By Jason Symons, Partner, Max Feng, Lawyer, Jeremy Williams, Paralegal
Introduction
The Privacy Commissioner through the determinations of Datateks Pty Ltd (Privacy) [2023] AICmr 97 (Datateks)[1] and Pacific Lutheran College (Privacy) [2023] AICmr 98 (PLC)[2] highlighted the critical importance of responding to an “eligible data breach” expeditiously to comply with its regulations. The Commissioner also emphasised the need for organisations to prepare an incident response plan before any cyber incident occurs, which is ready to guide the entity through the assessment process promptly as time is of the essence.
Assessment of eligible data breaches
The Notifiable Data Breach (NDB) Scheme, found in Part IIIC of the Privacy Act (Cth) (Privacy Act), regulates the investigation and notification of “eligible data breaches” (EDB) suffered by regulated entities[3].
An EDB occurs when there has been unauthorised access or disclosure of personal information (or other information referred to in s 26WE(1)) that a reasonable person would consider is likely to result in serious harm to the individuals whom the information relates.[4]
Critically, the investigation must be undertaken in accordance with s 26WH, which requires:
Essentially, the EDB assessment requires the entity to investigate the data breach in such a way that it moves as promptly and efficiently as reasonably possible in the circumstances,[5] from merely having a ‘suspicion’, to ‘believing’ it has suffered an EDB that requires notification[6] (unless effective remedial steps can be taken[7]).
Background
Datateks operated a business that builds, operates, and maintains communication networks and infrastructures for various entities. On 26 June 2020, Datateks became aware three of its email accounts were subject to unauthorised access by a third party and had been used to carry out a phishing campaign. The types of personal information held in the email accounts were dates of birth, credit card information, bank account details, superannuation information, driver licence, birth certificate, working with children check and Medicare card information, and tax file numbers (TFNs).
PLC was subjected to unauthorised access of an email account belonging to the manager of PLC’s Early Learning Centre and Outside School Hours Care Services on 28 May 2020. The unauthorised access by a third party exposed the financial details, TFNs, medical information, identity information and contact information of 367 individuals.
Determinations
The Commissioner found that both Datateks and PLC had interfered with individuals’ privacy under the Privacy Act by failing to:
The Commissioner further required Datateks and PLC to prepare an incident response plan (IRP) containing certain minimum details and provide a copy to the Commissioner within 3 and 6 months of the determination respectively. PLC also had to implement an information security program to ensure it protected personal information in accordance with APP 11.1.
Suspicion vs belief
Relevantly, the Commissioner attributed “suspicion” and “belief” to the definitions ascribed by the High Court of Australia in George v Rockett[8] whereby:
Evident from the Commissioner’s perspective, the threshold for ‘suspicion’ for a regulated entity is far lower than that of a ‘belief’. In both cases, the Commissioner took the view the required ‘suspicion’ existed within the first 24 hours of both entities discovering the unauthorised access to email accounts. The Commissioner placed significance on each entity’s awareness of their ‘usual practice’ of using email accounts to collect personal information and health information; and, in Datatek’s case, as also the ‘de factor usual practice’ to hold such information as sufficient basis in fact to form a suspicion that an EDB had occurred.
Hence, both Datateks and PLC were expected to start their EDB assessment under s 26WH the very next day of discovering the cyber incident. The Commissioner differentiated a suspicion and belief in relation to the forensic investigation work, by finding the suspicion can be formed prior, but the belief may require its completion.
Taking all reasonable steps
While not a strict timeframe, s 26WH dictates that the entity take “all reasonable steps” to complete the EDB assessment within 30 days. The Commissioner in PLC noted that “what constitutes ‘all reasonable steps’ in this context will vary depending on all the circumstances, including the circumstances of the entity and the suspected eligible data breach”.
In Datateks, the Commissioner found whilst efforts were made to engage a cyber security specialist for a forensic investigation within the first 30 days, the scope and depth of the investigation was limited, with no evaluation of the personal information involved. As Datateks’ activities primarily focused on containment and basic investigation of the root cause, it did not undertake any assessment of the personal information involved “and the potential risk of harm that may follow, [which] is an essential element of an assessment under s 26WH” until after the forensic investigation was completed on day 74.
