Last modified on November 21st, 2022 at 5:07 pm

OAIC commences investigation into Optus data leak

Following the data breach of millions of Optus customers, the Office of the Australian Information Commission (OAIC) has launched a formal investigation into the personal information handling practices of Optus. The OAIC, in collaboration with the Australian Communications and Media Authority (ACMA), will determine whether Optus took reasonable steps to protect consumers’ personal information from …

Last modified on November 21st, 2022 at 5:19 pm

Victorian Institute of Technology found in breach of anti-spam laws

The Victorian Institute of Technology (VIT) has been found to be in breach of Australia’s anti-spam legislation. The Australian Communications and Media Authority (ACMA) commenced an investigation into VIT’s compliance following a written complaint. In its report, AMCA detailed 6045 unsolicited marketing emails sent by VIT to email addresses purchased from a third party. VIT …

Last modified on November 21st, 2022 at 5:10 pm

New research project finds growing presence of artificial intelligence in courtrooms worldwide

The Australian Institute for Judicial Administration (AIJA), UNSW Law & Justice, UNSW Allens Hub for Technology, Law, and Innovation, and the Law Society of NSW’s Future of Law and Innovation in the Profession (FLIP Stream) have conducted a joint research project into the use of artificial intelligence (AI) in the courtrooms around the world. AI …

Last modified on December 3rd, 2022 at 3:26 am

Human Technology Institute releases a model law for facial recognition in Australia

Following the alleged misuse of facial recognition technology by local retailers this year, the Human Technology Institute has released a report proposing a model law for facial recognition. Facial recognition technology in the report refers to “any computer system or device with embedded functionality that uses data drawn from human faces to verify an individual’s …

Last modified on December 3rd, 2022 at 3:26 am

Meta fined $400 million for breach of Europe’s General Data Protection Regulation

Ireland’s Data Protection Commission (Commission) has fined Meta (Facebook) approximately $400 million for contravening the General Data Protection Regulation’s (GDPR) privacy laws relating to the protection of children’s privacy online. The fine was centred on the treatment of children’s data on Meta’s app Instagram. The Commission began its investigation into Instagram back in 2020 and …

Last modified on December 3rd, 2022 at 3:26 am

APRA proposes new operational risk management requirements for emerging technology activities

At Arnotts Technology Lawyers, we regularly advise technology providers, including As-a-Service providers who supply services to Australian Prudential Regulation Authority (APRA) regulated entities, including banks, in relation to prudential and reporting standards compliance including CPG 231 Outsourcing, CPG 234 Information Security and CPG 235 Managing Data Risk. APRA has commenced consultation for a new prudential …

Last modified on December 3rd, 2022 at 3:27 am

Treasury seeks stakeholder consultation to allow virtual regulatory hearings and examinations

The Treasury is seeking stakeholder opinion on new legislation to clarify the ability of regulators to hold virtual hearings and examinations. The proposed Treasury Laws Amendment (Modernising Business Communications) Bill 2022 (Cth) will amend existing regulator legislation to enable respective authorities to hold technology-based hearings and examinations. Respective authorities that will be affected by the …

Last modified on December 3rd, 2022 at 3:27 am

Federal Court decision examines insurance policy in the context of cyberattacks

In the decision of Inchcape Australia Limited v Chubb Insurance Australia Limited [2022] FCA 883, the Federal Court of Australia interpreted the terms of an insurance policy in the case of a cyberattack. The facts of the case include a ransomware attack on Inchcape, destroying the company’s data on its primary server, offsite backup, and …

Last modified on December 3rd, 2022 at 3:27 am

Priority registration for “.au” domain names until 20 September 2022

Australian organisations, businesses and individuals can now register for a new category of domain names in Australia. This category is known as “.au direct” and will allow website URLs to drop dot com variants, ie. “www.example.au” rather than “www.example.com.au”. Australian entities with an existing “.com.au” suffix have priority registration until 20 September 2022 to register …

Last modified on December 3rd, 2022 at 3:28 am

Commonwealth Ombudsman report highlights compliance issues when handling telecommunications metadata

The Commonwealth Ombudsman released its annual report of the Telecommunications (Interception and Access) Act 1979 (Cth). This report detailed the inspection of agencies’ records relating to stored communications and access to telecommunications data between 1 July 2020 and 30 June 2021. The investigation discovered a serious lack of compliance by law enforcement agencies, such as …