Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

GDPR & PbD: what Aussies need to know about new privacy laws

April 27, 2017, Anna Johnston

Unless you’ve been living under a rock recently, you have probably at least heard about this new big thing in the privacy world called ‘GDPR’ … and maybe you have even wondered whether it matters to you.  But once you realised it is a new European privacy law, did you mentally switch off?  Well folks it’s time to switch back on, sit up straight and pay attention, because EU privacy law is going to impact on Australian organisations, whether we like it or not.  Some of us will be directly regulated, others only indirectly affected, but there will be an impact nonetheless.

So first, the headline facts.  GDPR stands for General Data Protection Regulation.  It is a new privacy law which will apply from May 2018 across all 28 EU member states – including the UK for now, and likely even post-Brexit too.  The GDPR will replace the current set of differing national privacy statutes with one piece of legislation, and will offer a one-stop-shop approach when dealing with the privacy regulators across those 28 countries.  So the GDPR is about harmonising privacy law across the EU, and streamlining its application.  That’s the fairly impressive carrot.

The stick is impressive too: fines for failing to comply with the GDPR will reach up to €20M, or 4% of a company’s annual global turnover, whichever is the greater.  Oh yeah, these new penalties are aimed squarely at the Facebooks and Ubers and Googles – behemoths who could previously afford to shake off smaller fines as the price of doing business.

While those potential penalties are startling enough, the other kicker is the new, expanded reach of GDPR, well beyond European land borders.  The privacy rules in the GDPR apply to any organisation which offers goods or services (including free services) to, or monitors the behaviour of, “data subjects in the Union”.  That is EU-legalese for “anyone inside the EU” – not just citizens.

Your organisation does not need to have any physical or legal presence in the EU to be directly regulated.  If you offer your goods or services to people in the EU, you will be required to comply with the GDPR.  So if you are a retailer selling Aussie cossies to Greta of Germany, you will need to comply.  If you are a travel agent booking tours to Uluru for Bertrand from Belgium, ditto.

Even for those of us not directly regulated by the GDPR, there will be indirect impacts.  Europe has raised the bar in terms of expectations about privacy protection, and the rest of the world is likely to follow.

Take for example the Accountability principle, which requires organisations to be proactive.  This means that if you don’t have an effective privacy compliance program, you can be found in breach of your data protection obligations even if you don’t suffer a data breach.

Although by no means a European invention – our APP 1 has the same objective – the financial penalties attached to the GDPR are intended to kick-start proper privacy governance in even the most heel-dragging organisations.  No surprise then that Elizabeth Denham, the UK Information Commissioner, has described the Accountability principle as a “game changer”:

“The new legislation creates an onus on companies to understand the risks that they create for others, and to mitigate those risks. It’s about moving away from seeing the law as a box ticking exercise, and instead to work on a framework that can be used to build a culture of privacy that pervades an entire organisation.”

To help achieve this, the GDPR embeds a requirement to do ‘data protection by design’, or as we tend to know it, Privacy by Design (PbD).  In our view, the GDPR will be the stimulus for plenty of talk about PbD – but it needs to be more than just a hollow set of catchy promises.

Turning PbD into a reality poses significant challenges for any organisation.  There is a cultural divide between the lawyers who are comfortable with principles-based fuzzy law and concepts like ‘within reasonable expectations’, and the system engineers who need to code for decision-making in a binary fashion.  Even the central tenets of PbD are fuzzy: what is a solution architect actually supposed to do if she is told to ‘embed privacy into the design’?

(Well, actually, here at Salinger Privacy we have developed eight Privacy Design Strategies, which offer clearer guidance for system designers.  And now, just in time for you to get ready for Privacy Awareness Week, we have launched new online training modules on this topic: how to identify privacy risks in projects, and how to resolve those risks.  Our objective is to turn abstract privacy principles into concrete design strategies, so that privacy officers and system designers can work together to deliver on the promise of PbD.)

The GDPR also has a strong focus on getting reactive strategies right.  Although data breach notification requirements have been around in the United States for some years now, and Australia has just passed its own data breach notification laws, the GDPR ramps up the pressure further, by setting a default 72-hour timeframe on notifying the relevant regulator.  However the GDPR also offers escape clauses for organisations that have “appropriate technical and organizational measures” in place to protect data.  We predict the result will be bigger infosec spends on data loss prevention technologies.

There are other ways in which I am already seeing the influence of the GDPR in Australia, such as new thinking about the right of consumers to data portability from the Productivity Commission.  And last month on behalf of iappANZ I was one of four panellists discussing the impact of the recent Privacy Commissioner v Telstra case, when discussion inevitably turned to comparisons with the GDPR.  The GDPR skips straight past the is-this-data-‘about’-an-individual dilemma in Australian privacy jurisprudence, by defining ‘personal data’ more simply as “any information relating to an identified or identifiable natural person”.

Finally, the GDPR was carefully drafted to reject the old binary “either it’s personal information or it’s not” approach to de-identification, in favour of recognising that de-identification is a risk management tool, not a perfect end-state.  Further, the GDPR explicitly refers to “taking into consideration the available technology” when testing for (re)identifiability, meaning that considering a dataset in isolation is not enough.  This more nuanced and pragmatic approach is influencing contemporary thinking on the topic, including our own introductory guide to de-identification techniques.

So whether your organisation will be directly regulated by GDPR or not, I predict that privacy professionals across Australia will be feeling its positive influence for years to come.

Vive l’Europe!

(April 2018 update: If you would like some privacy tools to help you assess the risks posed by a new project, or if you are wondering how the GDPR’s requirement to incorporate Data Protection by Design should be implemented in practice, our Compliance Kits are now available.  The privacy tools included in our Kits include a template Data Breach Response Plan, a template Privacy Policy, and a template Privacy Risk Assessment Procedure & Questionnaire you can download and easily customise for your organisation for use when conducting Privacy Impact Assessments or privacy audits.  Each of those templates cover both the GDPR and the Australian Privacy Act.  Our Comprehensive Compliance Kit also includes a GDPR Compliance Checklist, and loads more templates, checklists, eBooks and eLearning modules.  Check out our range of Compliance Kits to see what suits your needs.)

 

Image (c) Shutterstock

Filed Under: Uncategorized

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Recent Posts

  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk
  • How to get ahead of the new ADM rules before they rule you

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.