Case Law – Respond expeditiously to cyber incidents; but plan now! – Datateks Pty Ltd (Privacy) [2023] AICmr 97 and Pacific Lutheran College (Privacy) [2023] AICmr 98

May 6 2024

By Jason Symons, Partner, Max Feng, Lawyer, Jeremy Williams, Paralegal

 Introduction

The Privacy Commissioner through the determinations of Datateks Pty Ltd (Privacy) [2023] AICmr 97 (Datateks)[1] and Pacific Lutheran College (Privacy) [2023] AICmr 98 (PLC)[2] highlighted the critical importance of responding to an “eligible data breach” expeditiously to comply with its regulations.  The Commissioner also emphasised the need for organisations to prepare an incident response plan before any cyber incident occurs, which is ready to guide the entity through the assessment process promptly as time is of the essence.

Assessment of eligible data breaches

The Notifiable Data Breach (NDB) Scheme, found in Part IIIC of the Privacy Act (Cth) (Privacy Act), regulates the investigation and notification of “eligible data breaches” (EDB) suffered by regulated entities[3].

An EDB occurs when there has been unauthorised access or disclosure of personal information (or other information referred to in s 26WE(1)) that a reasonable person would consider is likely to result in serious harm to the individuals whom the information relates.[4]

Critically, the investigation must be undertaken in accordance with s 26WH, which requires:

  1. if:
    1. an entity is aware that there are reasonable grounds to suspect that there may have been an EDB of the entity; and
    2. the entity is not aware that there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity,
  2. then the entity must:
    1. carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an EDB of the entity; and
    2. take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware of a suspected EDB.

Essentially, the EDB assessment requires the entity to investigate the data breach in such a way that it moves as promptly and efficiently as reasonably possible in the circumstances,[5] from merely having a ‘suspicion’, to ‘believing’ it has suffered an EDB that requires notification[6] (unless effective remedial steps can be taken[7]).

Background

Datateks operated a business that builds, operates, and maintains communication networks and infrastructures for various entities.  On 26 June 2020, Datateks became aware three of its email accounts were subject to unauthorised access by a third party and had been used to carry out a phishing campaign.  The types of personal information held in the email accounts were dates of birth, credit card information, bank account details, superannuation information, driver licence, birth certificate, working with children check and Medicare card information, and tax file numbers (TFNs).

PLC was subjected to unauthorised access of an email account belonging to the manager of PLC’s Early Learning Centre and Outside School Hours Care Services on 28 May 2020.  The unauthorised access by a third party exposed the financial details, TFNs, medical information, identity information and contact information of 367 individuals.

Determinations

The Commissioner found that both Datateks and PLC had interfered with individuals’ privacy under the Privacy Act by failing to:

  1. conduct the EDB assessment in an expeditious manner and take all reasonable steps to complete the assessment within 30 days, in breach of s 26WH(2); and
  2. notify the Commissioner as soon as reasonably practicable that an EDB had occurred, in breach of s 26WK(2).

The Commissioner further required Datateks and PLC to prepare an incident response plan (IRP) containing certain minimum details and provide a copy to the Commissioner within 3 and 6 months of the determination respectively.  PLC also had to implement an information security program to ensure it protected personal information in accordance with APP 11.1.

Suspicion vs belief

 Relevantly, the Commissioner attributed “suspicion” and “belief” to the definitions ascribed by the High Court of Australia in George v Rockett[8] whereby:

  • The facts which can reasonably ground a suspicion may be quite insufficient to reasonably ground a belief, yet some factual basis for the suspicion must be shown”; and
  • The objective circumstances sufficient to show a reason to believe something need to point more clearly to the subject matter of the belief, but that is not to say that the objective circumstances must establish on the balance of probabilities that the subject matter in fact occurred or exists: the assent of belief is given on more slender evidence than proof. Belief is an inclination of the mind towards assenting to, rather than rejecting, a proposition and the grounds which can reasonably induce that inclination of the mind may, depending on the circumstances, leave something to surmise or conjecture evidently.

Evident from the Commissioner’s perspective, the threshold for ‘suspicion’ for a regulated entity is far lower than that of a ‘belief’.  In both cases, the Commissioner took the view the required ‘suspicion’ existed within the first 24 hours of both entities discovering the unauthorised access to email accounts.  The Commissioner placed significance on each entity’s awareness of their ‘usual practice’ of using email accounts to collect personal information and health information; and, in Datatek’s case, as also the ‘de factor usual practice’ to hold such information as sufficient basis in fact to form a suspicion that an EDB had occurred.

Hence, both Datateks and PLC were expected to start their EDB assessment under s 26WH the very next day of discovering the cyber incident.  The Commissioner differentiated a suspicion and belief in relation to the forensic investigation work, by finding the suspicion can be formed prior, but the belief may require its completion.

Taking all reasonable steps

 While not a strict timeframe, s 26WH dictates that the entity take “all reasonable steps” to complete the EDB assessment within 30 days.  The Commissioner in PLC noted that “what constitutes ‘all reasonable steps’ in this context will vary depending on all the circumstances, including the circumstances of the entity and the suspected eligible data breach”.

