top of page
Search

How Has the Privacy Act Responded to Breaches of Critical Infrastructure Data at the Public and Private Level?

  • Writer: Policy Research Program
    Policy Research Program
  • Jun 27
  • 24 min read

Authors: Elizabeth Thomas, Sharan Sidhu, Keona Rangwala and Helena Bradshaw


EXECUTIVE SUMMARY


This policy proposal is the research product of the inaugural Protocol Policy Lab’s Policy Research Program. The Program is a semester-long extracurricular program that provides young Australians the opportunity to conduct in-depth research on a current issue in Australian technology policy. 


The thesis topic of this Submission explores how the Privacy Act has responded to breaches of critical infrastructure data at the public and private level in Australia. The Submission will respond to the thesis question by first, outlining the current scope and landscape of the research parameters, the relevant legislative and data protection frameworks and issues surrounding the management of critical infrastructure sector data breaches. Followed by providing case studies of recent breaches of data held within the critical infrastructure sector, which were analysed and evaluated through the lens of the key issues identified in relation to the current legislative frameworks. Finally, the submission outlines potential recommendations and discussions on future implications to encourage the implementation of stronger data protection measures and frameworks relating to the critical infrastructure sector in Australia. 


Based on our research, we developed two key recommendations:


  1. Strengthening the current Notifiable Data Breaches Scheme (the NDB Scheme) through establishing a clearer and objective risk threshold and severity mapping; and


  1. Strengthening the current “reasonable steps” requirement for cybersecurity and data privacy management under the Privacy Act through articulating clearer and enforceable standards.



INTRODUCTION


Public and private sector entities hold vast amounts of personal information as part of their critical infrastructure operations. The expansion of digital service delivery has increased the scale and consequences of privacy risks and data breaches. Consequently, the management of data privacy and protective infrastructures have become a key point of discussion for the Australian Government, particularly in the interests of national security and the protection of the Australian critical infrastructure sector. Within the public sector, individuals often have limited choice in allowing public sector organisations to collect and store their information, whereas the private sector exists within a separate range of access to data and related sensitive materials. However, both of these sectors share a common point when their operations exist within the critical infrastructure sector, such as healthcare, education or national defence. 

 

Recent data breaches and the findings of Auditor-General Report No. 12 of 2025–26 have exposed vulnerabilities in the capacity of some entities to protect personal information.1  In critical infrastructure sectors such as health, education and social services, the information held may include identification details, financial records, employment history and health data. This submission focuses on the following case studies: the recent audit of Services Australia and data breaches at the Australian National University, MediSecure and Medibank. These incidents suggest a gap between current privacy obligations under the Privacy Act 1988 and the operational capacity of public and private sector entities to identify, assess and respond to breaches.2

 

The significance of these risks is illustrated by Services Australia, which manages personal information for approximately 27.5 million Australians across Medicare, Centrelink and child support programs. Auditor-General Report No. 12 of 2025–26 found Services Australia only partly effective in managing client privacy, identifying compliance deficiencies across risk management, data matching, record-keeping and transparency. The report recorded 6,042 substantiated privacy incidents between 2022–23 and 2024–25.3



SCOPE AND LANDSCAPE OF RESEARCH


This Submission focuses on evaluating Australia’s current frameworks for identifying and managing privacy risks, with specific emphasis on compliance pursuant to the current Privacy Act 1988 (Cth), herein referred to as the Privacy Act. The scope of the submission will be limited to the Commonwealth level and will examine the current statutory mechanisms, regulatory guidance and enforcement practices which are applicable to both public and private sectors operating within the critical infrastructure space. The submission will not extend its analysis and comments to state or territory-specific privacy laws for the purpose of this submission’s parameters. 


This submission will encompass identification and analysis of the relationship between core privacy instruments and critical infrastructure protections available, particularly the Privacy Act. The current Privacy Act and its protective frameworks mandates the handling of personal information through the Australian Privacy Principles (APPs)4 and empowers the Office of the Australian Information Commissioner (OAIC)5 to investigate breaches and issue enforcement outcomes. There are sector-specific overlays which work alongside the primary privacy framework, including the Notifiable Data Breaches Scheme (NDBS) pursuant to Part IIIC of the Privacy Act.6 The NDBS requires mandatory reporting of eligible data breaches affecting 500 or more individuals, with certain threshold exceptions dependent on the severity of the breach.7 


The Privacy Act applies across both the public and private sectors, but does not regulate all entities. Public sector entities covered by the Act include Commonwealth Government agencies and statutory authorities under section 6(1),8 including Commonwealth universities such as the ANU. State and territory government bodies and public schools and universities are generally excluded.9 Within the private sector, prior to the 2024 Privacy Act reforms, the Privacy Act only covered organisations with an annual turnover exceeding $3 million and certain smaller organisations including private health service providers and contracted service providers.10


When it comes to critical infrastructure which spans sectors including but not limited to energy, transport, and communication, this analysis will limit its scope to observing critical infrastructure data breaches consisting of healthcare, government and educational data. As such, this submission will also make consideration of the Security of Critical Infrastructure Act 2018 (SOCI Act) alongside its 2021 amendments to bridge the gaps and highlight the relationship between the SOCI and Privacy Act in responding to and managing data breaches.11 


Within the public sector, frameworks emphasise accountability pursuant to the APPs alongside the Freedom of Information Act obligations, with breach responses being coordinated through OAIC oversight. Meanwhile, the private sector designates heightened scrutiny to “high-risk” entities handling sensitive data, whereby the SOCI Act reporting requirements intersects with NDBS notifications to mitigate the waterfall effects of privacy harms from cyber incidents. This Submission aims to identify and analyse key issues and findings relating to the current Australian privacy and data protection frameworks and provide relevant recommendations and comment on the future implications relating to any gaps in harmonisation of the primacy source doctrine of the Privacy Act.



LEGISLATIVE FRAMEWORKS


The handling of personal information by both the public and private sector entities are governed primarily by the Privacy Act. The broader legal framework also includes the Australian Privacy Principles (the APPs), the NDB Scheme and the Privacy (Australian Government Agencies — Governance) APP Code 2017 (the APP Code). Entities operating in critical infrastructure sectors have additional security and resilience obligations under the Security of Critical Infrastructure Act 2018 (Cth) (the SOCI Act)).

 


1: PRIVACY ACT 1988 (CTH)

 

The Privacy Act contains 13 APPs which establish standards, rights and obligations for the collection, use, storage, disclosure, and access of personal information.12 The most relevant principles for this Submission are: APP 3, which regulates the collection of personal information; APP 5, which requires notification of collection; APP 6, which governs use and disclosure; and APP 11, which concerns the security of personal information.13

 

APP 11 is particularly significant in the data breach context. It requires an APP entity that holds personal information to take reasonable steps to protect that information from misuse, interference and loss, and from unauthorised access, modification or disclosure.14 The Privacy and Other Legislation Amendment Act 2024 clarified that “reasonable steps” now explicitly encompasses both technical and organisational measures.15

 

The Office of the Australian Information Commissioner (the OAIC) is the national privacy regulator and is responsible for privacy guidance, complaint handling, investigations and enforcement under the Privacy Act.16

 


2: NOTIFIABLE DATA BREACHES SCHEME


The NDB Scheme is established under Part IIIC of the Privacy Act.17 It requires regulated entities to notify the OAIC and affected individuals where there are reasonable grounds to believe an eligible data breach has occurred. An eligible data breach involves unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm.18 Where an entity merely suspects an eligible data breach, section 26WH requires it to conduct a reasonable and expeditious assessment and take all reasonable steps to complete that assessment within 30 days.19

 


3: PRIVACY (AUSTRALIAN GOVERNMENT AGENCIES — GOVERNANCE) APP CODE 2017

 

The APP Code is established under section 26G of the Privacy Act.20 Its objectives are to enhance the privacy capability and accountability of agencies, promote good privacy governance, and build community trust and confidence in personal information handling practices.21

 

The Code imposes additional governance obligations on Australian government agencies. Agencies must maintain a privacy management plan and measure and document performance at least annually.22 A Privacy Officer must be designated to handle privacy enquiries, complaints and conduct privacy management plan reviews.23 Agencies must also conduct privacy impact assessments (PIAs) for all high privacy risk projects and maintain a publicly accessible register of those assessments.24

 


4: SECURITY OF CRITICAL INFRASTRUCTURE ACT 2018 (CTH)


Acting alongside the Privacy Act, the SOCI Act aims to provide a framework for managing risks relating to critical infrastructure.25 Its statutory objectives include improving transparency over ownership and operational control, requiring responsible entities to identify and manage risks to critical infrastructure assets, imposing enhanced cyber security obligations, and enabling Commonwealth responses to serious incidents.26 The Act applies across eleven critical infrastructure sectors, including data storage and processing, higher education and health care.27

 

The SOCI Act imposes operational and cyber security obligations on responsible entities. Sections 30AC to AG include the requirement to adopt, maintain and comply with a critical infrastructure risk management program, subject to regular review, update and annual reporting.28 The Act also imposes mandatory cyber incident reporting obligations. Section 30BC requires critical cyber security incidents to be reported to the relevant Commonwealth body within 12 hours of awareness, and section 30BD requires other cyber security incidents reported within 72 hours of awareness.29 



5: COMPENSATION AND INDIVIDUAL REDRESS

 

Section 52 of the Privacy Act gives the OAIC power to investigate complaints and make determinations.30 Under section 52(1)(b)(iii), following investigation of a complaint, the Commissioner may declare that a complainant is entitled to a specified amount by way of compensation for loss or damage suffered.31 Section 52(1AB) clarifies “loss or damage” is not limited to direct financial loss and expressly includes injury to feelings and humiliation.32 The OAIC may also require the respondent to take specified steps to ensure conduct is not repeated or continued,33 and reimburse the complainant for expenses reasonably incurred by the complainant in connection with the complaint and investigation.34

