Australia Announces Tougher Fines for Data Breaches Following Recent Cyberattacks

Australia's penalties for breaches of the Privacy Act would increase from AUD 2.2 million (nearly Rs. 11 crore) to AUD 50 million (nearly Rs. 260 crore).

Australia Announces Tougher Fines for Data Breaches Following Recent Cyberattacks

In Australia, unknown hackers stole personal data from 9.8 million customers of Optus

Highlights
  • Optus theft has left Australians at heightened risk of identity fraud
  • Dreyfus said both breaches had shown “existing safeguards are inadequate
  • New penalties will not be retroactive, will not effect Optus or Medibank
Advertisement

Australia on Saturday proposed tougher penalties for companies that fail to protect customers' personal data after two major cybersecurity breaches left millions vulnerable to criminals.

The penalties for serious breaches of the Privacy Act would increase from AUD 2.2 million (nearly Rs. 11 crore) now to AUD 50 million (nearly Rs. 260 crore) under amendments to be introduced to Parliament next week, Attorney-General Mark Dreyfus said.

A company could also be fined the value of 30 percent of its revenues over a defined period if that amount exceeded AUD 50 million.

Dreyfus said “big companies could face penalties up to hundreds of millions of dollars” under the new law.

“It is a very, very substantial increase in the penalties,” Dreyfus told reporters.

“It's designed to make companies think. It's designed to be a deterrent so that companies will protect the data of Australians,” he added.

Parliament resumes on Tuesday for the first time since mid-September.

Since Parliament last sat, unknown hackers stole personal data from 9.8 million customers of Optus, Australia's second-largest wireless telecommunications carrier. The theft has left more than one-third of Australia's population at heightened risk of identity theft and fraud.

Unknown cybercriminals this week demanded ransom from Australia's largest health insurer, Medibank, after claiming to have stolen 200GB of customers' data including medical diagnoses and treatments. Medibank has 3.7 million customers. The company said the hackers had proved they hold the personal records of at least 100.

The thieves have reportedly threatened to make public medical conditions of high-profile Medibank customers.

Dreyfus said both breaches had shown “existing safeguards are inadequate.”

As well as failing to protect personal information, the government is concerned that companies are unnecessarily holding too much customer data for too long in the hope of monetising that information.

“We need to make sure that when a data breach occurs the penalty is large enough, that it's a really serious penalty on the company and can't just be disregarded or ignored or just paid as a part of a cost of doing business,” Dreyfus said.

Dreyfus hopes the proposed amendments will become law in the final four weeks that Parliament will sit this year.

Any new penalties will not be retroactive and will not effect Optus or Medibank.


Should you buy a 4G or 5G budget phone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
Comments

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Australia, cyberattack, data breach
Redmi Note 12 Pro+, Realme 10 Pro+ Tipped to Have Curved AMOLED Displays
Facebook Gadgets360 Twitter Share Tweet Snapchat LinkedIn Reddit Comment google-newsGoogle News

Advertisement

Follow Us
© Copyright Red Pixels Ventures Limited 2024. All rights reserved.
Trending Products »
Latest Tech News »