Third-party providers a customer data ‘weak spot’, Australian privacy commissioner says

third-party providers a customer data ‘weak spot’, australian privacy commissioner says

The Australian privacy commissioner has warned third-party providers may be a weak spot for protecting customer privacy after a massive data breach this week. Photograph: Andrew Brookes/Getty Images/Image Source

The Australian privacy commissioner has warned third party suppliers are “a real weak spot” for protecting customer privacy after Australian user details were compromised in a leak of supplier data held by NSW and ACT clubs.

Last week more than 1 million people had their personal information including names, addresses, and driver’s licence information exposed after data collected by IT provider Outabox was published online. Outabox’s customers included dozens of clubs in New South Wales, including hospitality giant Merivale.

The Office of the Australian Information Commissioner’s data breach report stated that there were 483 notifications in the past six months related to direct data breaches, and 121 secondary data breaches – that is, where another company has suffered a data breach and that company is thereby affected by it.

The privacy commissioner, Carly Kind, said it was a growing issue, and larger organisations such as clubs needed to ensure they were passing on their privacy obligations to third party suppliers.

“We’re absolutely seeing a rise in third party suppliers being the source of data breaches,” Kind said in an interview to mark the launch of Privacy Awareness Week. “Being a point of vulnerability for others in terms of compliance with Privacy Act is very real and what we’re cautioning organisations about is ensuring that they’re passing on their obligations in the best way possible in any contract with third parties.

“So either by through contractual provisions about compliance with privacy standards, but also through due diligence and ensuring that they know what kinds of privacy protections are in place for those third-party suppliers … it’s becoming a real weak spot in the chain of protecting privacy.”

Kind is the first stand-alone privacy commissioner to hold the federal role in eight years. She took up the position in late February, moving back to Australia after being the inaugural director of the London-based AI and date research organisation the Ada Lovelace Institute since 2019. Her appointment comes as the federal government is planning a substantial overhaul of the Privacy Act.

On Thursday, the attorney general, Mark Dreyfus, said reform of the law was vital in a time when the “personal privacy of citizens is under attack”. The government plans to introduce legislation overhauling the privacy act and targeting doxing – the malicious use of their personal and private information – in August.

In consultation with industry, he said, the government was considering bringing in a fair and reasonable test regarding the collection, use and disclosure of personal information, and has agreed in principle that a statutory tort for serious invasions of privacy should be introduced complementary to the privacy act protections. Also under consideration is requirements for businesses around maximum and minimum retention periods for personal information.

Kind said since coming into the role in February, she had noticed no resistance to the privacy reform from industry, and there was political support for the change. She said what she was more concerned about was Australian organisations not considering what personal information they currently collect and whether they still need to collect it.

“When these data breaches occur, we’re seeing a lot of data that’s being exposed, perhaps some of which doesn’t need to be held or retained by those entities. So [that’s] perhaps a challenge of excessive collection of data in the first place … I think there’s some probably some habits and trends there that have been baked in and because there hasn’t been that Privacy Act reform, and it’s feeling a bit overdue.”

Kind said some of the larger tech companies had improved their data-collection practices as a result of passing on requirements under the EU’s data privacy regime to the rest of the world, but that alone was not sufficient, and local laws needed updating, with regulators given stronger powers to enforce privacy law.

“The role of regulators there is really key. We’ve seen that in Europe very active enforcement of privacy law in certain aspects really can change business models.”

OTHER NEWS

21 minutes ago

Rudy Giuliani is served indictment papers at his own birthday party after mocking Arizona attorney general

22 minutes ago

China's April retail sales data 'a little bit of a blip,' economist says

22 minutes ago

Nadler questions Supreme Court ethics after Alito flag debacle: ‘None of them have clean hands’

22 minutes ago

Ex-Manly star Josh Schuster reveals he's the happiest he's been in a long while after losing his $3.2 million NRL contract

22 minutes ago

Anthony Edwards confident ahead of Game 7: 'We're a great team'

22 minutes ago

Scottie Scheffler finally hit the wall

22 minutes ago

Trapped cargo ship Dali will refloat to Baltimore Monday at high tide

22 minutes ago

‘Oh my god, I am beautiful’: the people who pay to have their portrait painted

22 minutes ago

AOC knocks Fetterman after fight with MTG: 'I stand up to bullies, instead of becoming one.'

