Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, 6 August 2014

What is Privacy? OAIC are showing us the way.

When looking for a new home we like to see photos of what the house looks like but for a tenant/home owner are there any rules that govern what photos the real estate agent takes and is there anything you can do if you are unhappy about the photos they have taken.

The OAIC's fifth video in their Privacy series tell us,'Is my real estate agent aloud to take photos in my house?'


________________________________________________________________________________ If your neighbour has a security camera and you are concerned about your Privacy the OAIC's latest video gives you some advice on what you can do to apease the situation.

The OAIC's fourth video in their Privacy series tell us,'What can i do about my neighbours security camers?'


________________________________________________________________________________
We all have personal information held by organisations, but how do you access that information, are you able to just ask for it or might you have to pay or wait for an extended period of time, and then what if it is incorrect are you able to make changes where you need to?

The OAIC's third video in their Privacy series tell us,'How do I access my personal information?'


________________________________________________________________________________
If you know that personal information about you has been mishandled what should you do, and how do you go about making a complaint?

The OAIC's second video in their Privacy series tell us, 'How do I make a privacy complaint?'


_________________________________________________________________________________
Following on from PRIVACY AWARENESS WEEK in May 2014 when CQR were partners of the OAIC (The Office of Australia Information Commissioner), the OAIC have released the first a series of 5 video's which are designed to help individuals learn more about PRIVACY and the common concerns they may have.

All of the video's are to be release over the next 2 weeks and we will be here to support the OAIC in spreading the word on PRIVACY.

The first in the series is 'What is Privacy?'



Further information on the changes to the PRIVACY ACT can be found on the OAIC website.

Sarah Taylor
www.cqr.com

Wednesday, 7 May 2014

Privacy Awareness Week Day 3: What you can do to protect your privacy when using mobile phones

We have to remember that mobiles aren't just phones anymore! They store a significant amount of data to make life easier for us, but we must ensure that we don’t make it an easy target for thieves or hackers! 
So…what can we do to protect our personal information on our ‘smart’ phones?

1 - Familiarise yourself with the settings of your phone, understand the key features and enable the security features including setting a password or PIN so that no one else can access your information if your phone is lost or stolen.

2 - Turn off the Bluetooth function when not in use so that your device is only visible when you specifically need other people or devices to see it.  This means that potential hackers cannot connect to it unless they already have your Bluetooth address.

3 - When connecting to the internet, try to use an encrypted network that requires a password.

4 - Check for updates regularly, install as soon as they become available as these often contain important changes that will make your phone more secure.

5 – Keep your phone safe and on your person at all times.

6 – Back up your data regularly.

According to the OAIC 62% of Australians have chosen to not use a mobile app due to privacy concerns.

What can we do to ensure we are kept safe when downloading and using apps?

1 – Download apps from reputable websites and mobile phone apps.
2 – Follow the set up properly and consider the need for an app to access your contacts list or location details.  If in doubt don’t use it!


Other posts from Privacy Awareness Week
Privacy Awareness Week, Day 1: What is privacy and changes to the Ac
Privacy Awareness Week Day 2: Protect your privacy online

Yvonne Sears
Senior Security Specialist
@yvonnesearsCQR
www.cqr.com

Monday, 5 May 2014

Privacy Awareness Week, Day 1: What is privacy and changes to the Act

web banner with border

 This week (5th -10th May) is Privacy Awareness Week (PAW) and CQR has partnered with the Office of the Australian Information Commissioner (OAIC) to help promote Privacy Awareness amongst the community.

So what is Privacy?
Privacy is about the protection of an individual’s personal information.  We are all responsible for protecting our own identity and that of others.  Think about it:  We expose or own personal information on a daily basis.  When we use social media, contact our utility companies and shop online we provide a large amount of our own personal data.  You may make the assumption that the person or website you are sharing your information with will take care of it, ensure it is secure and not share it with anyone else.
This to a degree is true and most companies will have a privacy policy in place to demonstrate a level of commitment to protecting your personal information, but this isn't a fool proof solution.

The person who is actually responsible for your personal data at the end of the day is you!  What is the best way to safeguard yourself and look after your own identity?  Have you ever taken the time to think about it?

To help you understand, Australia an independent Government agency responsible for privacy functions that are conferred by the Privacy Act 1988 (Privacy Act) called the Office of the Australian Information Commissioner (OAIC).  The OAIC provides advice and guidance to the public, Businesses and Government agencies on how they are to handle personal information. 

The changes to the Privacy Act on 12th march 2014 brought about a heightened awareness of the message that we should be protecting our own privacy and together with PAW CQR has put together a program of Blogs covering:
-          How you can protect your privacy online;
-          What you can do to protect your privacy when using mobile apps;
-          Business obligations to privacy; and
-          How to manage breaches to personal information.