Whilst in PLC, the Commissioner found substantive progress was lacking until after the 30 day mark, with the scope of investigation work not agreed until day 67 and the investigation commencing on day 71. Notably, despite extracting the compromised email account’s contents within 2 days after the initial breach, no further analysis of the personal information was conducted within the initial 30 days. Significantly, the Commissioner also took into account “the resources available to the respondent” and found that “the presence of multiple workstreams should not present such a significant burden to warrant such an untimely response”.
Serious harm test
Essential to the EDB assessment is the satisfaction of the serious harm test of an eligible data breach in s 26WE(2). An entity can suspect an eligible data breach, but if it never forms a belief that it is one, notification is not required. As outlined above, that requires the breach to be “likely to result in serious harm” to the individuals impacted.
Accordingly, when undertaking the EDB assessment, both the forensic investigation of the compromise and the data review, must be working towards forming the required belief that the individuals are likely to suffer serious harm taking into account all relevant matters[9], including the kinds of information involved.
In these decisions, the Commissioner only very briefly considered the serious harm test. In Datateks, it was found “Given the types of personal information routinely held within its general email account … a reasonable person would conclude that unauthorised access to this information would be likely to result in serious harm to the individuals” in the form of identity theft or other fraud. PLC admitted the serious harm test was satisfied, so the Commissioner was not required to make a finding.
In circumstances where the compromised email account does not contain such highly valuable information, it will be interesting to see where the Commissioner ‘draws the line’ on serious harm. The Commissioner also did not clarify the likelihood of serious harm in situations where forensic investigation work uncovers activity by the threat actor that suggests it was not motivated to use (or sell) the personal information accessible to commit fraud against individuals, but rather misdirection payment fraud against the entity for example.[10]
Cyber insurance assists expeditiousness
Evident from the Commissioner’s determinations, both Datateks’ and PLC’s investigation delays, including the need for expert assistance and the engagement of third-party vendors, significantly hindered timely assessment completion.
A cyber insurance policy is designed to assist organisations navigate through a cyber incident as it occurs and, amongst other things, can assist with:
The structure and purpose of the first party cover available in cyber insurance assists an insured to investigate an incident, assess and meet its legal obligations, with the expeditiousness required when time is of the essence.
Fail to (incident response) plan, plan to fail
The Australian Institute of Company Directors (AICD) emphasised in its recently released “Governing Through a Cyber Crisis” guidebook[11] that a “board must be confident the organisation is adequately prepared” for a cyber incident and “this experience can only be gained through having a well-tested cyber incident response plan in place”.
Leaving it until an event occurs will put the entity at risk of regulatory action[12]. Organisations should be planning for it now, by having a robust IRP (like Datateks and PLC were ordered to prepare) that outlines the internal roles and responsibilities, external vendors to be engaged, as well as details of the insurer and coverage, and aligns with existing business continuity plans. It should also be tested regularly with simulated incident exercises.
The OAIC has clearly placed priority on investigating incidents where delay in notifying is an issue. Understanding and planning how to undertake a reasonable and expeditious assessment of a suspected eligible data breach within the tight timeframe is critical for any organisation regulated by the Privacy Act.
[1] See here: https://www6.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2023/97.html.
[2] See here: https://www6.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2023/98.html.
[3] A regulated entity for the purposes of the NDB scheme is any private organisation with an annual turnover of more than AU$3 million (APP entity), private sector health service provider, credit reporting body, credit provider, entity that trades in personal information, and tax file number (TFN) recipient.
[4] See ss 26WE(2) and 26WG.
[5] Explanatory Memorandum, Privacy Amendment (Notifiable Data Breaches) Bill 2016, cl 95.
[6] See ss 26WK and 26WL.
[7] See s 26WF.
[8] [1990] HCA 26; 170 CLR 104.
[9] See s 26WG.
[10] The OAIC discusses the issue of having limited or no evidence of unauthorised access and the motivations of threat actors in its Notifiable data breaches report (January to June 2023), p.22-23 (see here: https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2023).
[11] See here: https://www.aicd.com.au/risk-management/framework/cyber-security/governing-through-a-cyber-crisis-cyber-incident-response-and-recovery-for-australian-directors.html.
[12] On 3 November 2023, the Commissioner commenced civil penalty Federal Court proceedings against Australian Clinical Labs Ltd alleging it failed to conduct a reasonable and expeditious assessment in contravention of s 26WH(2).
If you would like further information or have any queries regarding other matters, please do not hesitate to contact: