SlideShare a Scribd company logo
1 of 40
The Changing
Face of Privacy
Laws
Craig Subocz
BE (Hons), LLB, LLM, Grad.
Cert. in Entrepreneurship &
Innovation
Senior Associate
1 April 2014
The information contained in this
presentation is intended as general
commentary and should not be
regarded as legal advice. Should you
require specific advice on the topics or
areas discussed please contact the
presenter directly.
Disclaimer
Agenda
What are the
new laws?
How the new
laws may
affect you
What should
you do?
A brief history of the Privacy Act
1988: Privacy Act
introduced
12/2001: NPPs
introduced
1/2006: ALRC
asked
to report on Act’s
effectiveness
8/2008: ALRC
delivers 3-volume
report, with 295
recommendations
10/2009: Govt
releases its First
Stage Response
10/2010: Govt
releases
exposure draft of
legislation
12/3/2014:
Privacy Act
amendments
take effect
12/2012:
Enhancing
Privacy
Protection Bill
passed by
Parliament
5/2012:
Enhancing
Privacy
Protection Bill
introduced
What are the new laws?
• Distinguished from laws protecting
confidential information, Spam Act, Do Not
Call Register Act, etc.
• Privacy Act regulates the collection, use and
disclosure of “personal information” by “APP
entities” from individuals.
• APP entities are organisations bound to
comply with the Privacy Act
Disclosure
Collection Use
Third Party
Organisation
Individual
What are the new laws?
• Replace the NPPS with the APPs
• Re-write credit reporting regime
• Greater consumer protections
• Expand OAIC powers
• Greater investigatory powers
• Increase penalties for privacy breaches
• Penalties up to $1.7 million
• Enforceable undertakings
How privacy laws may affect you
You must comply with the Act if you answer ‘yes’ to
any of the following questions:
• Is your annual turnover in excess of $3 million?
• Do you provide a “health service”?
• a private health service provider
• Do you disclose personal information about
another individual to a 3rd party for a benefit,
service or advantage?
• Do you provide a benefit, service or advantage to
collect personal information about an individual
from a 3rd party?
Definition of ‘personal
information’
• Although definition of ‘personal information’
amended, little practical change.
• From 12 March 2014, ‘personal information’
means “information or an opinion about an
identified individual, or an individual who is
reasonably identifiable:
• Whether the information or opinion is true or
not; and
• Whether the information or opinion is recorded
in a material form or not.”
• NB: ‘employee records’ still exempt from Privacy
Act, but note Fair Work Act requirements
APP 1 (openness and
transparent management)
• More than just updating your privacy policies (if you
have one).
• APP 1 requires “APP entities” to implement
practices, procedures and systems to ensure
compliance.
• Employee training on privacy
• Clear, transparent complaints handling procedure
• An APP entity is an organisation bound by the Act
to comply with the Australian Privacy Principles
Case Study – LSO Pty Ltd
• Annual turnover of $5 million
• Sells fast moving consumer goods
• Online sales
• Retail channels
• Direct to consumer channels
• Offers ‘valued’ customers regular “discount days”
• To qualify, customers must provide LSO with their
name, email address and mobile number
• LSO stores this information in a computerised
database.
Case Study – LSO Pty Ltd
• In LSO’s privacy policy (last updated in 2006), a
director is named the “privacy officer”.
• He has little knowledge of Australia’s privacy
laws.
• LSO has not provided its directors and staff with
privacy training.
• LSO has no formal privacy compliance policies
or procedures.
APP 2 (anonymity and
pseudonymity)
• Individuals may deal anonymously or
pseudonymously with you.
• But you are not obliged to if:
• You are required or authorised by law or court or
tribunal order to deal with identified individuals;
or
• It is impracticable for you to deal with individuals
who have not identified themselves.
Case study – LSO Pty Ltd
• LSO encourages customer participation on its
interactive social media presence
• LSO removes posts made by individuals who do
not use their real names.
APP 3 (collection of solicited
personal information)
• You solicit personal information if you expressly ask for
the information or take active steps to collect the
information
• Personal information should only be collected if it is
reasonably necessary for your functions or activities
• Your privacy policy should set out the relevant
functions and activities for which the information is
being collected
• Sensitive information should generally only be collected
with individual’s consent
• Personal information should only be collected by lawful
and fair means and directly from an individual (unless
an exception applies)
APP 3 (examples of soliciting
personal information)
• You ask for the personal information to be provided through
the completion of a form by an individual relating to the
goods/services you supply
• You exchange business cards with an individual at a meeting
• Information is disclosed to you in response to your request by
an entity where that information includes personal
information
• You offer prizes in a competition that requires entries to be
submitted
• You receive a complaint in response to a general invitation
on your website to individuals to complain to you
• An individual submits an employment application in response
to a job advertisement
APP 4 (unsolicited personal
information)
• Personal information is unsolicited if you receive it without
asking for it
• misdirected mail, unsolicited employment applications
or promotional flyers containing personal information
• Must decide whether you could have collected the
information under APP 3.
• If you decide you could not have collected the information,
must be destroyed or de-identified as soon as practicable if
lawful and reasonable to do so.
• You may need it for tax reasons
• You may be prohibited by law or court order from
destroying or de-identifying the information
Case study – LSO Pty Ltd
 Solicits PI via numerous methods:
• Customers sign up for daily discounts
• Customers’ social media interactions
• Customer complaints
• Occasional customer surveys
 Also receives PI occasionally:
• Misdirected mail
• Promotional materials from suppliers with information
identifying a salesperson, including contact information
• Employment applications
Case Study – LSO Pty Ltd
Directors unclear on
their legal obligations
regarding collection of
PI.
Directors do not
understand how the
PI which LSO collects
may be used in LSO’s
business, whether
LSO needs all the PI
it actually collects and
from where and how
LSO collects PI.
APP 5 (notification of collection)
• Your identity and contact details
• The fact and circumstances of collection
• Whether the collection is authorised or required
by law
• Why you collected the PI
• What happens if the PI is not collected
