Charity Lawyers
  • Home
  • About Us
    • Who we are
    • Our team
  • Expertise
    • At a glance
    • In depth
      • Tax & duties
      • Governance
      • Charitable Trusts
      • Structures: establishment & restructuring
      • Mergers, collaborations & strategic alliances
      • Gifts, charitable fundraising & promotions
      • Disputes & regulatory reviews
      • Workplace & People issues
      • Brand, information & reputation protection
      • Property
  • Insights
    • At a glance
    • View articles
      • Updated transparency requirements under the Commonwealth Electoral Act
      • Pastoral care services DGR category
      • Resignation of director notification
      • Permanent changes to the Corporations Act regarding meetings and documents to come into force
      • Global Alliance of Impact Lawyers Launch Week
      • Prolegis Lawyers ranked Band 1 by Chambers
      • Recent changes to the Corporations Act for electronic meetings, notices, minute books and e-signing due to the Covid-19 pandemic
      • Recent decisions in Australian charity law – update
      • New requirements for DGRs to be registered as charities with the ACNC
      • High Court rules on who is a Casual employee
      • Streamlining of regulation of charities undertaking fundraising in NSW
      • Changes to Charities’ Financial Reporting Obligations
      • Changes to Casual Employment
      • Women’s Life Centre – A recent decision of the Administrative Appeals Tribunal regarding Public Benevolent Institutions (PBIs)
      • Final Report of the 2020 Review of Disability Standards for Education 2005
      • Royal Commission into Aged Care Quality and Safety - final report released
      • UPDATE 25 February 2021: Introducing ACNC Governance Standard 6 and changes to Basic Religious Charity eligibility
      • Treasury Consultation: Proposed changes to ACNC Governance Standard 3
      • Breaking: Charities to lose charitable status if they fail to join the National Redress Scheme
      • New Bill – Requiring DGRs to Register as Charities
      • Federal Budget 2020-21
      • NZ High Court finds Greenpeace NZ should be registered as a charity
      • A member of a charity has a fiduciary duty to act in the best interest of the charity?
      • Key Changes- incorporated associations in Queensland
      • Bill for new DGR category for Community Sheds now law
      • UPDATE 2 June 2020: SME Commercial Leasing Principles During COVID-19 - what does it mean for charities and not-for-profits?
      • UPDATE 19 May 2020: COVID-19 – Information for Charities and Not-for-Profits
      • UPDATE 6 May 2020: COVID-19 - Ancillary Funds, Disaster Relief Funds and AGM for companies
      • Draft bill for new DGR Category: Men’s and Women’s Sheds
      • An Update: COVID-19 Australian government’s economic response – What’s for charities and not-for-profits?
      • COVID-19 Australian government’s economic response – What’s for charities and not-for-profits?
      • ACNC to review registered charities beginning with Public Benevolent Institutions in July 2020
      • Government response to the recommendations of the ACNC Legislation Review
      • Fundraising– considerations for charities, fundraisers and donors
      • Minute-taking post Banking Royal Commission
      • Taxation Ruling: 'in Australia' conditions
      • Key changes to the Victorian Fundraising Act
      • Religious Discrimination Bill- Update
      • New protections for whistleblowers – what does it mean for charities and not-for-profits? UPDATE
      • Significant Changes in Payment and Record Keeping Requirements for Clerical and Administrative Staff
      • New Tax Office Ruling - Fringe Benefits Provided to Religious Practitioners
      • ACNC External Conduct Standards - Update
      • Fair Work Australia decision will introduce changes in entitlements and record keeping requirements of clerical and administrative employees
      • Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability
      • National Redress Scheme Update
      • DGR reform proposals
      • Release of the ACNC Review Report
      • Not So Casual
      • ACNC External Conduct Standards - Public Consultation
      • Law on Advocacy by Charities
      • New ATO Draft Ruling on the fringe benefits tax: benefits provided to religious practitioners
      • Employment update - New numbers for key employment issues for a new tax year
      • Electoral disclosure & funding reform: why charities and NFPs should be concerned
      • Review of ACNC Framework
      • Reforming Administration of Tax Deductible Gift Recipients - a victory for common sense?
      • Righting Wrongs: Victoria takes lead on organisational child abuse legislation
      • Tax Deductible Gift Recipient Reform Opportunities
      • When may a charity board member be paid for their services?
      • #fixfundraising
      • Privacy Law Update: Mandatory Data Breach Notifications to come into force by the end of 2017
      • Good Things Come To Those Who Wait? ACNC releases Commissioner’s Interpretation Statement on Public Benevolent Institutions
      • Privacy Obligations - Lessons and reminders from the Red Cross Data Breach
      • Charities and the Australian Consumer Law - reducing duplication and confusion
  • Careers
  • Contact

Get In Touch


Sydney

Level 4, 107 Mount Street
North Sydney NSW 2060
Australia

   +61 2 9466 5222

  info@prolegis.com.au

Melbourne

Level 12
500 Collins Street
Melbourne VIC 3000
Australia

   +61 3 8672 2920

  info@prolegis.com.au

Insights

Privacy Obligations - Lessons and reminders from the Red Cross Data Breach

   November 2016   |  Article   |  Mary Sheargold

On Friday 28 October 2016 the Australian Red Cross announced that one of its IT providers had inadvertently caused the personal information of over half a million Australian blood donors to be published on a public-facing website. The extent of the damage from this data breach remains unknown. The breach is currently under investigation by the Australian Cyber Security Centre and the Office of the Australian Information Commissioner (OAIC). This is the most significant data breach reported in Australia’s cyber history. It provides a timely reminder to charities and the not-for-profit sector regarding the importance of protecting donors’ personal information – especially where sensitive information, as described below, is collected.

It’s vital that charity and not-for-profit boards and senior executives remain fully informed about their privacy obligations - and ensure that these obligations are given strong operational effect across their organisation.

What are your obligations under the Privacy Act?
Any organisation in Australia with an annual turnover greater than $3 million is bound by the 13 Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) (the Act).  The APPs also apply to any health service provider, companies that trade in personal information, and several other narrow groups of organisations, regardless of annual turnover.

The 13 APPs impose a range of obligations on organisations to protect the privacy of persons from whom information is collected.  The obligations range from ensuring secure protection of any data stored to notifying people about the types of information collected and what will be done with it. 

There are provisions relating to:

  • the way in which you may store personal information (for example, where cloud storage is used, requiring any offshore third parties engaged to facilitate such storage to be compliant with the obligations under the APPs);
  • the ways in which information may be shared with third parties generally (e.g. sale of databases to marketing companies, etc.); 
  • an obligation to maintain the accuracy of personal information collected and stored (e.g. accuracy; is the information up to date?); and
  • additional care that must taken when collecting government related identifiers (Medicare numbers, drivers licence numbers, tax file numbers and Centrelink details etc.) and other 'Sensitive Information'.

What is ‘Sensitive Information’?

APP3 governs the circumstances in which your organisation may be able to collect Sensitive Information.  Sensitive Information includes information about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences or practices criminal record or health information.  

When can you collect Sensitive Information?

Sensitive information can only be collected if an individual consents to the collection of the information, and it is reasonably necessary for, or directly related to, one or more of your organisation’s functions.  For example, the media was quick to comment on the potential disclosure of sensitive information the Red Cross collects regarding its donors’ propensity to engage in at-risk sexual behaviour.  It is reasonably necessary for the Red Cross to collect that information to help ensure the quality of its blood supply.  Similarly, it may be considered reasonably necessary for organisations such as faith-based schools to collect information regarding a prospective student’s religious affiliations (and that of his/her parents).

Do you really need to worry about this?

The answer to this question is a resounding ‘Yes’. Apart from honouring the trust that people who provide sensitive information rely on, when the APPs were introduced in March 2014, the Act also incorporated significant penalties for breaches of the obligations.  The maximum fine for a breach of the APPs currently sits at $1.8m.  Further, the Act now provides the OAIC with a range of options to investigate organisations, especially where data breaches occur.  For example, the OAIC can instigate an ‘own motion’ investigation, where an organisation is put under the microscope on suspicion of a data breach. The outcome of an own motion investigation can comprise a range of penalties, including the fines described above.

Mandatory data breach notifications
Since the overhaul of Australia’s federal privacy legislation in 2013-14, there has been great debate as to whether breaches such as the one the Red Cross found itself in last week should be subject to a mandatory OAIC disclosure obligations.  In March 2016, the federal Attorney-General issued a discussion paper in relation to mandatory obligations to notify regarding a serious data breach.  It seems increasingly likely that some form of mandatory reporting obligation will be introduced to the Act in the near future.

What should you do now?
If you have not reviewed your privacy policies since the APPs were introduced in 2014, this is a timely reminder of the importance of doing so.  Many not-for-profit groups will be bound by the APPs, and it is important that you understand and uphold your obligations. 

We can assist you with a privacy law health check to ensure your organisation and those who support you are not left exposed. Please contact us.

Mary Sheargold | Senior Associate





Quick Links

⇢    Our Team
⇢    About Us
⇢    Expertise
⇢    Insights
⇢    ACNC

Latest News

  • March 2022
    Updated transparency requirements under the Commonwealth Electoral Act
  • March 2022
    Pastoral care services DGR category
  • March 2022
    Resignation of director notification
  • March 2022
    Permanent changes to the Corporations Act regarding meetings and documents to come into force
  • February 2022
    Global Alliance of Impact Lawyers Launch Week

Latest News & Insights

  • Updated transparency requirements under the Commonwealth Electoral Act March 2022
  • Pastoral care services DGR category March 2022
  • Resignation of director notification March 2022

Useful Links

  • Our Team
  • About Us
  • Expertise
  • Insights
  • ACNC

Sydney Office

Level 4, 107 Mount Street
North Sydney  NSW   2060
Australia

+61 2 9466 5222

info@prolegis.com.au

Melbourne Office

Level 12

500 Collins Street
Melbourne  VIC  3000
Australia

+61 3 8672 2920

info@prolegis.com.au

Copyright © Prolegis Lawyers. All Rights Reserved.

  • Privacy Policy