Following the data breach of millions of Optus customers, the Office of the Australian Information Commission (OAIC) has launched a formal investigation into the personal information handling practices of Optus. The OAIC, in collaboration with the Australian Communications and Media Authority (ACMA), will determine whether Optus took reasonable steps to protect consumers’ personal information from …
The Victorian Institute of Technology (VIT) has been found to be in breach of Australia’s anti-spam legislation. The Australian Communications and Media Authority (ACMA) commenced an investigation into VIT’s compliance following a written complaint. In its report, AMCA detailed 6045 unsolicited marketing emails sent by VIT to email addresses purchased from a third party. VIT …
The Australian Institute for Judicial Administration (AIJA), UNSW Law & Justice, UNSW Allens Hub for Technology, Law, and Innovation, and the Law Society of NSW’s Future of Law and Innovation in the Profession (FLIP Stream) have conducted a joint research project into the use of artificial intelligence (AI) in the courtrooms around the world. AI …
Following the alleged misuse of facial recognition technology by local retailers this year, the Human Technology Institute has released a report proposing a model law for facial recognition. Facial recognition technology in the report refers to “any computer system or device with embedded functionality that uses data drawn from human faces to verify an individual’s …
Ireland’s Data Protection Commission (Commission) has fined Meta (Facebook) approximately $400 million for contravening the General Data Protection Regulation’s (GDPR) privacy laws relating to the protection of children’s privacy online. The fine was centred on the treatment of children’s data on Meta’s app Instagram. The Commission began its investigation into Instagram back in 2020 and …
At Arnotts Technology Lawyers, we regularly advise technology providers, including As-a-Service providers who supply services to Australian Prudential Regulation Authority (APRA) regulated entities, including banks, in relation to prudential and reporting standards compliance including CPG 231 Outsourcing, CPG 234 Information Security and CPG 235 Managing Data Risk. APRA has commenced consultation for a new prudential …
The Treasury is seeking stakeholder opinion on new legislation to clarify the ability of regulators to hold virtual hearings and examinations. The proposed Treasury Laws Amendment (Modernising Business Communications) Bill 2022 (Cth) will amend existing regulator legislation to enable respective authorities to hold technology-based hearings and examinations. Respective authorities that will be affected by the …
In the decision of Inchcape Australia Limited v Chubb Insurance Australia Limited [2022] FCA 883, the Federal Court of Australia interpreted the terms of an insurance policy in the case of a cyberattack. The facts of the case include a ransomware attack on Inchcape, destroying the company’s data on its primary server, offsite backup, and …
Australian organisations, businesses and individuals can now register for a new category of domain names in Australia. This category is known as “.au direct” and will allow website URLs to drop dot com variants, ie. “www.example.au” rather than “www.example.com.au”. Australian entities with an existing “.com.au” suffix have priority registration until 20 September 2022 to register …
The Commonwealth Ombudsman released its annual report of the Telecommunications (Interception and Access) Act 1979 (Cth). This report detailed the inspection of agencies’ records relating to stored communications and access to telecommunications data between 1 July 2020 and 30 June 2021. The investigation discovered a serious lack of compliance by law enforcement agencies, such as …