 

The Privacy Amendments Act introduced a statutory tort for serious invasions of privacy, which commenced on 10 June 2025.35 This provides individuals with an additional avenue to seek redress in court, separate from the OAIC complaint process. Under Schedule 2, clause 7(2) of the Privacy Act, the tort is actionable without proof of damage.36 The plaintiff must show that the invasion of privacy was intentional or reckless,37  serious,38 and that the public interest in privacy outweighed any countervailing public interest.39 A primary purpose of introducing the statutory tort is to balance the right to privacy against competing public interests, including freedom of expression.40 Further, Schedule 2 includes exemptions for agencies and State or Territory authorities acting in good faith in the performance of their functions, as well as broader exemptions for law enforcement and intelligence bodies.41 



KEY ISSUES IN PUBLIC SECTOR DATA MANAGEMENT



LEGISLATIVE GAPS AND MISALIGNMENT IN PRACTICE IN THE PUBLIC SECTOR


The management of critical infrastructure data in the public sector faces several challenges due to a misalignment between regulatory frameworks provided by current legislation, and the capacity of Commonwealth agencies in managing the risks associated with vast critical datasets. 


CONFLICTING REQUIREMENTS UNDER LEGISLATIVE FRAMEWORKS

Notably, Commonwealth service delivery for social services, education and healthcare is defaulting to a primarily digital model, with a goal of reaching complete online flexibility by 2030.42 


Nonetheless, current legislative frameworks may not be able to support such a model and corresponding expansion. Conflicting requirements imposed by the Privacy Act, its subsidiary schemes and the SOCI Act result in a regulatory environment which struggles to ensure that agencies are well-equipped to safeguard the information collected from critical services.43 A single cyber incident involving personal information held in, or connected to, a critical infrastructure asset may trigger obligations under both the SOCI Act and the NDB Scheme simultaneously. This makes government agencies’ compliance with legal obligations complex because the regimes create different thresholds, reporting pathways and policy objectives. 


As mentioned above, the SOCI Act has a cyber incident reporting regime to ensure that the Commonwealth has timely visibility of cyber incidents affecting critical infrastructure so that the government can assess national security risks. Thus, the SOCI Act reporting mechanism is directed primarily to government visibility and critical infrastructure resilience as opposed to public disclosure to affected individuals. Section 22 of the SOCI Act expressly states the Register of Critical Infrastructure Assets is non-public.44 The Register of Critical Infrastructure Assets contains information about who controls and has access to critical infrastructure, used to help the government manage and assess risks to national security.45 Compliance with SOCI Act reporting may therefore not satisfy an entity’s separate Privacy Act notification obligations, which require entities to notify the OAIC and affected individuals where there are reasonable grounds to believe a data breach has occurred.46


LACK OF ENFORCEABLE DEADLINES FOR RESPONDING TO DATA BREACHES

The regulations outlined by the Privacy Act do not provide a legally enforceable deadline for responding to a data breach. This is evident in both the ‘serious harm’ threshold for identifying an eligible data breach, and the stipulation of practicability when notifying affected individuals.47 Neither phrase is defined in the Act or any subsequent legislative instruments, and so a report is dependent on the individual interest of an organisation, as opposed to the wider public interest.48 In the public sector, this may be compromised or inhibited by political, reputational, or other arbitrary individual justifications. This subjective test is at odds with the 12 hour reporting window posited by the SOCI Act, which sets a legal requirement for the reporting of cyber security incidents to the Australian Signals Directorate’s Australian Cyber Security Centre.49 


The statutory assessment window imposed by the NDB Scheme posits a window of up to 30 days to conduct a ‘reasonable and expeditious’ assessment of a suspected breach.50 Permitting public sector organisations to conduct investigations of suspected or occurring data breaches in an extensive window may increase the risk of harm as delays in identifying, assessing and notifying breaches can reduce the ability of affected individuals to take remedial steps.51 Simultaneously occurring data breaches may remain undetected for a prolonged period, developing to an extent which is difficult to control whilst compromising further data.52 Additionally, already compromised data may be used to facilitate financial fraud or identity theft before individuals are made aware of the incident, developing beyond the control of the regulatory framework.53 


LIMITED PROTECTION PROVIDED BY PRIVACY ACT

The Privacy Act has narrow application, potentially inhibiting its ability to protect substantial datasets. The Act, which applies to protect the ‘personal information’ of individuals, defines this phrase as ‘information or an opinion about an identified individual, or an individual who is reasonably identifiable’.54 This fails to encompass multifaceted data often found in critical infrastructure including metadata which falls outside the statutory definitions of ‘personal’ and ‘sensitive’ information.55 Whilst this data can be de-identified, a risk of re-identification through ‘jigsaw identification’ exists, where anonymised data can be cross referenced and combined from both public and private sources to identify specific individuals.56 Moreover, consideration is absent in the Privacy Act as to the relationships between government entities and third party providers, where third parties are not held to the same reporting obligations as public organisations, regardless of their mutual management of public data.57 As such, the Privacy Act does not address the risks associated with modern, multifaceted datasets. 


CASE STUDIES

1: Organisational Discrepancies at Services Australia


The Auditor-General Report concerning Service Australia’s management of privacy found several instances where current legal frameworks were not sufficient for the protection of critical infrastructure data, or where the agency did not fulfill its obligations.


The Report found that the agency set internal deadlines for reporting data breaches, of within 3 business days to the OAIC and 10 business days for affected individuals following a breach assessment.58 This is beyond the regulations of the Privacy Act, and theoretically mitigates risks of subjective action. However, the agency frequently failed to meet these targets; 71% of NDBs between 2018-19 and 2024-25 were reported to the OAIC ‘50 or more days after Services Australia became aware of the incident’.59 


Secondly, the Report found that the agency failed to process 72% of its confirmed NDBs within the required 30-day period, between 2019 and 2025.60 Whilst the agency justified its inability to meet internal reporting targets due to its undertaking of complex assessments that aim to support vulnerable customers, a failure to complete such assessments in the 30-day period heightens risks for individuals.61 This is demonstrated by an increase from 7 maliciously motivated NDBs in the 2022-23 period to 82 in the 2024-25 period.62


Thirdly, the Report discusses the need for entity compliance to effectively enact the existing data management framework. The Report found that Services Australia failed to fulfil its PIA obligations as per the APP Code, failed to complete preliminary privacy threshold assessments, was delayed in adding PIAs to the public register and made several overall record keeping discrepancies.63 The effectiveness of the APP code and the wider Privacy Act to reduce critical infrastructure data breaches is hence partially dependent on the receptiveness of an organisation, and their engagement with a proactive privacy regulatory framework.


Finally, the Report found that legislative gaps in the Privacy Act inhibit Services Australia's abilities to protect critical infrastructure data. The Report makes reference to the organisation’s ‘Third Party Compromise Plan’, which, whilst a response to data leaks involving public infrastructure, carries no ‘legislated authority’ to compel a private party to disclose a data breach where critical infrastructure data has been compromised.64 Reliance on media, affected individuals and delayed advice from other Commonwealth agencies inhibits an organisation's ability to respond promptly to developing data breaches, for an indefinite period.65 


2: Attacks on Modern, Complex Data Sets at the Australian National University 


The issues observed in Services Australia’s data management practices are not isolated to service delivery, and occur across several areas of critical infrastructure data. The Incidental Report on the Breach of the Australian National University’s Administrative Systems (the ANU Report) illustrates the limitations of legislative frameworks in proactively preventing significant data breaches through its discussion of the 2019 Australian National University cyber attack.66 ANU acted swiftly in the aftermath of the attack in contrast to the resistance demonstrated by Services Australia in fulfilling its obligations under the Privacy Act. However, this case study remains a crucial example of the risks posed by current legal frameworks to individual data privacy.


Firstly, the Privacy Act’s scope of individual privacy protections is centered around ‘personal’ and ‘sensitive’ information.67 The ANU Report draws attention to the process by which ANU’s administrative data was breached. The ‘Enterprise Systems Domain’ (‘ESD’) network was covertly targeted, a database consisting of ‘human resources, financial management, student administration and enterprise e-forms systems’.68 Using third party, commercial tools to extract combined records from this multifaceted database, the perpetrator acquired the requisite data necessary to engage in a strategy of ‘jigsaw identification’, which the Act’s narrow definition of ‘personal information’ may fail to encompass.69 The Act's definitions of information are difficult to apply to the multilayered databases of modern organisations, which, as observed at the ANU, consist of the data of individuals across several areas.70 This scattered data is then vulnerable as a unit, risking the privacy of individuals. 


Secondly, the functional risks posed by a substantial statutory assessment window are illustrated by the persistent, volatile threat environment observed during the ANU cyber attack. As opposed to the 30 days stipulated in the NDB Scheme, the ANU report outlines the relative immediacy of the organisation's public disclosure of the attack, which occurred  after two weeks.71 The ANU report also highlights continuous malicious attempts to regain access to the compromised ESD, followed by an almost immediate secondary attack following public disclosure.72 Resultingly, the NDB Scheme’s 30 day assessment period poses a significant risk to critical public infrastructure data. By allowing at-risk organisations to delay discovery and intervention, vulnerable networks are exposed to ongoing exploitation and secondary attacks.


Finally, the subjective nature of the Privacy Act’s ‘serious harm’ threshold, alongside the organisational cooperation required to enforce pre-existing frameworks illustrates the tension between public transparency and individual interests.73 The Act’s reliance on undefined, subjective thresholds of ‘serious harm’ and practicability results in a lack of incentive for organisations to engage in transparency when publicising data breaches.74 This tension is highlighted by the contrast between ANU’s proactive response to its cyberattack, and Service Australia’s lack of engagement with regulatory frameworks.75 Notably, the ANU Report states that the report was “the first of its kind in Australia following a cyber attack on a public institution”, with the purpose of "encourag[ing] disclosure of these attacks more broadly".76 ANU’s voluntary report indicates that a stronger, legally robust framework may normalise transparency and disclosure, as opposed to the current reliance upon individual organisational structure.



WEAK LEGISLATIVE FRAMEWORKS IN THE PRIVATE SECTOR


Data breaches in the private sector, whilst often as impactful and devastating as their public sector counterparts, must be assessed separately. This is due to a distinction in the relevant legislative frameworks. Although the private sector shares much of the same regulatory framework as its public sector counterparts, the exclusionary scope of the APP code77 means that there are limited structured governance requirements for corporations. The APPs, as stipulated by the Privacy Act, whilst inclusive of the private sector, are vastly broader and principles-based, in opposition to the specific requirements of the APP code. 


With respect to breaches of data, APP 11 in particular governs the protection of sensitive information, providing that an entity must take “reasonable steps” to protect personal information against misuse or unauthorised access.78 Although the scope of these “reasonable steps” has been somewhat clarified in s 34 of the Privacy and Other Legislation Amendment Act, as requiring “technical and organisational measures”, this is nonetheless principles-based, and fails to provide a concrete framework. Such subjectivity leaves alignment to the APPs beholden to individual corporate interests, failing to prioritise the protection of critical infrastructure data.


CASE STUDY: Compromising Critical Infrastructure Data through the MediSecure Data Breach

A significant gap in the legislative framework governing private entities is the lack of accountability for these institutions in event of data breaches or mismanagement. The MediSecure data breach, its aftermath and its management by the OAIC serves as an illustration of the implications of such conduct for customers. MediSecure, one of two significant electronic prescription delivery services under contract by the Australian Government, experienced a ransomware attack from an unidentified third party actor.79 This data was inclusive of personal identifiers, including “full names, phone numbers, dates of birth, home addresses, Medicare numbers, and Medicare card expiry dates”.80 


The immediate aftermath of the breach exposed the significant limitations of holding private entities accountable for breaches of critical infrastructure data in the current legislative environment. Regardless of extensive scale of data exposure,  compromising the data of 12.9 million individuals,81 MediSecure's entering into administration82 resulted in a lack of remedies available for impacted individuals; as the company ceased to exist, there was no viable avenue for those affected by the breach to be notified, or compensated.83 Concurrently, the OAIC chose not to pursue an investigation into the background or causes of the data breach, finding that any remaining avenues for redress would not be “proportionate” to the resources expended in an investigation.84


This financial collapse and subsequent dissolution of investigation or remedies highlights a critical vulnerability in the current legislative framework; although private entities are beholden to governance requirements under the Privacy Act and the Privacy Amendments Act, the largely principles based framework for private corporations creates a weak regulatory environment. Theoretically, accountability for the violation of the APPs can only be retrospective, as the current legislative environment requires corporations to manage compliance internally; violations of the principles would only be investigated by external entities after the fact. The aftermath of the MediSecure breach complicates such a process; the collapse of a private entity eliminates any possibility for investigation and enforcement of the principles. As a result, there is a lack of accountability and opportunity for redress for impacted individuals, and a lack of transparency regarding the extent of the data breach and its causes. A lack of adequate investigation into a data breach restricts the opportunity to develop the appropriate legislative and governance frameworks to mitigate future incidents.



LEGISLATIVE INCONSISTENCIES AND THE MEDIBANK DATA BREACH


CASE STUDY: Legislative Inconsistencies and the Medibank Data Breach

Despite the limitations in holding private sector entities to account as a result of gaps in the legislative framework, the cases in which they are held accountable demonstrates inconsistencies in their overall application. Similarly to breaches in the public sector, the Medibank data breach is an example of organisational negligence yet also highlights the uneven application of legislative frameworks, limiting the capacity to anticipate and respond to breaches of critical infrastructure data. 


Medibank is a health insurance provider that centrally involves the collection and holding of customers’ personal and sensitive health information, where the 2022 Medibank data breach occurred when a contracted employee of a third-party IT provider saved their credentials to their work computer connected to their personal device, which were stolen by malware. Subsequently, the threat actor extracted and published 350GB of data, including names, addresses, dates of birth and Medicare card numbers, exposing the information of 9.7 million current and former customers.85 


Whilst private organisations must take “reasonable steps” to prevent the loss and misuse of personal information, the Medibank data breach further demonstrates limitations in preventing organisational negligence. At the time of the Medibank data breach, Medibank’s private network did not necessitate multi-factor identification (MFA), requiring a username and a password,86 despite an internal audit completed by KPMG in 2020 that identified that “MFA had not been enabled” and described this as a “critical” defect.87 Furthermore, there was a significant delay in Medibank’s response to the breach. The company’s endpoint detection and response security software generated alerts to its internal IT Security Operations email inbox around 24–25 August 2022. The threat actor accessed and extracted data during 25 August–13 October 2022, and was not escalated by Medibank until 11 October 2022. Around 16 October 2022, the third party engaged by Medibank confirmed “suspicious volumes of data” had been extracted by the threat actor, which was later published on the dark web around 9 November-1 December 2022.88  The lack of appropriate technical measures demonstrates Medibank’s systematic failure, furthering the ineffectiveness of the “reasonable steps” in ensuring that organisations proactively prioritise and implement the robust protection of the personal information they hold. 


However, unlike the MediSecure data breach, the Medibank data breach is a case in which a private organisation was held to account by the legislative framework. In 2024, the OAIC alleged that from March 2021 to October 2022, Medibank interfered with the privacy of 9.7 million Australians by failing to take the reasonable steps to protect their personal information from misuse and unauthorised access as a breach of the Privacy Act.89 The Australian Information Commissioner considered that Medibank did not take the reasonable steps given its size, resources and the volume and sensitivity of the personal information it held,90 imposing a significant risk upon its customers as a result of their inaction in substantively implementing protective measures and responding to technical advice. Given that Medibank still held the data, the Federal Court may impose a civil penalty of up to $2,220,000 for each contravention of section 13G of the Privacy Act.91 Nevertheless, whilst Medibank was held to account, the lack of accountability in the MediSecure data breach demonstrates the inconsistent application of the Privacy Act across cases and an ongoing lack of assurance that the “reasonable steps” requirement guarantees that the prevention of the loss or misuse of data supersedes corporate interests. 



FUTURE IMPLICATIONS AND MITIGATION


This Submission’s examination of Australia’s data privacy and protection frameworks comes in light of multitudes of high profile data privacy breaches, particularly relating to the critical infrastructure sector. The most recent Canvas data breach affected countless educational institutions worldwide, with millions of students, teachers and staff being negatively impacted, all of which continue to underscore the persistent and evolving nature of cyber threats and growing public concern around how personal data is handled. The stakes are particularly high where critical infrastructure is involved, with individuals often unable to opt out of sharing sensitive and personally identifying information when accessing the essential services of healthcare, education and government services. All of which, moving forward, underlines the dire need for strengthening the safeguards and frameworks which respond to bridging the gaps identified within the current data privacy and protection frameworks in Australia. As the 2024 Privacy Act reforms come into effect over 2025 and 2026, there are a few points of recommendations that this Submission puts forward. 



1: STRENGTHENING THE CURRENT NDB SCHEME THROUGH ESTABLISHING A CLEARER, OBJECTIVE RISK THRESHOLD AND SEVERITY MAPPING


Policymakers may strengthen and clarify the current NDB Scheme through the introduction of a more objective and tiered harm threshold for organisations to refer to and be obligated to assess data breaches and security incidents against. The current “likely to result in serious harm” test lacks definitional clarity and requires subjective assessment from organisations in determining the reporting responsibilities pursuant to the Privacy Act.92 Establishing a criteria which refers to predefined risk categories and mandatory reporting requirements for certain types of incidents (such as ransomware attacks or breaches involving critical infrastructure systems) regardless of severity at the first instance would improve consistency, timeliness and regulatory oversight. 



2: STRENGTHENING THE CURRENT 'REASONABLE STEPS' REQUIREMENT FOR CYBERSECURITY AND DATA PRIVACY MANAGEMENT UNDER THE PRIVACY ACT THROUGH ARTICULATING CLEARER, ENFORCEABLE STANDARDS


Embedding clearer and enforceable standards within the current “reasonable steps” may place greater emphasis on proactive cybersecurity obligations through the requirement. This could include mandating baseline security controls such as encryption, multi-factor authentication, and continuous monitoring and requiring organisations to demonstrate real-time visibility over data flows.93 In aligning these requirements with existing data privacy frameworks like the SOCI Act, the overall compliance complexity would be reduced, creating a more unified response mechanism to cyber threats under the Privacy Act



CONCLUSION


This Submission has evaluated the efficacy of current frameworks and legislation in adequately identifying and managing privacy risks at the Commonwealth level to meet the requirements of the Privacy Act. This Submission has found limitations in the Privacy Act that inhibit the ability to effectively respond to data breaches and secure the highly sensitive information of the Australian public in a rapidly changing and evolving digital landscape. 


The current legislative framework includes the amalgamation of the Privacy Act, supported by the Australian Privacy Principles, the Notifiable Data Breaches scheme and the Privacy (Australian Government Agencies — Governance) APP Code, alongside the Security of Critical Infrastructure Act, involving additional obligations for entities in critical infrastructure sectors. However, key issues in the management of critical infrastructure data have been identified, highlighting prominent gaps between the current legislation and private and public sector entities’ capacities to identify, rectify and assess critical infrastructure related data breaches. 


The case study on the recent audit of Services Australia highlighted their limitations in reporting data breaches in a timely manner due to internal resource constraints and the Privacy Act’s omission of critical infrastructure data, demonstrating challenges in ensuring organisational receptiveness to legislative frameworks. Moreover, the case study on the recent data breach at the Australian National University presents the gaps in the current legislation in preventing data breaches in light of the changing requirements of a contemporary digital landscape. This is evident in the narrowness of the Privacy Act’s scope despite increasingly complex data sets, the imposed delays to discovery and hence intervention, and the subjectivity of harm thresholds, undermining the ability to effectively mitigate the risk of data breaches. 


Therefore, this Submission recommends the strengthening of the objectivity of risk thresholds under the current NDB Scheme to improve the timeliness and robustness of regulatory oversight. Secondly, further emphasis on strengthening the standards for security control under the ‘reasonable steps’ requirement of the Privacy Act to improve and unify the capacity to comply. Such measures, designed to minimise the gaps between the current legislation and their objectives to meet the requirements of the Privacy Act amidst rapid technological transformation, may reduce the occurrence and risks of data breaches and their privacy implications for Australian individuals. This would preserve the social licence and security of public and private sector entities operating within the critical infrastructure space, whilst allowing for the use of public and private data for its intended purpose in servicing the public good and other wide range of interests.



REFERENCES


 1. Australian National Audit Office, Managing the Privacy of Client Information in Services Australia, Auditor-General Report No 12 of 2025–26 (ANAO, 2026) ('ANAO Report No 12').


 2. Privacy Act 1988 (Cth) ‘Privacy Act’. 


3. ANAO Report No 12 (n 1).



4. Privacy Act (n 2) sch 1. 


5. Ibid s 40. 


6. Ibid pt IIIC. 


7. Ibid


8. Privacy Act (n 2) s 6(1).


9. Office of the Australian Information Commissioner, State and Territory Privacy Legislation (Webpage, 20 May 2026) https://www.oaic.gov.au/privacy/privacy-legislation/state-and-territory-privacy-legislation.


10.  Privacy Act (n 2) s 6D.


11. Security of Critical Infrastructure Act 2018 (Cth) ‘SOCI Act’. 


12.  Privacy Act (n 2) sch 1.


13. Ibid APPs 3, 5, 6, 11.


14. Privacy Act (n 2) cl 11.2.


15.  Privacy and Other Legislation Amendment Act 2024 (Cth) sch 1 (‘Privacy Amendments Act’).


16.  Privacy Act (n 2) s 27.


17.  Ibid s 26WA–26WR.


18.  Ibid s 26WE.


19.  Ibid s 26WH.


 20. Privacy Act (n 2) s 26G; Office of Australian Information Commissioner, Privacy (Australian Government Agencies – Governance) APP Code 2017 (OAIC, 2017) (‘APP Governance Code’).


21.  OAIC, APP Governance Code (n 20) s 4.


22. Ibid s 9.


23. Ibid s 10.


24. Ibid s 14.


25. SOCI Act (n 11) s 3.


26. SOCI Act (n 11).


27. Ibid s 9, sch 2.


28. Ibid ss 30AC–30AG.


29. Ibid ss 30BC–30BD.


30. Privacy Act (n 2) s 52.


31. Privacy Act (n 2) s 52(1)(b)(iii).


32. Ibid s 52(1AB).


33. Ibid s 52(1)(b)(ia).


34. Ibid s 52(3). 


35. Privacy Amendments Act (n 15) sch 2.


36. Privacy Act (n 2) sch 2, cl 7(2).


37. Ibid sch 2, cl 5(1)(c).


38. Ibid sch 2, cl 5(1)(d).


39. Ibid sch 2, cl 5(2).


40. Privacy and Other Legislation Amendment Bill 2024 (Cth), Explanatory Memorandum 57.


41. Privacy Act (n 2) sch 2, cls 16, 16A, 16B, 17.


42. Department of the Prime Minister and Cabinet (Cth), Australian Data Strategy: The Australian Government's Whole-of-Economy Vision for Data (Report, 2021) 32 <https://www.finance.gov.au/sites/default/files/2022-10/australian-data-strategy.pdf>.


43. SOCI Act (n 11).


44. Ibid s 22.


45. Cyber and Infrastructure Security Centre, Registering a Critical Infrastructure Asset (Guidance, November 2025) 4 https://www.cisc.gov.au/resources-subsite/Documents/register-critical-infrastructure-assets.pdf


46. Privacy Act (n 2) s 26WA–26WR.


47. Ibid s 26WL.


48. Julian Fell, Georgina Piper and Matt Liddy, ‘This is the most detailed portrait yet of data breaches in Australia’, ABC News (online, 23 March 2023) <https://www.abc.net.au/news/2023-03-28/detailed-portrait-data-breaches-oaic-disclosures/102131586>.


49. SOCI Act (n 15) s 30BC; Cyber and Infrastructure Security Centre, Department of Home Affairs, Security of Infrastructure Act 2018 General Guidance for Critical Infrastructure Assets (Factsheet, 2025) <https://www.cisc.gov.au/resources-subsite/Documents/cisc-factsheet-soci-obligations.pdf>.


50. Privacy Act (n 2) s 26WH.


51. Office of the Australian Information Commissioner, Notifiable Data Breaches Report: January to June 2023 (Report, September 2023).



53. Ibid.


54. Privacy Act (n 2) s 6(1) (definition of ‘personal information’).


55. Ibid s 6(1) (definition of ‘sensitive information’). 


56. Teresa Scassa and Amy Conroy, ‘The Privacy/Transparency Balance in Open Government’ in A Ojo and J Millard (eds), Government 3.0: Next Generation Government Technology Infrastructure and Services (Springer, 2017) 333, 339, 341. 


57. OAIC, ANAO Report 12 (n 1) 12.


58. OAIC, ANAO Report 12 (n 1) 57.


59. Ibid.


60. Ibid 60.


61. Ibid 62.


62. Ibid 59.


63. Ibid 51, 53.


64. Ibid 30.


65. Ibid.


66. Australian National University, Incidental Report on the Breach of the Australian National Universities Administrative Systems (Report, 2019) (‘ANU Report’). 


67. Privacy Act (n 2) s 6(1) (definition of ‘personal information’ and ‘sensitive information’).


68. ANU Report (n 66) 2.


69. Ibid 6; Scassa and Conroy (n 33) 339, 341; Privacy Act (n 4) s 6(1) (definition of ‘personal information’).


70. ANU Report (n 66). 


71. Privacy Act (n 2) s 26WH; ANU Report (n 66) 3.


72. ANU Report (n 66). 


73. Privacy Act (n 2) s 26WL.


74. Privacy Act (n 2) s 26WL. 


75. ANAO Report (n 1) 51, 53.


76. ANU, ANU Report (n 66) 1.


77. APP Governance Code (n 20). 


78. Privacy Act (n 2) cl 11.2.


79. ‘MediSecure Statement on Cyber Security Incident’, MediSecure (Web Page, 16 May 2024) <https://medisecurenotification.wordpress.com/> (‘MediSecure Statement’).


80. Angie Lavoipierre, ‘MediSecure reveals 12.9 million Australians had personal data stolen in cyber attack earlier this year’, ABC News (online, 18 July 2024) <https://www.abc.net.au/news/2024-07-18/medisecure-data-cyber-hack-12-million/104112736>.


81. MediSecure Cyber Security Incident’, Department of Home Affairs (Web Page, 19 July 2024) <https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-coordinator/medisecure-cyber-security-incident>.


82. MediSecure Statement (n 72).


83. Lavoipierre (n 80).


84. Office of the Australian Information Commissioner, ‘Statement on MediSecure Data Breach’ (Media Release, 13 September 2024). <https://www.oaic.gov.au/news/media-centre/statement-on-medisecure-data-breach-september-2024>. 


85. Office of the Australian Information Commissioner, ‘OAIC Takes Civil Penalty Action against Medibank’ (Media Release, 5 June 2024) <https://www.oaic.gov.au/news/media-centre/oaic-takes-civil-penalty-action-against-medibank> ‘OAIC Media Release’.


86. Ibid.


87. Australian Information Commissioner, ‘Concise Statement’, Concise Statement in Australian Information Commissioner v Medibank Private Ltd, VID497/2024, 19 June 2024, Annexure C, 3.


88. OAIC, Medibank Data Breach: Alleged Timeline (Infographic, 5 June 2024) https://www.oaic.gov.au/__data/assets/pdf_file/0037/228979/Medibank-data-breach-alleged-timeline-infographic.pdf.


89. ‘Medibank Civil Penalty Action’, Office of the Australian Information Commissioner (Infographic) <https://www.oaic.gov.au/__data/assets/pdf_file/0029/228980/Medibank-civil-penalty-action-overview-infographic.pdf> ‘OAIC Infographic’.


90. OAIC Media Release (n 85). 


91. OAIC Infographic (n 89). 


92. Privacy Act (n 2) s 26WL.


93. Office of the Australian Information Commissioner, Guide to Securing Personal Information (Guide, June 2018) pt B; Australian Signals Directorate, Essential Eight (Web Page) <https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight>.  








 
 
 

Comments


Protocol Logo

Contact Us

Email

emma@protocolpolicylab.org

We would love to hear from you! 

Follow Us

  • Instagram
  • LinkedIn

Subscribe to our Newsletter 

Subscribe and stay up-to-​date on Protocol's latest news, upcoming events and opportunities. 

bottom of page