Manawatu Standard

Watchdog backs $1m fines for privacy breaches

- HAMISH MCNICOL

Privacy Commission­er John Edwards is recommendi­ng fines of up to $1 million for serious privacy breaches.

Both public and private sector organisati­ons could face such a fine, which would be more in line with Australia, while individual­s would face a maximum civil penalty of $100,000.

‘‘In light of internatio­nal trends and current conditions, privacy enforcemen­t sanctions no longer appear adequate to deal with serious breaches,’’ Edwards said.

The recommenda­tions come in the commission­er’s latest report on the viability of the Privacy Act, which the Government planned to reform.

As well as being able to apply for the fines, Edwards recommende­d the introducti­on of data portabilit­y as a consumer right, giving them the ability to transfer personal informatio­n between things like social networks or cloud services.

The report cited recent privacy breach penalties in the UK, such as when the British Pregnancy Advice Service was fined £200,000 (NZ$344,000) after thousands of personal files were revealed to a malicious hacker.

‘‘Internatio­nally, the trend is towards privacy and data protection regulators having a variety of sanctions in order to respond effectivel­y and meaningful­ly to the range of breaches and noncomplia­nce that arise.

‘‘This includes the potential for large civil sanctions to be imposed for those rare, sufficient­ly serious cases that require them.’’

Privacy law reform has been considered since 1998, and between 2008 and 2011 there was a Law Commission review on the subject.

But Edwards said a lot had changed since then. There were gaps and weaknesses which needed to be addressed if the proposed modernisat­ion of the Privacy Act was to be effective.

‘‘Important developmen­ts since 2011 that impact on the operation and adequacy of the privacy legislatio­n include developmen­ts in data science and informatio­n technology, and new business models built on data-driven enterprise.

‘‘These developmen­ts have highlighte­d the importance for both the public and private sectors to optimise trust in the digital economy.’’

His report also suggested an update to protection against the risk of individual­s being unexpected­ly identified from supposedly anonymised data, the power to require an agency to show its compliance with the law, narrowing the defences available, and providing for the suppressio­n of personal informatio­n in public registers when there is a safety risk.

In January, the Department of Correction­s agreed to change its CCTV policy following a reprimand from the Privacy Commission­er over a case involving a prisoner who was severely beaten.

Edwards found that Correction­s interfered with the prisoner’s privacy after it refused to release footage of him being assaulted.

Last September, Edwards said a hack of Yahoo, from which Spark said 130,000 Xtra email addresses were ‘‘at risk’’, showed the need for a New Zealand law to force companies to own up to data breaches.

He praised Spark, but questioned Yahoo’s response after the 2014 hack only came to light last year.

 ?? PHOTO: 123RF ?? Residentia­l property has enjoyed huge capital gains but at the same time it has become a tougher class of investment to break into.
PHOTO: 123RF Residentia­l property has enjoyed huge capital gains but at the same time it has become a tougher class of investment to break into.
 ??  ?? John Edwards
John Edwards

Newspapers in English

Newspapers from New Zealand