We hope that you will keep a keen eye out on blogs, get engaged in conversation and most importantly retweet the messages to colleagues, family and friends to share the importance of Privacy.


You can find more information on your privacy rights and Privacy Awareness Week from the OAICwebsite

Yvonne Sears
Senior Security Specialist
@yvonnesearsCQR
www.cqr.com

Wednesday, 12 March 2014

Privacy and your organisation, do you understand the rules?

The Australian Privacy Amendment Act 2012 will come in to force on 12th March 2014 and will introduce significant amendments to the Privacy Act 1998.

The Privacy Act changes will give the Information Commissioner the ability to: 
  • Resolve complaints, use external dispute resolution services, conduct investigations and promote compliance;
  • Investigate serious breaches (including the right to impose penalties of up to 1.7 Million on businesses);
  • Assess the privacy performance of businesses.
Who must comply with the Act?

The Privacy Act protects personal information handled by businesses with an annual turnover of more than $3 million and health service providers of any size.

The Act may also apply to a small business however if they pose a higher risk to privacy, for example, small businesses that hold health information and provide health services or those that:
  • trades in personal information
  • provides services under a Commonwealth contract
  • runs a residential tenancy database
  • is related to a larger business
  • is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act.
Other small business operators may choose to opt in to the regime or may be brought into the regime by regulation.

If you’re not sure whether the Privacy Act applies to your business, try the 9 Step Privacy Checklist for Small Business External linkon the Office of the Australian Information Commissioner (OAIC) website.  http://www.oaic.gov.au


How will the changes affect you?

The changes will affect how businesses can:
  • Handle and process personal information;
  • Use personal information for direct marketing;
  • Disclose personal information to people overseas.
Although you may already have a requirement to comply with the Privacy Act you need to be particularly aware of the changes as you will need to change your privacy policies and practices significantly in order to comply with requirements of the Australian Privacy Amendment Act 2012.

A point to note

Each State has its own Privacy legislation and therefore you must understand the legislative restrictions on processing personal data, not only within the State you reside, but of the States you interact with!

NSW for example has the Privacy and Personal Information Protection Act 1998 (NSW) together with the Health Records and Information Privacy Act 2002.  

Private sector company’s should be aware of requirements if they provide services to a NSW government agency.

Private sector health services providers of any size in NSW will have to comply with the Health Records and Information Privacy Act 2002 and also the Commonwealth Privacy Act 1988.

How confident are you in your Privacy practices?
For example, APP11 requires an organisation to take reasonable steps to ensure personal information is protected from “Interference, unauthorised access, modification and disclosure”. 

  • How do you provide this assurance?
  • Are you able to demonstrate ‘reasonable’ steps have been taken to protect personal data?
You must take reasonable steps to “implement practices, procedures and systems that ensure compliance with the APPS”.

So how well do you know your information processes?  What personal information do you collect and do you understand its lifecycle within your organisation?  Are you able to answer the following:
  • What personal information is collected, where, when, why and by whom?
  • What controls do you have at the collection point?
  • Do you collect consent?
  • How do you record consent?
  • Do you understand the purpose(s) for which information is collected?
  • How is it kept relevant?
  • Where does the information go?
  • How is it stored?
  • How is it kept up to date?
  • What format is data stored? For how long?
  • What happens at ‘end-of life’?
If you’re not confident you can answer these questions, we are here to help!

CQR Services


CQR is able to help organisations through the following services:



Service

Overview

Privacy Compliance Jumpstart

We will conduct a Privacy Impact Assessment (PIA), Provide an implementation roadmap and draft a Privacy Policy.

Privacy Impact Assessment (PIA)

We will conduct a series of interviews to understand how you currently use and protect personal information.

Provide recommendations on how you can improve your processes to ensure the personal information is:

·         Processed fairly

·         Kept accurate, complete and up to date

·         Kept secure

·         Made available to data subjects


Update to Privacy Policy

We will review and update your Privacy Policy to ensure it captures the requirements of the Australian Privacy Amendment Act 2012.

Third Party Audit

We will conduct an audit on how you manage third party relationships.

Information Security Gap Analysis

We will conduct a series of interviews to understand how you currently protect personal information using ISO 27001 information security standard as the benchmark for compliance.

Privacy Audit

We will conduct an audit on your privacy practices covering:

·         Consent management

·         Subject access requests

·         How you use and protect personal data

·         Defined roles and responsibilities

·         Review of Privacy Policies, Procedures and Guidelines

·         Risk Management