Site icon Auspreneur

Queensland Government Introduces Mandatory Data Breach Notification Legislation

Queensland Government

The Queensland government has introduced a bill to establish a mandatory data breach notification scheme, following a recommendation made about 15 months ago in the Coaldrake review into the culture and accountability of the Queensland government. With the introduction of this scheme, Queensland joins New South Wales as “the only other state to introduce such a scheme.”

The legislation requires Queensland government agencies to notify individuals of data breaches, empowering them to take steps to reduce the risk of harm resulting from a data breach. When a government agency suspects a breach, it must take reasonable containment measures and assess the incident within generally up to 30 days. Some exemptions exist, such as if notifying could compromise or worsen the agency’s cybersecurity.

Agencies will also need to maintain a “register” of breaches and publish a “data breach policy.” Furthermore, the legislation aligns Queensland privacy principles with the Australian Privacy Principles, potentially setting the stage for further reforms after the Commonwealth government’s review of the federal Privacy Act.

This move reflects the increasing focus on data privacy and protection, with high-profile data breaches highlighting the need for clear and consistent requirements to address potential harm to individuals arising from unauthorized data access or disclosure.

Exit mobile version