• Your usual disclosures of collected PI
• Information about your privacy policy
• Whether you are likely to disclose PI overseas
Before or at the time of collection, clients
must notify individuals, or otherwise ensure
that individuals are aware of:
APP 6 (use and disclosure)
Personal information may only be used or disclosed
for the purpose of collection (‘primary purpose’) or
for a secondary purpose if an exception applies:
Individual consents
Individual would reasonably expect our client
to use or disclose his/her PI for that purpose
and that purpose is related to the primary
purpose
Other exception applies
APP 6 (use and disclosure)
If using or disclosing personal information for a
secondary purpose, must record the use or
disclosure in writing:
• Date of use or disclosure
• Details of information used or disclosed
• How the information was used
• To whom was the information disclosed
• The exception on which use or disclosure is
based
Case study – LSO Pty Ltd
• To frame LSO’s purposes for use and disclosure, its directors
should understand:
• When does LSO use PI
• How LSO uses PI
• To whom LSO discloses PI
• For example, PI could be used or disclosed for:
• Order fulfilments
• Marketing and promotions
• Credit checks
• Debt recovery
APP 7 (direct marketing)
APP 7 prohibits you
from using or disclosing
PI in direct marketing
unless exception
applies: Collection direct from
individual and individual
would reasonably
expect their PI to be
used for direct
marketing
Individual would not
reasonably expect their
PI to be used for direct
marketing, but consents
to the use
APP 7 (direct marketing)
• NB: fine distinction between ‘reasonable
expectation’ and ‘consent’
• Whether an individual would reasonably
expect depends on circumstances
• Consent can be express or inferred
• If permitted to use PI for direct marketing, each
message must contain an ‘opt out’ provision.
• APP 7 remains subject to the Do Not Call
Register Act and the Spam Act.
Case Study – LSO Pty Ltd
• LSO constantly markets products
to its customers.
• Posts customers catalogues
• Emails customers ‘daily deals’
• Tracks customers’ browsing
habits and buys ad-words to
trigger ads in search engines
and social media sites
• Whether LSO must comply with
APP 7 depends on the context of
the marketing.
APP 8 (cross-border disclosures)
• Regulates cross-border disclosure of PI.
• Two choices for compliance:
• APP 8.1 - before disclosure, take reasonable steps
to ensure overseas recipient does not breach the
APPs.
• Contract with recipient
• APP 8.2 allows compliance in a variety of ways:
• Reasonable belief about overseas laws
• Individual consents to disclosure
• Disclosure is required or authorised by law
Case Study – LSO Pty Ltd
• LSO uses a multinational cloud
provider to host its critical
business systems.
• Cloud provider hosts information
about LSO’s customers, including
their PI.
• LSO agrees to cloud provider’s
terms.
APP 9 (government identifiers)
• Prohibits an organisation from adopting, using
or disclosing a government related identifier
(except ABNs).
• An ‘identifier’ is a number, letter or symbol (or
combination) that is used to identify an
individual or verify that individual’s identity.
• A ‘government related identifier’ is an identifier
assigned by any government agency.
APP 10 (qualify of personal
information)
When holding PI, you must take reasonable
steps to ensure:
• the PI collected is accurate, up-to-date and
complete.
• the PI used and disclosed is, having regard
to the purpose of use or disclosure,
accurate, up-to-date, complete and
relevant.
APP 10 (quality of personal
information)
‘Reasonable steps’ depend on the
circumstances, including:
• The nature of the PI
• The adverse consequences for the
individual if poor quality PI is collected,
used or disclosed
• Method or time of collection
• The practicability of taking steps to ensure
quality.
APP 11 (security of personal
information)
• Reasonable steps to protect PI
against misuse, interference and
loss
• Unless information is in a Cwth
record or you must by law retain
PI, if PI is no longer needed,
must take reasonable steps to
destroy PI
• You should consider document
destruction, tax records and other legal
obligations on preservation of
documents
Case study – LSO Pty Ltd
• PI of LSO’s customers becomes
inadvertently public when the sales
director loses an unencrypted USB drive
containing latest survey results in a pub.
• Privacy Commissioner investigates LSO’s
alleged privacy breach.
• Privacy Commissioner concludes that LSO
breached APPs 1, 2, 3, 8 and 11.
• LSO gives enforceable undertakings to the
Privacy Commissioner.
APP 12 (access)
• If you hold PI about an individual, our client must,
on the individual’s request, grant the individual
access to the PI.
• Access may be denied on a number of grounds,
including:
• Serious threat to life, health or safety
• Unreasonable impact on other individuals’ privacy
• Frivolous or vexatious request
• Anticipated legal proceedings
• Prejudice negotiations between you and the individual
• Law enforcement matters
APP 12 (access)
• You must deal with access requests within a
reasonable period of time
• If reasonable and practicable, grant access in
the manner requested
• If access is refused, must give written notice
setting out reasons for refusal and the
mechanisms available for complaint
• You can charge for access
APP 13 (correction)
• You must take reasonable steps to correct PI
that is inaccurate, incomplete, etc.
• Take reasonable steps to notify third parties to
whom PI was previously disclosed, if requested
• Reasons must be given if correction is refused
• Must deal with correction requests within a
reasonable period after request is made
What should you do?
THE NEW PRIVACY LAWS ARE
COMPREHENSIVE
What should you do now?
Complete a privacy audit to understand what PI
you collect, hold, use and disclose:
Include a review of client’s privacy policy,
collection statements, etc
Assess what, if any, complaints resolution
process the client may have
If disclosing PI to third parties, review the
basis on which disclosure is made
The audit’s outcome should help prepare you for
the new privacy laws
What should you ASAP?
Don’t dawdle – the new laws are already in effect!
Design and implement a privacy compliance
program
Focus on:
risk identification and management
training for all staff
compliance monitoring
Don’t forget to update your privacy policy
Review interactions with your customers
What should you do in the future?
• Apart from complying with the Privacy Act,
document how you comply with the Act
• If OAIC investigates, documentary proof will
help your arguments
• Remember – the Act is designed to protect
individuals, not you
• In particular, treat complaints appropriately
and responsively
• Generally, take no longer than 30 days to
deal with a complaint
Please Contact
Craig Subocz
Senior Associate
(03) 9609 1646
csubocz@rk.com.au
rk.com.au
Questions

More Related Content

What's hot

Privacy and Electronic Communications (EC Directive) Regulations 2003
Privacy and Electronic Communications (EC Directive) Regulations 2003Privacy and Electronic Communications (EC Directive) Regulations 2003
Privacy and Electronic Communications (EC Directive) Regulations 2003Alexander Zhuravlev
 
spy after employees
spy after employeesspy after employees
spy after employeesJuscutum
 
01.05.2020 finalised joint representation on aarogya setu
01.05.2020   finalised joint representation on aarogya setu01.05.2020   finalised joint representation on aarogya setu
01.05.2020 finalised joint representation on aarogya setuZahidManiyar
 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Quarles & Brady
 
Manufacturing Success Seminar - April 29, 2015
Manufacturing Success Seminar - April 29, 2015Manufacturing Success Seminar - April 29, 2015
Manufacturing Success Seminar - April 29, 2015This account is closed
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
Vietnam – Intellectual Property Rights – 2015
Vietnam – Intellectual Property Rights – 2015Vietnam – Intellectual Property Rights – 2015
Vietnam – Intellectual Property Rights – 2015Dr. Oliver Massmann
 
FINAL Employers Guide to Best Practices 2013 (1)
FINAL Employers Guide to Best Practices 2013 (1)FINAL Employers Guide to Best Practices 2013 (1)
FINAL Employers Guide to Best Practices 2013 (1)Julie Sweeney
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake Morgan
 

What's hot (12)

Legal pro
Legal proLegal pro
Legal pro
 
Privacy and Electronic Communications (EC Directive) Regulations 2003
Privacy and Electronic Communications (EC Directive) Regulations 2003Privacy and Electronic Communications (EC Directive) Regulations 2003
Privacy and Electronic Communications (EC Directive) Regulations 2003
 
spy after employees
spy after employeesspy after employees
spy after employees
 
01.05.2020 finalised joint representation on aarogya setu
01.05.2020   finalised joint representation on aarogya setu01.05.2020   finalised joint representation on aarogya setu
01.05.2020 finalised joint representation on aarogya setu
 
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
Business Law Training: Pushing CCPA Compliance Over the Finish Line: New Deve...
 
Manufacturing Success Seminar - April 29, 2015
Manufacturing Success Seminar - April 29, 2015Manufacturing Success Seminar - April 29, 2015
Manufacturing Success Seminar - April 29, 2015
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
HR 210 Bennett9e ppt ch14
HR 210 Bennett9e ppt ch14HR 210 Bennett9e ppt ch14
HR 210 Bennett9e ppt ch14
 
EANJ Letter Brief to NLRB RE: Purple Communications
EANJ Letter Brief to NLRB RE: Purple CommunicationsEANJ Letter Brief to NLRB RE: Purple Communications
EANJ Letter Brief to NLRB RE: Purple Communications
 
Vietnam – Intellectual Property Rights – 2015
Vietnam – Intellectual Property Rights – 2015Vietnam – Intellectual Property Rights – 2015
Vietnam – Intellectual Property Rights – 2015
 
FINAL Employers Guide to Best Practices 2013 (1)
FINAL Employers Guide to Best Practices 2013 (1)FINAL Employers Guide to Best Practices 2013 (1)
FINAL Employers Guide to Best Practices 2013 (1)
 
Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012Blake lapthorn In House Lawyer forum - 11 Sept 2012
Blake lapthorn In House Lawyer forum - 11 Sept 2012
 

Viewers also liked

Four Things You May Be Doing Wrong In HR
Four Things You May Be Doing Wrong In HRFour Things You May Be Doing Wrong In HR
Four Things You May Be Doing Wrong In HRRussell_Kennedy
 
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016Russell_Kennedy
 
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016Russell_Kennedy
 
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...Russell_Kennedy
 
Grounded Communications - Communicating in a Crisis - 24 May 2016
Grounded Communications - Communicating in a Crisis - 24 May 2016Grounded Communications - Communicating in a Crisis - 24 May 2016
Grounded Communications - Communicating in a Crisis - 24 May 2016Russell_Kennedy
 
Global Mobility - legal issues for work safety and security
Global Mobility - legal issues for work safety and securityGlobal Mobility - legal issues for work safety and security
Global Mobility - legal issues for work safety and securityFiona Austin
 
WHS Risks - Overview for Public Sector Managers
WHS Risks - Overview for Public Sector ManagersWHS Risks - Overview for Public Sector Managers
WHS Risks - Overview for Public Sector ManagersRussell_Kennedy
 
Workplace health and safety inspection form (self guided)
Workplace health and safety inspection form (self guided)Workplace health and safety inspection form (self guided)
Workplace health and safety inspection form (self guided)D S
 

Viewers also liked (8)

Four Things You May Be Doing Wrong In HR
Four Things You May Be Doing Wrong In HRFour Things You May Be Doing Wrong In HR
Four Things You May Be Doing Wrong In HR
 
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016
Russell Kennedy - Legal Issues in Crisis Management - 24 May 2016
 
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016
Russell Kennedy Health Seminar by Matthew Carroll - 6 September 2016
 
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...
Russell Kennedy Not-for-profit Seminar: Strategic challenges facing primary ...
 
Grounded Communications - Communicating in a Crisis - 24 May 2016
Grounded Communications - Communicating in a Crisis - 24 May 2016Grounded Communications - Communicating in a Crisis - 24 May 2016
Grounded Communications - Communicating in a Crisis - 24 May 2016
 
Global Mobility - legal issues for work safety and security
Global Mobility - legal issues for work safety and securityGlobal Mobility - legal issues for work safety and security
Global Mobility - legal issues for work safety and security
 
WHS Risks - Overview for Public Sector Managers
WHS Risks - Overview for Public Sector ManagersWHS Risks - Overview for Public Sector Managers
WHS Risks - Overview for Public Sector Managers
 
Workplace health and safety inspection form (self guided)
Workplace health and safety inspection form (self guided)Workplace health and safety inspection form (self guided)
Workplace health and safety inspection form (self guided)
 

Similar to The changing face of privacy laws

MDCC: Privacy and trade practices - 29 October 2014
MDCC: Privacy and trade practices - 29 October 2014MDCC: Privacy and trade practices - 29 October 2014
MDCC: Privacy and trade practices - 29 October 2014Infodec Communications
 
pp_101_notes_eng.pdf
pp_101_notes_eng.pdfpp_101_notes_eng.pdf
pp_101_notes_eng.pdfAbel Mutize
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentationIan Clive Oultram
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013Rachel Aldighieri
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowOgilvy Health
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Financial Poise
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Financial Poise
 
Education law conference, March 2017 - Manchester - Understanding and dischar...
Education law conference, March 2017 - Manchester - Understanding and dischar...Education law conference, March 2017 - Manchester - Understanding and dischar...
Education law conference, March 2017 - Manchester - Understanding and dischar...Browne Jacobson LLP
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationEndcode_org
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants
Welcome to the Team! Recruiting and Hiring, Including Restrictive CovenantsWelcome to the Team! Recruiting and Hiring, Including Restrictive Covenants
Welcome to the Team! Recruiting and Hiring, Including Restrictive CovenantsFinancial Poise
 
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...Financial Poise
 
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...Hanaysha
 
What You Need to Know About Privacy
What You Need to Know About PrivacyWhat You Need to Know About Privacy
What You Need to Know About PrivacyNow Dentons
 

Similar to The changing face of privacy laws (20)

MDCC: Privacy and trade practices - 29 October 2014
MDCC: Privacy and trade practices - 29 October 2014MDCC: Privacy and trade practices - 29 October 2014
MDCC: Privacy and trade practices - 29 October 2014
 
pp_101_notes_eng.pdf
pp_101_notes_eng.pdfpp_101_notes_eng.pdf
pp_101_notes_eng.pdf
 
Vanessa Baic
Vanessa BaicVanessa Baic
Vanessa Baic
 
Data Protection Act presentation
Data Protection Act presentationData Protection Act presentation
Data Protection Act presentation
 
POPI Update 2013
POPI Update 2013POPI Update 2013
POPI Update 2013
 
Can we ask that
Can we ask thatCan we ask that
Can we ask that
 
DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013DMA - DPC Workshop - 23 October 2013
DMA - DPC Workshop - 23 October 2013
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
 
4514611.ppt
4514611.ppt4514611.ppt
4514611.ppt
 
Privacy Needs to be Personal
Privacy Needs to be PersonalPrivacy Needs to be Personal
Privacy Needs to be Personal
 
PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants (...
 
Education law conference, March 2017 - Manchester - Understanding and dischar...
Education law conference, March 2017 - Manchester - Understanding and dischar...Education law conference, March 2017 - Manchester - Understanding and dischar...
Education law conference, March 2017 - Manchester - Understanding and dischar...
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants
Welcome to the Team! Recruiting and Hiring, Including Restrictive CovenantsWelcome to the Team! Recruiting and Hiring, Including Restrictive Covenants
Welcome to the Team! Recruiting and Hiring, Including Restrictive Covenants
 
Ppt
PptPpt
Ppt
 
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...
Recruiting and Hiring, Including Restrictive Covenants (Series: Protecting Yo...
 
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
 
What You Need to Know About Privacy
What You Need to Know About PrivacyWhat You Need to Know About Privacy
What You Need to Know About Privacy
 

More from Russell_Kennedy

Seminar: Social media in the workplace - 30 November 2016
Seminar: Social media in the workplace - 30 November 2016Seminar: Social media in the workplace - 30 November 2016
Seminar: Social media in the workplace - 30 November 2016Russell_Kennedy
 
Illicit Tobacco Investigations and Prosecutions Presentation
Illicit Tobacco Investigations and Prosecutions PresentationIllicit Tobacco Investigations and Prosecutions Presentation
Illicit Tobacco Investigations and Prosecutions PresentationRussell_Kennedy
 
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...Russell_Kennedy
 
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...Russell_Kennedy
 
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ..."He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...Russell_Kennedy
 
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016Clinical Governance Presentation by Michael Gorton AM - 21 July 2016
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016Russell_Kennedy
 
Workplace Relations Seminar - Wednesday 20 July 2016
Workplace Relations Seminar - Wednesday 20 July 2016Workplace Relations Seminar - Wednesday 20 July 2016
Workplace Relations Seminar - Wednesday 20 July 2016Russell_Kennedy
 
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016Russell_Kennedy
 
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...Russell_Kennedy
 
Restructures, redundancies and transfer of business: Getting it Right
Restructures, redundancies and transfer of business: Getting it RightRestructures, redundancies and transfer of business: Getting it Right
Restructures, redundancies and transfer of business: Getting it RightRussell_Kennedy
 
Cyber Security in the Interconnected World
Cyber Security in the Interconnected WorldCyber Security in the Interconnected World
Cyber Security in the Interconnected WorldRussell_Kennedy
 
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...Russell_Kennedy
 
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...Russell_Kennedy
 
Changes to the ACT Coroner Act
Changes to the ACT Coroner ActChanges to the ACT Coroner Act
Changes to the ACT Coroner ActRussell_Kennedy
 
Workplace Relations Seminar
Workplace Relations Seminar Workplace Relations Seminar
Workplace Relations Seminar Russell_Kennedy
 
Merge, restructure or wind up?
Merge, restructure or wind up?Merge, restructure or wind up?
Merge, restructure or wind up?Russell_Kennedy
 
The National Disability Insurance Scheme - Update
The National Disability Insurance Scheme - UpdateThe National Disability Insurance Scheme - Update
The National Disability Insurance Scheme - UpdateRussell_Kennedy
 
Marsh V Baxter - A Legal Perspective
Marsh V Baxter - A Legal PerspectiveMarsh V Baxter - A Legal Perspective
Marsh V Baxter - A Legal PerspectiveRussell_Kennedy
 
Bullying and the Fair Work Commission – a year in review
Bullying and the Fair Work Commission – a year in reviewBullying and the Fair Work Commission – a year in review
Bullying and the Fair Work Commission – a year in reviewRussell_Kennedy
 

More from Russell_Kennedy (20)

Seminar: Social media in the workplace - 30 November 2016
Seminar: Social media in the workplace - 30 November 2016Seminar: Social media in the workplace - 30 November 2016
Seminar: Social media in the workplace - 30 November 2016
 
Illicit Tobacco Investigations and Prosecutions Presentation
Illicit Tobacco Investigations and Prosecutions PresentationIllicit Tobacco Investigations and Prosecutions Presentation
Illicit Tobacco Investigations and Prosecutions Presentation
 
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...
RKWN event: Women and the Power of Negotiation by Nicole Davidson, CMA Learni...
 
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...
I'm Never Going to Die and My Partner's Never Going to Leave Me - RKWN event ...
 
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ..."He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...
"He's never going to leave me..." and other myths - RKWN event - Wednesday 3 ...
 
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016Clinical Governance Presentation by Michael Gorton AM - 21 July 2016
Clinical Governance Presentation by Michael Gorton AM - 21 July 2016
 
Workplace Relations Seminar - Wednesday 20 July 2016
Workplace Relations Seminar - Wednesday 20 July 2016Workplace Relations Seminar - Wednesday 20 July 2016
Workplace Relations Seminar - Wednesday 20 July 2016
 
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016
Russell Kennedy and Pitcher Partners NFP Seminar - 12 July 2016
 
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...
Barrington Centre - Psychological Risks and Human Management in a Crisis - 24...
 
Restructures, redundancies and transfer of business: Getting it Right
Restructures, redundancies and transfer of business: Getting it RightRestructures, redundancies and transfer of business: Getting it Right
Restructures, redundancies and transfer of business: Getting it Right
 
Cyber Security in the Interconnected World
Cyber Security in the Interconnected WorldCyber Security in the Interconnected World
Cyber Security in the Interconnected World
 
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...
Russell Kennedy - Abuse issues in the Not For Profit sector: Handling and Pr...
 
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...
Russell Kennedy Women's Network: Develop seminar - Wills & Estates Planning f...
 
Changes to the ACT Coroner Act
Changes to the ACT Coroner ActChanges to the ACT Coroner Act
Changes to the ACT Coroner Act
 
Workplace Relations Seminar
Workplace Relations Seminar Workplace Relations Seminar
Workplace Relations Seminar
 
Aged Care Seminar
Aged Care SeminarAged Care Seminar
Aged Care Seminar
 
Merge, restructure or wind up?
Merge, restructure or wind up?Merge, restructure or wind up?
Merge, restructure or wind up?
 
The National Disability Insurance Scheme - Update
The National Disability Insurance Scheme - UpdateThe National Disability Insurance Scheme - Update
The National Disability Insurance Scheme - Update
 
Marsh V Baxter - A Legal Perspective
Marsh V Baxter - A Legal PerspectiveMarsh V Baxter - A Legal Perspective
Marsh V Baxter - A Legal Perspective
 
Bullying and the Fair Work Commission – a year in review
Bullying and the Fair Work Commission – a year in reviewBullying and the Fair Work Commission – a year in review
Bullying and the Fair Work Commission – a year in review
 

Recently uploaded

如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书SD DS
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书SD DS
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Dr. Oliver Massmann
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书SD DS
 
如何办理纽约州立大学石溪分校毕业证学位证书
 如何办理纽约州立大学石溪分校毕业证学位证书 如何办理纽约州立大学石溪分校毕业证学位证书
如何办理纽约州立大学石溪分校毕业证学位证书Fir sss
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书SD DS
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxsrikarna235
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书FS LS
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSDr. Oliver Massmann
 

Recently uploaded (20)

如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
如何办理(CQU毕业证书)中央昆士兰大学毕业证学位证书
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书如何办理(Rice毕业证书)莱斯大学毕业证学位证书
如何办理(Rice毕业证书)莱斯大学毕业证学位证书
 
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
Legal Alert - Vietnam - First draft Decree on mechanisms and policies to enco...
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
 
如何办理纽约州立大学石溪分校毕业证学位证书
 如何办理纽约州立大学石溪分校毕业证学位证书 如何办理纽约州立大学石溪分校毕业证学位证书
如何办理纽约州立大学石溪分校毕业证学位证书
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
Test Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptxTest Identification Parade & Dying Declaration.pptx
Test Identification Parade & Dying Declaration.pptx
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
如何办理伦敦南岸大学毕业证(本硕)LSBU学位证书
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
 

The changing face of privacy laws

  • 1. The Changing Face of Privacy Laws Craig Subocz BE (Hons), LLB, LLM, Grad. Cert. in Entrepreneurship & Innovation Senior Associate 1 April 2014
  • 2. The information contained in this presentation is intended as general commentary and should not be regarded as legal advice. Should you require specific advice on the topics or areas discussed please contact the presenter directly. Disclaimer
  • 3. Agenda What are the new laws? How the new laws may affect you What should you do?
  • 4. A brief history of the Privacy Act 1988: Privacy Act introduced 12/2001: NPPs introduced 1/2006: ALRC asked to report on Act’s effectiveness 8/2008: ALRC delivers 3-volume report, with 295 recommendations 10/2009: Govt releases its First Stage Response 10/2010: Govt releases exposure draft of legislation 12/3/2014: Privacy Act amendments take effect 12/2012: Enhancing Privacy Protection Bill passed by Parliament 5/2012: Enhancing Privacy Protection Bill introduced
  • 5. What are the new laws? • Distinguished from laws protecting confidential information, Spam Act, Do Not Call Register Act, etc. • Privacy Act regulates the collection, use and disclosure of “personal information” by “APP entities” from individuals. • APP entities are organisations bound to comply with the Privacy Act Disclosure Collection Use Third Party Organisation Individual
  • 6. What are the new laws? • Replace the NPPS with the APPs • Re-write credit reporting regime • Greater consumer protections • Expand OAIC powers • Greater investigatory powers • Increase penalties for privacy breaches • Penalties up to $1.7 million • Enforceable undertakings
  • 7. How privacy laws may affect you You must comply with the Act if you answer ‘yes’ to any of the following questions: • Is your annual turnover in excess of $3 million? • Do you provide a “health service”? • a private health service provider • Do you disclose personal information about another individual to a 3rd party for a benefit, service or advantage? • Do you provide a benefit, service or advantage to collect personal information about an individual from a 3rd party?
  • 8. Definition of ‘personal information’ • Although definition of ‘personal information’ amended, little practical change. • From 12 March 2014, ‘personal information’ means “information or an opinion about an identified individual, or an individual who is reasonably identifiable: • Whether the information or opinion is true or not; and • Whether the information or opinion is recorded in a material form or not.” • NB: ‘employee records’ still exempt from Privacy Act, but note Fair Work Act requirements
  • 9. APP 1 (openness and transparent management) • More than just updating your privacy policies (if you have one). • APP 1 requires “APP entities” to implement practices, procedures and systems to ensure compliance. • Employee training on privacy • Clear, transparent complaints handling procedure • An APP entity is an organisation bound by the Act to comply with the Australian Privacy Principles
  • 10. Case Study – LSO Pty Ltd • Annual turnover of $5 million • Sells fast moving consumer goods • Online sales • Retail channels • Direct to consumer channels • Offers ‘valued’ customers regular “discount days” • To qualify, customers must provide LSO with their name, email address and mobile number • LSO stores this information in a computerised database.
  • 11. Case Study – LSO Pty Ltd • In LSO’s privacy policy (last updated in 2006), a director is named the “privacy officer”. • He has little knowledge of Australia’s privacy laws. • LSO has not provided its directors and staff with privacy training. • LSO has no formal privacy compliance policies or procedures.
  • 12. APP 2 (anonymity and pseudonymity) • Individuals may deal anonymously or pseudonymously with you. • But you are not obliged to if: • You are required or authorised by law or court or tribunal order to deal with identified individuals; or • It is impracticable for you to deal with individuals who have not identified themselves.
  • 13. Case study – LSO Pty Ltd • LSO encourages customer participation on its interactive social media presence • LSO removes posts made by individuals who do not use their real names.
  • 14. APP 3 (collection of solicited personal information) • You solicit personal information if you expressly ask for the information or take active steps to collect the information • Personal information should only be collected if it is reasonably necessary for your functions or activities • Your privacy policy should set out the relevant functions and activities for which the information is being collected • Sensitive information should generally only be collected with individual’s consent • Personal information should only be collected by lawful and fair means and directly from an individual (unless an exception applies)
  • 15. APP 3 (examples of soliciting personal information) • You ask for the personal information to be provided through the completion of a form by an individual relating to the goods/services you supply • You exchange business cards with an individual at a meeting • Information is disclosed to you in response to your request by an entity where that information includes personal information • You offer prizes in a competition that requires entries to be submitted • You receive a complaint in response to a general invitation on your website to individuals to complain to you • An individual submits an employment application in response to a job advertisement
  • 16. APP 4 (unsolicited personal information) • Personal information is unsolicited if you receive it without asking for it • misdirected mail, unsolicited employment applications or promotional flyers containing personal information • Must decide whether you could have collected the information under APP 3. • If you decide you could not have collected the information, must be destroyed or de-identified as soon as practicable if lawful and reasonable to do so. • You may need it for tax reasons • You may be prohibited by law or court order from destroying or de-identifying the information
  • 17. Case study – LSO Pty Ltd  Solicits PI via numerous methods: • Customers sign up for daily discounts • Customers’ social media interactions • Customer complaints • Occasional customer surveys  Also receives PI occasionally: • Misdirected mail • Promotional materials from suppliers with information identifying a salesperson, including contact information • Employment applications
  • 18. Case Study – LSO Pty Ltd Directors unclear on their legal obligations regarding collection of PI. Directors do not understand how the PI which LSO collects may be used in LSO’s business, whether LSO needs all the PI it actually collects and from where and how LSO collects PI.
  • 19. APP 5 (notification of collection) • Your identity and contact details • The fact and circumstances of collection • Whether the collection is authorised or required by law • Why you collected the PI • What happens if the PI is not collected • Your usual disclosures of collected PI • Information about your privacy policy • Whether you are likely to disclose PI overseas Before or at the time of collection, clients must notify individuals, or otherwise ensure that individuals are aware of:
  • 20. APP 6 (use and disclosure) Personal information may only be used or disclosed for the purpose of collection (‘primary purpose’) or for a secondary purpose if an exception applies: Individual consents Individual would reasonably expect our client to use or disclose his/her PI for that purpose and that purpose is related to the primary purpose Other exception applies
  • 21. APP 6 (use and disclosure) If using or disclosing personal information for a secondary purpose, must record the use or disclosure in writing: • Date of use or disclosure • Details of information used or disclosed • How the information was used • To whom was the information disclosed • The exception on which use or disclosure is based
  • 22. Case study – LSO Pty Ltd • To frame LSO’s purposes for use and disclosure, its directors should understand: • When does LSO use PI • How LSO uses PI • To whom LSO discloses PI • For example, PI could be used or disclosed for: • Order fulfilments • Marketing and promotions • Credit checks • Debt recovery
  • 23. APP 7 (direct marketing) APP 7 prohibits you from using or disclosing PI in direct marketing unless exception applies: Collection direct from individual and individual would reasonably expect their PI to be used for direct marketing Individual would not reasonably expect their PI to be used for direct marketing, but consents to the use
  • 24. APP 7 (direct marketing) • NB: fine distinction between ‘reasonable expectation’ and ‘consent’ • Whether an individual would reasonably expect depends on circumstances • Consent can be express or inferred • If permitted to use PI for direct marketing, each message must contain an ‘opt out’ provision. • APP 7 remains subject to the Do Not Call Register Act and the Spam Act.
  • 25. Case Study – LSO Pty Ltd • LSO constantly markets products to its customers. • Posts customers catalogues • Emails customers ‘daily deals’ • Tracks customers’ browsing habits and buys ad-words to trigger ads in search engines and social media sites • Whether LSO must comply with APP 7 depends on the context of the marketing.
  • 26. APP 8 (cross-border disclosures) • Regulates cross-border disclosure of PI. • Two choices for compliance: • APP 8.1 - before disclosure, take reasonable steps to ensure overseas recipient does not breach the APPs. • Contract with recipient • APP 8.2 allows compliance in a variety of ways: • Reasonable belief about overseas laws • Individual consents to disclosure • Disclosure is required or authorised by law
  • 27. Case Study – LSO Pty Ltd • LSO uses a multinational cloud provider to host its critical business systems. • Cloud provider hosts information about LSO’s customers, including their PI. • LSO agrees to cloud provider’s terms.
  • 28. APP 9 (government identifiers) • Prohibits an organisation from adopting, using or disclosing a government related identifier (except ABNs). • An ‘identifier’ is a number, letter or symbol (or combination) that is used to identify an individual or verify that individual’s identity. • A ‘government related identifier’ is an identifier assigned by any government agency.
  • 29. APP 10 (qualify of personal information) When holding PI, you must take reasonable steps to ensure: • the PI collected is accurate, up-to-date and complete. • the PI used and disclosed is, having regard to the purpose of use or disclosure, accurate, up-to-date, complete and relevant.
  • 30. APP 10 (quality of personal information) ‘Reasonable steps’ depend on the circumstances, including: • The nature of the PI • The adverse consequences for the individual if poor quality PI is collected, used or disclosed • Method or time of collection • The practicability of taking steps to ensure quality.
  • 31. APP 11 (security of personal information) • Reasonable steps to protect PI against misuse, interference and loss • Unless information is in a Cwth record or you must by law retain PI, if PI is no longer needed, must take reasonable steps to destroy PI • You should consider document destruction, tax records and other legal obligations on preservation of documents
  • 32. Case study – LSO Pty Ltd • PI of LSO’s customers becomes inadvertently public when the sales director loses an unencrypted USB drive containing latest survey results in a pub. • Privacy Commissioner investigates LSO’s alleged privacy breach. • Privacy Commissioner concludes that LSO breached APPs 1, 2, 3, 8 and 11. • LSO gives enforceable undertakings to the Privacy Commissioner.
  • 33. APP 12 (access) • If you hold PI about an individual, our client must, on the individual’s request, grant the individual access to the PI. • Access may be denied on a number of grounds, including: • Serious threat to life, health or safety • Unreasonable impact on other individuals’ privacy • Frivolous or vexatious request • Anticipated legal proceedings • Prejudice negotiations between you and the individual • Law enforcement matters
  • 34. APP 12 (access) • You must deal with access requests within a reasonable period of time • If reasonable and practicable, grant access in the manner requested • If access is refused, must give written notice setting out reasons for refusal and the mechanisms available for complaint • You can charge for access
  • 35. APP 13 (correction) • You must take reasonable steps to correct PI that is inaccurate, incomplete, etc. • Take reasonable steps to notify third parties to whom PI was previously disclosed, if requested • Reasons must be given if correction is refused • Must deal with correction requests within a reasonable period after request is made
  • 36. What should you do? THE NEW PRIVACY LAWS ARE COMPREHENSIVE
  • 37. What should you do now? Complete a privacy audit to understand what PI you collect, hold, use and disclose: Include a review of client’s privacy policy, collection statements, etc Assess what, if any, complaints resolution process the client may have If disclosing PI to third parties, review the basis on which disclosure is made The audit’s outcome should help prepare you for the new privacy laws
  • 38. What should you ASAP? Don’t dawdle – the new laws are already in effect! Design and implement a privacy compliance program Focus on: risk identification and management training for all staff compliance monitoring Don’t forget to update your privacy policy Review interactions with your customers
  • 39. What should you do in the future? • Apart from complying with the Privacy Act, document how you comply with the Act • If OAIC investigates, documentary proof will help your arguments • Remember – the Act is designed to protect individuals, not you • In particular, treat complaints appropriately and responsively • Generally, take no longer than 30 days to deal with a complaint
  • 40. Please Contact Craig Subocz Senior Associate (03) 9609 1646 csubocz@rk.com.au rk.com.au Questions