Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
Our personal information is precious. It is unique to each of us and tells a story about who we are.
Under the Privacy Act, organisations that collect and hold personal information have a duty to protect it and respect it.
When things go wrong, and organisations breach the privacy of their customers, clients, or stakeholders, it can cause serious harm. Privacy breaches can lead to financial loss, identity theft or, in extreme cases, physical harm.
Organisations responsible for serious privacy breaches may also lose public trust and damage their brands or reputations.
Fortunately, there are many occasions when somebody realises a privacy breach is about to happen and acts before it is too late. Similarly, sometimes privacy breaches occur but no serious harm is caused. Each of these circumstances provides an opportunity for organisations to learn and make system changes to avoid a serious breach next time. Many of the most common privacy breaches are easily preventable.
A privacy breach is an event (whether intentional or accidental) in which someone’s personal information is accessed, used, altered, shared, lost, or destroyed without authorisation. A privacy breach also occurs if someone is either temporarily or permanently unable to access their personal information.
Under the Privacy Act, if an organisation experiences a privacy breach that it believes has caused or has the potential to cause serious harm, it must notify the Office of the Privacy Commissioner (OPC) and affected individuals as soon as possible*. It can do this using NotifyUs. *Unless an exception applies
Failure to report a notifiable privacy breach to OPC could result in a fine of up to $10,000.
Often organisations or individuals will narrowly avoid serious privacy breaches through sheer luck.
For example, you might be about to send an email containing personal information to the wrong person. Or you may have drafted an email containing sensitive information to a list of people and Cc’d each email address, rather than Bcc’d. In each of these instances, a breach could be avoided if, just before clicking ‘send’, you realise your mistake and take appropriate action to avert a breach.
Other examples of narrowly avoiding serious privacy breaches could be:
NotifyUs is OPC’s tool for organisations to report their privacy breaches to us.
More than a third of all privacy breaches reported to us over the past five months (since Privacy Act 2020 came into force) were the result of email errors.
If sensitive information relating to someone’s health, family, finances or other categories of sensitive personal information is attached to emails, it could easily cause someone serious harm.
Before you send an email containing personal information, follow these simple steps to avoid disaster:
Aside from avoiding email blunders, what other steps can you take to prevent privacy breaches or respond to near misses?
Near misses provide the perfect opportunity for organisations to examine how they handle customer or client information and improve their privacy game.
Once you have taken those steps, you should also review your organisation’s physical and technical security.
Store personal information securely. Put physical documents containing personal information in lockboxes or filing cabinets. Digital documents containing personal information should be password protected.
Only staff who need access to personal information should have access to it. If possible, implement a system to track who is accessing personal information on your systems. Many privacy breaches reported to our office are categorised as employee browsing. Employee browsing is when staff members access personal information they have no right to, e.g. a bank teller searching the account information of people they know out of curiosity or nosiness.
Finally, ensure you staff receive privacy training. An easy way to do this is to try our free e-learning units. Privacy ABC and Privacy Act 2020 are good units to get you started.
By following these simple steps, you can turn a narrowly avoided serious privacy breach into better privacy practice for your organisation.
Back