Newsroom

Search our media releases, articles, interviews and speeches

The KWM Digital Future Summit

Remarks by Australian Information Commissioner and Privacy Commissioner Angelene Falk to the KWM Digital Future Summit 2022

Speech
Data breach
Events
Privacy

14 November 2022

OAIC data breach report shows key privacy risks

The Notifiable Data Breaches Report released today stress the need for organisations to have robust information handling practices and an up-to-date data breach response plan.

Media release
Data breach
Privacy

10 November 2022

OAIC welcomes additional Budget funding

The Office of the Australian Information Commissioner (OAIC) welcomes funding announced in the October 2022-23 Federal Budget to assist its privacy investigations.

Media release
Funding
Privacy

26 October 2022

Advice on Medibank data breach

The Australian Government has released a factsheet to provide information on what to do if your data has been compromised in the recent Medibank and AHM cyber incident.

Media release
Data breach
Health
Privacy

25 October 2022

OAIC making inquiries with Medibank

The Office of the Australian Information Commissioner (OAIC) is making preliminary inquiries with Medibank following its cyber incident, to ensure compliance with the requirements of the Notifiable Data Breaches (NDB) scheme.

Media release
Data breach
Privacy

20 October 2022

OAIC annual report highlights its important work for the community

The OAIC navigated work of increasing volume and complexity in 2021–22 as it continued to promote and uphold privacy and information access rights.

Media release

19 October 2022

OAIC statement on MyDeal data breach

The Office of the Australian Information Commissioner (OAIC) confirms it has been notified by the Woolworths Group and made aware of the MyDeal data breach. Information on the breach is available on the MyDeal website here.

Media release
Data breach
Privacy

15 October 2022

OAIC opens investigation into Optus over data breach

The OAIC today commenced an investigation into the personal information handling practices of the Optus companies in regard to the data breach on 22 September 2022

Media release
Data breach
Investigation
Privacy

11 October 2022

OAIC updated statement on Optus data breach

The Office of the Australian Information Commissioner (OAIC) is continuing to seek information from Optus to ensure compliance with the requirements of the Notifiable Data Breaches (NDB) scheme.

Media release
Data breach
Privacy

29 September 2022

Information commissioners and ombudsmen hail importance of enabling digital access

Australian and New Zealand information commissioners and ombudsmen today highlight the importance of government agencies developing robust digital systems that strengthen the community’s access to information.

Media release
Information access
International

28 September 2022

Advice on Optus data breach

Individuals who are concerned that their personal information may have been disclosed due to the Optus data breach are advised in the first instance to check the Optus website for information and contact Optus via the My Optus App or call 133 937.

Media release
Data breach
Privacy

26 September 2022

OAIC statement on Optus data breach

The OAIC has been contacted by Optus and made aware of their data breach. The OAIC will engage with Optus to ensure compliance with the requirements of the Notifiable Data Breaches (NDB) scheme in accordance with our usual process.

Media release
Data breach
Privacy

22 September 2022

International Access to Information Day ICON session: September 2022

We hosted a livestreamed event for ICON members with the Attorney-General, Australian Information Commissioner and Privacy Commissioner, Freedom of Information Commissioner and Director-General of National Archives of Australia

Speech
Events
Freedom of Information
International

22 September 2022

Credit Reporting Code review proposes strengthened privacy protections

The Office of the Australian Information Commissioner (OAIC) has completed a major review of the Privacy (Credit Reporting) Code 2014 (the CR Code) to determine whether it remains fit for purpose and provides adequate privacy protections for

Media release
Credit reporting
Privacy

20 September 2022

Australian Government Solicitor FOI and Privacy Practitioners Update

Speech by Leo Hardiman, FOI Commissioner, his observations on information access 3 months into his appointment to the AGS FOI and Privacy Practitioners Update

Speech
Events
Freedom of Information

29 July 2022

Showing 61 to 75 of 172 results

61 to 75 of 172 search results
filter icon

Refine your search

2

Refine your search

Type

Topic

Can you confirm you have been notified of a data breach?

The OAIC generally will not comment publicly about the content of data breach notifications.

Where a particular incident is of community concern and has already been reported in the media, we may confirm publicly that we have received a notification or are investigating or making inquiries into the matter. We will generally not comment further until the investigation or our inquiries are complete.

We may also comment publicly on a matter where there is public interest in us doing so, for example, to enable members of the public to respond to a data breach.

Why don’t you list the names of organisations that have notified data breaches?

There is no specific provision that provides for the OAIC to make available a list of names of organisations that notify data breaches. The NDB scheme does have specific provisions regarding how organisations must notify individuals at likely risk of serious harm from a data breach and the OAIC. Accordingly, the OAIC will not generally disclose a list of names of organisations that notify data breaches.

Can you advise when an investigation will be completed?

Some investigations can be finalised quickly, but some take longer because of the type of inquiries and the volume of material that needs to be reviewed. We aim to finalise all investigations as quickly as possible.

Will you publish a report on the investigation?

Where the Commissioner makes a determination, a decision will be published. If the Commissioner takes proceedings for civil penalties, the Commissioner will file a statement of claim.

There’s more information on Commissioner-initiated investigations, including our approach to publication, in our Guide to Privacy Regulatory Action.

What penalties are available to the OAIC for an interference with privacy?

Section 80W of the Privacy Act 1988 empowers the Commissioner to apply to the FederalCourt or Federal Circuit Court for an order that an entity that is alleged to have contravened a civil penalty
provision in that Act pay the Commonwealth a penalty.

Under section 13G of the Privacy Act, since 13 December 2022 the maximum penalty for serious or repeated interferences with privacy are:

  • for a body corporate, the greater of either:
    • $50million; or
    • the value of any benefit the relevant court has determined that the body corporate, or any body corporate related to it, has obtained directly or indirectly that is reasonably attributable to the contravention, multiplied by three;
    • or if the court cannot determine the value of that benefit, 30% of the annual turnover of the body corporate during the 12-month period ending at the end of the month in which the contravention happened or began.
  • for a person other than a body corporate, the maximum penalty amount is $2.5million.

The Federal Court or Federal Circuit Court ultimately determines the penalty awarded, taking into account matters including:

  • the nature and extent of the contravention
  • the nature and extent of any loss or damage suffered because of the contravention
  • the circumstances in which the contravention took place
  • whether the person has previously been found by a court to have engaged in any similar conduct.

There is more information on civil penalties, including provisions in other legislative frameworks, in our Guide to Privacy Regulatory Action.

How to contact us if you have a media enquiry or interview request
Photographs of Australian Information Commissioner Angelene Falk
Photograph of Freedom of Information Commissioner Elizabeth Tydd
Photograph of Privacy Commissioner Carly Kind