23 minutes ago

Labor’s $300 energy bill rebate ‘nearly impossible’ to means test

23 minutes ago

Arsenal transfer news: All change for ‘stronger than Haaland’ striker Benjamin Sesko

27 minutes ago

Norridge police investigating ‘incident' involving officer, people asked to avoid area

28 minutes ago

Seize the Grey wins the Preakness, ending Mystik Dan's Triple Crown bid

29 minutes ago

Brooks Nader sizzles in busty corset with Lori Harvey and more top models at Sports Illustrated Swimsuit Issue party in Florida

29 minutes ago

Alcohol abuse costs a whopping £27,000,000,000 a year in England

29 minutes ago

Finlay Knox crushes Canadian record in 200m medley, qualifies for Paris 2024

29 minutes ago

Author Coco Mellors: ‘I needed from the book something that I needed in my life – a sense of hope’

29 minutes ago

China has economic 'upper hand' yet Xi & Putin 'need each other to form counterbalance against West'

29 minutes ago

When Eddie Kingston Aims To Return To AEW

29 minutes ago

Postecoglou would have done things differently had he known the atmosphere on Tuesday

30 minutes ago

Educators call Gov. Gavin Newsom’s slash to school funding ‘unconstitutional’

31 minutes ago

Pelican Island Causeway Bridge reopening after Wednesday's barge strike

34 minutes ago

Daisy Ridley is business chic in boxy gray blazer at special LA screening of Disney's Young Woman And The Sea

34 minutes ago

What time is Netflix releasing Bridgerton series three in the UK?

34 minutes ago

CNN political commentator and GOP strategist Alice Stewart dies

34 minutes ago

From 800 km away, dark horse Engineer Rashid unsettles the Baramulla race

34 minutes ago

Cate Blanchett looks chic in quirky fruit-print top and leather trousers as she attends Cannes Film Festival afterparty for her new flick Rumours

34 minutes ago

Dozens of Muslim teenagers sent to Government's anti-terror programme after being radicalised by Nazi propaganda that celebrates Adolf Hitler's genocide of Jews

34 minutes ago

Video: Horror as handsome high school jock, 17, is killed and his girlfriend, 16, fights for her life after 'drunk driver' slammed into them at 131 mph in his Mustang that split their car in HALF

34 minutes ago

Plans to roll out 'dental vans' in effort to tackle shortage of practitioners could be shelved by ministers due to 'limited availability' of vehicles

34 minutes ago

British Museum recovers 268 more missing or stolen objects that have been found across the world after legal action was launched against curator and director resigned

34 minutes ago

Christian enclave known as 'God's Square Mile' who banned people from using public beaches due to bizarre belief could finally be stopped after they 'made people buy badges with the CROSS on them'

34 minutes ago

Critics slam BBC Rebus reboot for 'reimagining' Ian Rankin's popular detective as an 'unhinged thug'

34 minutes ago

Shocking moment BMW driver wrecks £82,000 motor by slamming it into a bike stand in London, ripping off its wheel before motorist 'fled the scene'

34 minutes ago

Palestinians call for boycott of 'genocidal' Israel as fears grow of Cannes film festival becoming 'another Eurovision'

36 minutes ago

Team Penske dominates first day of Indy 500 qualifying as Ganassi and Ericsson shut out of pole

41 minutes ago

Seven Indian Filmmakers and Entrepreneurs Who Will Rock Cannes This Year

41 minutes ago

Long Week? ‘The Voices' Is the Rare Midnight Movie Better Enjoyed Alone

41 minutes ago

HOW much funding South Africa’s political parties received in 2024

41 minutes ago

Video: Revealed: Oleksandr Usyk's punch stats against Tyson Fury show he was the RIGHT winner despite throwing nearly 100 punches less... as the Ukranian bested the Gypsy King in several key areas

Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch