Cyber, Data and Privacy Law

In the wake of large-scale data breaches affecting millions of consumers nation-wide, cyber-security and privacy protection have become priorities in a tech-economy. Modern day developments including the world wide web, mobile and big data, HTTP cookies and artificial intelligence have threatened the safety of personal and sensitive information. SMEs nation-wide are facing increasing pressure from the Government, regulators and consumers to improve how they collect, use, store and disclose personal information. With the upcoming sweep to the national privacy regime, business-owners must invest in establishing iron-clad data and privacy frameworks to avoid cyber breaches and regulatory action.

2020 AUSTRALASIAN LAW AWARDS WINNER

Contact Form

  • This field is for validation purposes and should be left unchanged.

Testimonials

I would like to thank Keziah Holdsworth and the personal injury team at Chamberlains Law Firm for achieving a successful outcome on my claim.

As a young child I was placed at Stubbs Terrace Hospital in Perth for care, treatment and protection. Whilst there, my trust and innocence was violated and I was subjected to horrific abuse which significantly impacted my life forever.

The trauma of the abuse affected my personal, family and working life and the ability to achieve the things I wanted to achieve in life. I would not have been able to navigate the stress of the legal process without Keziah’s understanding, empathy and support.

Chamberlains believed in me and fought for me which resulted in a settlement that will help to set myself and my family up for the future.  I would recommend Chamberlains to anyone seeking justice for institutional child sexual abuse.

Abuse Compensation Client

Please pass on my thanks and gratitude to everyone who worked on this case for me. I appreciate all that has been done and especially that l was believed and always treated with kindness and understanding. Everyone l interacted with made a very stressful time much easier to deal with. l felt quite weak, vulnerable and fragile at the beginning of this process but as we went along l became stronger and more determined to see it through. This was due to counselling l received but mostly due to the way l was supported by all of the people involved in the legal team acting for me.

The monetary amount l will receive will be life changing for myself and my family, but speaking out and being believed by so many people means everything and l am confident l will be able finally begin to put this ugly chapter of my life behind me. Please pass this on to all involved. The work you all do is life changing for someone like me.

Injury & Compensation Client

Thank you Isabella. Really appreciated your help over this period, I learned a lot and found it very interesting. You had a very clear and professional approach throughout. Especially over the Christmas lead up.

Workplace Law Client

Many thanks to Mohamad for finalising the estate of my late brother and mother. I appreciate your professionalism, knowledge, and patience. Having lost both my mother and brother within 4 months of each other I felt overwhelmed with the legal processes that followed.

Not only did you explain and help me with the practical processes involved with selling a deceased estate; you outlined things from a layman’s perspective that made the whole process easier to understand.

I am very fortunate to have had you as my legal guide and companion navigating this legal and emotional minefield.

Estate Administration Client

I have had a hard time with an ex-employee lasting over 5 years, with the help from Antonia it was resolved within a month! I can’t express the amount of gratitude I have after this quick and efficient resolution.

Antonia went above and beyond for me along with her colleague Isabella, they both kept me in the loop every step of the way and I felt completely comfortable leaving it in their hands.

Workplace Law Client

Rufus and Jon assisted my mother in settling her claim. I want to say a big thank you to them both for all their work on settling mum’s claim. The settlement was conducted in such a calm manner and relieved a lot of mum’s anxiety, so I just wanted to pass on my appreciation for all of their support and guidance throughout this process.

Thank you Rufus and Jon for everything you have done and for achieving a great outcome for mum.

Personal Injury Client

Keziah made me feel like she was invested and concerned in my matter, going above and beyond to address issues I didn’t even know I could be helped with. The year leading up to my claim had brought me to breaking point, but Keziah motivated and inspired me to fight for my rights. Thanks to her I feel like there is some hope for justice, and that I might live my life in the future.

Personal Injury Client

Alison recently acted for me with respect to a complex personal injury matter resulting from prolonged sexual harassment within the workplace. She understood the impact of these events on my life from the outset, in some ways before I had even fully understood. Her clarity allowed me to focus on my treatment while she pursued legal action on my behalf.

I never felt judged by Alison or her team. I felt heard and cared for. She believed in me when I doubted myself and reassured me when I felt I was not strong enough to keep on fighting.

Personal Injury Client

I engaged Chamberlains Law Firm on the recommendation of my financial planner. Antonia Tahhan was professional, responsive and completed the advise on budget/ on time but more importantly provided clear legal advise and then followed this with a phone call explaining the advise. I have no hesitation recommending Chamberlains Law as your legal representatives.

Workplace Law Client

There are not enough stars for me to rate Jasmin Mantoufeh and Chamberlains Law Firm! Jasmin went above and beyond for me and I am so grateful to have her in my corner! From our first meeting, Jasmin took carriage of my case and her personal attention to me was amazing. I will most certainly refer and if I ever need a lawyer again, Jasmin is the person I will call!

Workplace Law Client

I cannot thank you enough for your professional and empathetic approach making it as smooth and seamless as possible during the mediation. You have all dealt with my ups and downs during the process and the level of detail, care and kindness from you all is appreciated more than I can express.

Family Law Client

You have given me the chance of a fresh start that I didn’t think I’d ever have again to be honest. You literally changed my life and I’ll never be able to thank you enough. Just wanted to let you know how much I sincerely appreciate all your help and hard work.

Compensation Client

We picked the most highly specialised and talented lawyers.

At Chamberlains Law Firm, our cyber, data and privacy lawyers are well-versed in new-age technology and traversing the legal challenges that arise from disruptive technologies in the workplace.

Process - what happens next?

Logo 1

Initial case evaluation

After an initial briefing of your matter, we will provide you with a preliminary quote.

Logo 2

Consultation

We look into all aspects of your matter and suggest the most viable path for you.

Logo 3

Case management

The Chamberlains team will work tirelessly to reach the best possible outcome for you.

Services

At Chamberlains Law Firm, we provide the following services in the cyber, data and privacy space:

a) Advice on privacy, data protection, data recovery and other issues arising from cyber incidents, including data breaches;

b) Bespoke cyber security policies and procedures, including advising on internal governance processes to maximise statutory compliance;

c) Regulatory and Compliance, including notifications to the Office of the Australian Information Commissioner (OIAC) for notifiable data breaches and Freedom of Information requests;

d) Acting on complaints and enquiries arising from the Privacy Act 1988 (Cth) and the Privacy and Personal Information Protection Act 1998 (NSW);

e) Corporate Governance including boardroom accountability and Director’s duties with respect to managing cyber risks, in line with their obligations codified in the Corporations Act 2001 (Cth);

f) Preparing bespoke incident response plans and policies, including implementation of an active compliance culture;

g) Drafting tailored website terms and conditions and privacy policies for SMEs specialising in e-commerce; and

h) Navigating and providing advice on the current guidelines, regulations and legislation regarding cybersecurity, data and privacy.

Quote Icon

Antonia was incredibly helpful, I am very grateful for her help and for Chamberlains' efficiency. Thank you so much, cannot recommend you enough for the assistance you've provided.

Gregory C.

FAQ - Employers

  • What is cyber security?

    Cyber security refers to the protection of online websites and systems from external cyberattacks, such as those seen in the Optus and Medibank data hacks. It is essential that online websites and systems protect themselves from cyberattacks that target sensitive information and disrupt businesses. As a business, you can protect your online presence through tangible methods like anti-virus software, as well as intangible means including privacy policies, website terms of use and employee training.


  • What is the difference between cyber, data and privacy?

    Cyber generally refers to the cyberspace which is a term that encompasses the entirety of the digital world, including digital technology and software such as computers, websites and the “Internet of Things”. Meanwhile, data is the information that may be obtained within this cyberspace, including personal and sensitive information. It is this personal data that is protected by the current Australian Privacy regime. The right to privacy is particularly enforced in Australian law, with the OAIC considering privacy to be a “fundamental human right”, referring to the right that all humans have to control who can see or use their information and data.


  • Do I need a privacy policy?

    Yes! There are two types of privacy policies that your business needs for both internal and external use.

    Any website operating on an Australian domain requires an online privacy policy in accordance with the Privacy Act 1988 (Cth). This policy should outline how a web-users information may be collected, stored, used, disclosed and deleted. Depending on the type of data collected (e.g. banking details via online check-outs), the method of collection and industry-specific requirements, such as AHPRA privacy collection regulations.

    In the event that your business employs staff or engages contractors, you must have an internal privacy policy that addresses how employee information is collected, stored, used and disclosed. This obligation is mirrored in the Fair Work Act 2009 (Cth) with respect to ensuring that employee personnel records are up-to-date and securely stored for a certain period of time.


  • How can a lawyer assist with my online presence?

    Cyber, data and privacy law are complex and dynamic practice areas. We can assist you with curating an online presence that reflects your creative and authentic brand without exposing your business to risk of liability arising from invasion of privacy, data breaches and intellectual property infringements.


  • I have a website, are there any legal requirements I should be aware of?

    Yes, in Australia there are a number of legal documents that you will need to create and embed within your website. Whilst these requirements vary from website to website, they include documents like a privacy policy, terms and conditions, email disclaimers and cookie policies.

    Your website may also be subject to industry-specific security obligations that imposes an additional source of regulations requiring compliance. For example, Optus were subject to a variety of legislation that extended beyond the purview of the Privacy Act, including the Security of Critical Infrastructure Act 2018 (Cth) to implement cyber-security infrastructure that protects sensitive data, as well as the Telecommunications Sector Security Reforms.


  • I operate a small online business, do I need bespoke website terms and conditions?

    Yes! Your website terms and conditions should not be a copy and paste exercise. Terms and conditions of a website act as an electronic contract that legally binds the users of a website to the provisions that govern the use and access of that website.

    Your brand, ethos, product and service offering is vastly different from the website that may be inclined to “copy”. Introducing bespoke website terms and conditions that are tailored directly to your business and website will ensure that the provisions reflect your business model in a legally compliant manner, whilst minimising risk of exposure to claims.


  • I monitor my employees and their internet usage on company computer devices, is this legal?

    Yes, it is legal to monitor your employee’s computer usage and performance on computer issued devices. However, it is essential that the employee is acknowledges and actively consents to the company’s surveillance procedures.

    Chamberlains Law Firm can prepare bespoke “Computer Usage” policies to ensure that businesses can monitor an employee’s browser history, online activity, download patterns and performance to manage their productivity in the workplace.

    The Australian Privacy Principles continue to operate internally. Therefore, it is important that a business has a “Computer Usage” and “Privacy Policy” to ensure that employees can be performance and/or disciplinary managed in accordance with those policies, and that the employer is aware of the parameters to collecting, using and disclosing that data during their employment tenure.


  • I am an employee. Can I gain access to my employee record?

    The Privacy Act 1988 (Cth) treats public and private employees differently. Public sector employees are able to access their employee record and any personal information kept about them at any time.

    However, employees in the private sector do not have a specific right to access their employee record, as the handling of employee records in the private sector is exempt from the Privacy Act 1988 (Cth).  The legislative requirements of the Privacy Act 1988 (Cth) will only become binding if an employer is not using the information in the employee record for the employment relationship, such as sharing documents online.


  • What is the difference between personal data and sensitive information?

    Personal information is any piece of data or information that may be used to identify a person including a name, IP address, phone number or date of birth. In isolation, these details may not disclose the identity of an individual. However, a collection of personal information may personally identify an individual.

    Meanwhile, sensitive data is a ‘step further’ than personal data which requires more sophisticated protection. Sensitive data includes a person’s beliefs, health records, financial information, or classified records such as criminal history. Sensitive information generally includes biometric and personally identifiable data.

    Often, businesses with websites that allows users to ‘check-out’ to purchase goods collect sensitive financial information and transmit that information to third party financial institutions. In the event that your business collects bank details to facilitate transactions, it is crucial that you indemnify your business from any loss or claims that may arise in the event that any third party that receives that information (i.e. financial institution) discloses that data. Your website terms of use and contract for services should address this.


  • What is a data breach?

    A data breach is when personal or sensitive information is accessed and disclosed to another party without the authorisation of a party involved. This could occur on a large scale, such as the Optus and Medibank data hacks, or a much smaller scale, such as a stolen or lost USB, or an email sent to the wrong person.


  • What is the OAIC?

    The OAIC is the Federal Government’s independent national independent regulator for privacy and freedom of information. Therefore, they are the governing body that handle any privacy complaints and data breaches. The OAIC has the authority to order compensation for financial or non-financial loss in order to remedy any breaches of the Privacy Act 1988 (Cth).


  • I received a complaint from OAIC, what do I need to do?

    Should you receive a complaint from OAIC, you should consult our team. We have the knowledge and resources to handle complaints in this jurisdiction and defend complaints to avoid the imposition of severe financial penalties or further judicial action. Here at Chamberlains Law Firm, you can book in for a free 15-minute consultation with one of our highly skilled lawyers and they will be able to guide you through the next steps of your complaint.


  • What are the new powers of the OAIC?

    Amidst the changes to Australian privacy laws following the Optus and Medibank data breaches, the powers of the OAIC have increased, including gaining the ability to request all information about a data breach and impose regulatory action (including financial penalties) depending on its findings.


  • Can I receive a fine for breaches of the Privacy Act 1998 (Cth)?

    You sure can, and it will not be cheap! Following the Optus and Medibank data breaches, the Australian Federal Parliament introduced the Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022. This increased the maximum penalty to whichever is the greater of:

    • $50 million;
    • three times the value of any benefit obtained through the misuse of information; or
    • 30 per cent of a company’s adjusted turnover in the relevant period

    Therefore, it is essential to seek legal advice and ensure that your website and cyber activities are compliant with Australian legislation to avoid these substantial fines.


  • What do I need to know about the Privacy Act Reforms?

    Workplace Health and Safety laws, regulations and codes of practice were modelled by SafeWork Australia in 2011 for other states and territories to adopt. The underlying principle of the model WHS Act is that, so far as is reasonably practicable, duty holders provide workers with the highest level of health and safety.

    This means that a person conducting and undertaking a business, as the duty holder, is required to do whatever is reasonably able to be done at the time to ensure the health and safety of their workers. Employers have notification requirements for notifiable incidents. Notifiable incidents are ones that involve death, serious injury or serious illness to a worker or a dangerous incident that exposes workers to a serious risk.

    Under WHS Laws, a person conducting or undertaking a business must report a notifiable incident to WorkSafe by the fastest possible means and keep a record of all notifiable incidents for at least five years. Failure to notify SafeWork of the occurrence of a notifiable incident, keep a record of a notifiable incident or preserve an incident site until an inspector arrives carries large penalties.

    Businesses also have to have workers compensation from an insurer to ensure that compensation can be paid to an employee injured at work. If an employee is injured at work, the employer needs to notify the insurance company and complete all relevant documentation.