recommend that you consider the type of data being collected, whether that data is (or may in the future be) personal information, whether there may be a need to obtain any consents for such data (and if so, we recommend future proofing such consent processes) and what internal and external governance is required to properly protect (and provide access to) such data and mitigate or remediate any potential issues or risks. This may be particularly relevant for organisations currently planning new projects and/or updates to their policies, consents or notices.
Finally, we recommend that you adopt a ‘privacy by design’ approach and consider whether it is necessary to conduct a PIA for any of your Ad Tech or digital advertising projects, especially any new projects in your business pipeline. This process will assist in identifying privacy risks associated with those projects and help to implement controls to mitigate those risks. When you are doing so, we recommend that you contemplate the potential new privacy framework and try to ensure that the PIA considers the relevant issues that may be presented in the future as a result of any potential changes in the privacy framework.
Greg has broad expertise advising on technology, media, intellectual property, hospitality, travel, privacy, sports law and general commercial matters.
View profileKeep up to date with our legal insights and events
Sign upThe potential liability arising from directors’ use of AI remains undeveloped and evolving.
The Security of Critical Infrastructure Act 2018 (Cth) is central to Australia’s critical infrastructure framework.
This case will have real consequences for how companies communicate product and pricing changes to Australian consumers.
Partner
Sydney