AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
as it enters another year of its multi-year cyber-resil - ience transformation programme. These two cases are ones to watch not, only for finan - cial licensees, but also all businesses with cybersecu - rity and data-protection obligations. There still remains an ongoing concern that this could become a hot spot for regulator “pile-ons”, given that data breaches and cybersecurity issues have generally been regulated from a privacy perspective by the Office of the Aus - tralian Information Commissioner (OAIC). While this concern remains, the regulators appear to be staying In a world-first, the Telecommunications (Assistance and Access) Act 2018 (Cth) granted the Department of Home Affairs the power to request or compel assistance from telecommunications providers and technology companies in accessing encrypted com - munications, such as Technical Assistance Requests (TARs), Technical Assistance Notices (TANs), and Technical Capability Notices (TCNs). According to the latest Telecommunication (Intercep - tion and Access) Act annual report (covering 2023- 24), these powers were overwhelmingly used by state police, specifically TARs (47 by NSW Police, 3 by Victorian Police, and 5 by WA police) and the ACIC (5). Most TARs were issued in relation to homicide (or related offences) or illicit drugs (38 of the 63 issued), suggesting they are indeed being reserved for serious offences, at least at the state level. in each their own siloed lanes. Technical assistance requests This distribution of use largely reflected previous years, with TARs being issued by state police forces or the ACIC, and no TANs or TCNs being used. In fact, in 2024, the ASIO Director stated “encryption damages intelligence coverage” in all priority counter-terrorism and counter-espionage cases; but instead of flagging an increased use of these powers, the Director called for “tech companies to do more[…] to give effect to the existing powers and to uphold existing laws”. The value in these powers that were rushed through parlia - ment was heavily in question, as was the authorities’ capacities to properly wield them.
However, in an Australia-first, the Australian Fed - eral Police issued two TANs during the 2023-2024. Whether this marks a shift in the AFP and other law enforcements’ capacity to properly use these powers
remains to be seen. Compliance sweep
From January 2026, the OAIC commenced its first- ever compliance sweep. This sweep involves the Pri - vacy Commissioner reviewing whether approximately 60 entities from six sectors are complying with the Privacy Act, particularly the changes passed in 2024 by the Privacy and Other Legislation Amendment Act 2024 (Cth). The six industries relate to property, phar - maceuticals, licenced venues, car rentals, car dealer - ships, and second-hand dealers. Under the Office’s regulatory powers, expanded in the December 2024 reforms, entities found to have non-compliant privacy policies may face compli - ance and infringement notices and penalties of up to AUD66,000. This is a marked shift in the Privacy Com - missioner’s regulatory approach, from educational to enforcement. Businesses in these six industries, and any industry that is covered by the Privacy Act, should ensure that they have up-to-date privacy policies that align with the Privacy Act, the Australian Privacy Principles, as well as any new guidance published by the Office. Cybersecurity sanctions The Australian government’s response to the 2022 cyber-attack against Medibank Private continues, as does its use of Magnitsky-style sanctions against cybercriminals. On 12 February 2025, the government imposed sanctions under the Autonomous Sanctions Regulations 2011 (Cth) on ZServers and five Russian employees. ZServers is reportedly a “bullet-proof hosting provider” (see “Threat Landscape”), which provided infrastructure to host and disseminate data stolen from Medibank Private in 2022. This was the first cybersanction against a business and the first sanction for the provision of services or infrastructure used to engage in cybercrime. The USA and the UK also imposed similarly targeted sanctions.
30 CHAMBERS.COM
Powered by FlippingBook