The financial penalty imposed on companies that suffer serious or repeated privacy breaches will be increased to at least $50 million.
Key points:
- The federal government believes the current $2.2 million fine is insufficient after recent cyber-attacks
- Attorney-General Mark Dreyfus will fast-track amendments to the Privacy Act next week
- The proposed legislation will see the fine for "serious or repeated privacy breaches" increase
The current penalty is $2.2 million and the federal government believes that is insufficient given massive cyber-attacks on Optus and Medibank Private in recent weeks.
Attorney-General Mark Dreyfus will fast-track amendments to the Privacy Act when federal parliament returns next week
"When Australians are asked to hand over their personal data they have a right to expect it will be protected," Mr Dreyfus said.
"Unfortunately, significant privacy breaches in recent weeks have shown existing safeguards are inadequate.
"It's not enough for a penalty for a major data breach to be seen as the cost of doing business."
The proposed legislation would see the fine for "serious or repeated privacy breaches" increased to either $50 million, three times the value of the benefit obtained through misuse of data, or 30 per cent of a company's adjusted turnover in the relevant period.
The fine would be whichever value is the highest.
Opposition wants jail terms for cyber extortion
The federal opposition has already called for tougher penalties in response to major cyber incidents.
Last month, shadow home affairs minister Karen Andrews also proposed new offences for cyber extortion that would carry a maximum 10 years imprisonment.
Earlier this week, Medibank admitted the personal data of some of its customers – including names, addresses, Medicare numbers and phone numbers – had been stolen in a cyber-attack.
Data related to health conditions and where people had received medical treatment was also compromised, with a criminal demanding ransom.
The matter has been referred to the Australian Federal Police and Medibank is working with the Australian Cyber Security Centre and Australian Signals Directorate.
It follows the breach on telco Optus, where hackers claimed to have accessed the data of 9.8 million current and former customers, including their passports, drivers licences and Medicare card details.
These hacks leave their customers vulnerable to identity theft, which can also lead to financial crime.
On Friday, The Australian Tax Office revealed it gets three million attempted hacks on its system every month.