In Datateks, the Commissioner found whilst efforts were made to engage a cyber security specialist for a forensic investigation within the first 30 days, the scope and depth of the investigation was limited, with no evaluation of the personal information involved.  As Datateks’ activities primarily focused on containment and basic investigation of the root cause, it did not undertake any assessment of the personal information involved “and the potential risk of harm that may follow, [which] is an essential element of an assessment under s 26WH” until after the forensic investigation was completed on day 74.

Whilst in PLC, the Commissioner found substantive progress was lacking until after the 30 day mark, with the scope of investigation work not agreed until day 67 and the investigation commencing on day 71.  Notably, despite extracting the compromised email account’s contents within 2 days after the initial breach, no further analysis of the personal information was conducted within the initial 30 days.  Significantly, the Commissioner also took into account “the resources available to the respondent” and found that “the presence of multiple workstreams should not present such a significant burden to warrant such an untimely response”.

Serious harm test

Essential to the EDB assessment is the satisfaction of the serious harm test of an eligible data breach in s 26WE(2).  An entity can suspect an eligible data breach, but if it never forms a belief that it is one, notification is not required.  As outlined above, that requires the breach to be “likely to result in serious harm” to the individuals impacted.

Accordingly, when undertaking the EDB assessment, both the forensic investigation of the compromise and the data review, must be working towards forming the required belief that the individuals are likely to suffer serious harm taking into account all relevant matters[9], including the kinds of information involved.

In these decisions, the Commissioner only very briefly considered the serious harm test.  In Datateks, it was found “Given the types of personal information routinely held within its general email account … a reasonable person would conclude that unauthorised access to this information would be likely to result in serious harm to the individuals” in the form of identity theft or other fraud.  PLC admitted the serious harm test was satisfied, so the Commissioner was not required to make a finding.

In circumstances where the compromised email account does not contain such highly valuable information, it will be interesting to see where the Commissioner ‘draws the line’ on serious harm.  The Commissioner also did not clarify the likelihood of serious harm in situations where forensic investigation work uncovers activity by the threat actor that suggests it was not motivated to use (or sell) the personal information accessible to commit fraud against individuals, but rather misdirection payment fraud against the entity for example.[10]

Cyber insurance assists expeditiousness

Evident from the Commissioner’s determinations, both Datateks’ and PLC’s investigation delays, including the need for expert assistance and the engagement of third-party vendors, significantly hindered timely assessment completion.

A cyber insurance policy is designed to assist organisations navigate through a cyber incident as it occurs and, amongst other things, can assist with:

  1. Incident response support – comprised of legal expertise, forensic investigators, and crisis communication specialists to help organisations respond efficiently and effectively to cyber incidents, and meet regulatory obligations such as the EDB assessment and reporting.
  2. Costs protection – assist with mitigating the financial impact of a cyber incident, such as data breaches, ransomware attacks, or network disruptions, by covering expenses related to investigation, legal and other vendor fees, and even extortion payments, reducing the financial burden on the insured entity.

The structure and purpose of the first party cover available in cyber insurance assists an insured to investigate an incident, assess and meet its legal obligations, with the expeditiousness required when time is of the essence.

Fail to (incident response) plan, plan to fail

The Australian Institute of Company Directors (AICD) emphasised in its recently released “Governing Through a Cyber Crisis” guidebook[11] that a “board must be confident the organisation is adequately prepared” for a cyber incident and “this experience can only be gained through having a well-tested cyber incident response plan in place”.

Leaving it until an event occurs will put the entity at risk of regulatory action[12].  Organisations should be planning for it now, by having a robust IRP (like Datateks and PLC were ordered to prepare) that outlines the internal roles and responsibilities, external vendors to be engaged, as well as details of the insurer and coverage, and aligns with existing business continuity plans.  It should also be tested regularly with simulated incident exercises.

The OAIC has clearly placed priority on investigating incidents where delay in notifying is an issue.  Understanding and planning how to undertake a reasonable and expeditious assessment of a suspected eligible data breach within the tight timeframe is critical for any organisation regulated by the Privacy Act.

 

 

 

[1] See here: https://www6.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2023/97.html.

[2] See here: https://www6.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2023/98.html.

[3] A regulated entity for the purposes of the NDB scheme is any private organisation with an annual turnover of more than AU$3 million (APP entity), private sector health service provider, credit reporting body, credit provider, entity that trades in personal information, and tax file number (TFN) recipient.

[4] See ss 26WE(2) and 26WG.

[5] Explanatory Memorandum, Privacy Amendment (Notifiable Data Breaches) Bill 2016, cl 95.

[6] See ss 26WK and 26WL.

[7] See s 26WF.

[8] [1990] HCA 26; 170 CLR 104.

[9] See s 26WG.

[10] The OAIC discusses the issue of having limited or no evidence of unauthorised access and the motivations of threat actors in its Notifiable data breaches report (January to June 2023), p.22-23 (see here: https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2023).

[11] See here: https://www.aicd.com.au/risk-management/framework/cyber-security/governing-through-a-cyber-crisis-cyber-incident-response-and-recovery-for-australian-directors.html.

[12] On 3 November 2023, the Commissioner commenced civil penalty Federal Court proceedings against Australian Clinical Labs Ltd alleging it failed to conduct a reasonable and expeditious assessment in contravention of s 26WH(2).