From information governance to the pleasure of information itself: Mona in Hobart has opened Phrontisterion, a subterranean library more than a decade in the making and built at a cost of just over $100 million. It houses David Walsh’s growing collection of books, rare volumes, maps and manuscripts, with around […]
Archive
Privacy Awareness Week – 16- 22 June 2025
This Privacy Awareness Week (PAW) runs from Monday 16 June to Sunday 22 June with the theme: ‘Privacy – it’s everyone’s business’. There are a number of free events on topical issues and featuring the Australian Privacy Commissioner and Privacy Commissioners from around Australia. Learn more and register for these […]
New Zealand Privacy Week 12-16 May 2025
The theme of New Zealand Privacy Week 2025 is ‘Privacy on Purpose.’ Be purposeful and proactive with privacy – doing privacy well is a business advantage. The Office of the Privacy Commissioner is hosting 22 free webinars over Privacy Week 2025 to educate and raise awareness about privacy. New Zealand […]
Explore our AI Resources
Visit the Artificial Intelligence (AI) section of our Resource Hub, where we’re continually adding valuable content to support your work. Be sure to check out the dedicated sub-sections on: Alogorthim Impacts Assessment Tools Gen AI Guidance AI and record-keeping Our goal is to create a central hub where members can easily access trusted, […]
Australia’s Cyber Security Bill 2024
In introducing the Cyber Security Bill on 9 October 2024, the Honorable Tony Burke MP explained that the Bill addresses whole-of-economy cybersecurity issues and positions the government to respond to new and emerging threats, including the ability to counter ransomware and cyber extortion. The key measures of the Cyber Security Act 2024 include:
- Mandatory 72-hour reporting obligation for entities who receive a ransomware demand and make a payment in connection with that cyber security incident;
- ‘Limited use’ obligation restricting the information provided to the National Cyber Security Coordinator (NCSC) during a cyber incident, being provided to another Commonwealth body for investigation or enforcement not related to the Bill.
- Establishing a Cyber Incident Review Board (CIRB) to conduct no-fault post-incident reviews of significant cyber security incidents. The Board is modelled on similar bodies, including the U.S. Cyber Safety Review Board, and will also make recommendations for both government and organisations to enhance Australia’s cyber resilience.
- Enabling the government to establish mandatory security standards for smart devices. The aim is to bring Australia into line with international best practice and enhance consumer security, such as prohibiting universal default passwords on smart devices.
Access the Cyber Security Act 2024 here
Privacy Bill tabled in Parliament
On 12 September 2024, the Attorney-General, the Hon Mark Dreyfus KC tabled the long-awaited Privacy and Other Legislation Amendment Bill 2024 (the Bill). This would enact the first tranche of reforms to the Privacy Act 1988 (Cth) (Privacy Act) and implement 23 of the 25 proposals the Government agreed to in its September […]
Digital ID Bill passes Senate
The Digital ID Bill 2023 and Digital ID (Transitional and Consequential Provisions) Bill 2023 have now passed the Senate and are expected to progress to the House of Representatives in the next sitting period this year. The key amendments made to the Exposure Draft of the Digital ID Bill […]
AI Governance now mandated for U.S. Federal Government Agencies
On 28 March 2024, President Biden issued a Memorandum establishing new agency requirements and guidance for AI governance, innovation, and risk management, including through specific minimum risk management practices for uses of AI that impact the rights and safety of the public. Specific actions required by agencies include: Designating a Chief […]
OAIC’s Latest Data Breach Report
The Office of the Australian Information Commissioner (OIAC) has released the Data Breach Report for 1 July to 31 December 2023. The key findings include a 19% increase in notifications in the second half of 2023, and that the top 5 sectors to notify of data breaches were health, finance, insurance, […]
NZ Government Guidance on Information Sharing
The New Zealand Government has released a Guide on information sharing for government agencies. The Guide is aimed at helping agencies to design and implement information sharing safely. Katrine Evans, Government Chief Privacy Officer, in a statement accompanying the Guide explains that the guidance and templates are designed to help agencies: […]
Update on Digital ID Bill 2023
The Senate Economics Legislation Committee Report on the Digital ID Bill introduced on 30 November 2023, has recommended that the bill together with consequential legislation be passed. The purpose of the Digital ID Bill will establish new legislation to codify and expand the Australian Government Digital ID System (AGDIS), which […]
U.S. President issues Executive Order to Protect Sensitive Personal Data
On 28 February 2024, President Biden issued an Executive Order which authorises the Attorney General to prevent the large-scale transfer of Americans’ personal data to countries of concern and provides safeguards around other activities that can give those countries access to Americans’ sensitive data. Pursuant to the Executive Order, the Department […]
UK ICO priorities for 2024
In a recent speech at the IAPP Data Protection Intensive in the UK, Information Commissioner, John Edwards laid out the priorities for the ICO including children’s privacy, advertising technology, AI and biometrics including: Referring to the ICO cases against Snap and TikTok and other investigations underway, stating that the ICO […]
LawFest 24 Highlights
At this year’s LawFest conference in Auckland, over 400 attendees were privileged to hear Professor Cat (Caitlin) Moon, Founding Co-Director, Vanderbilt AI Law Lab at Vanderbilt University in her keynote address, Designing Tomorrow and the future ready professional in the Age of AI. As Professor Moon explained, even if AI does eat […]
Australia’s Digital ID System
On 30 November 2023, the Minister for Finance, Senator the Hon Katy Gallagher, introduced into Parliament the Digital ID Bill 2023 and the Digital ID (Transitional and Consequential Provisions) Bill 2023. Minister Gallaghed explained, ‘the Digital ID system will enable people to verify their ID when interacting online without having to […]
New FOI and Privacy Commissioners
For the first time since 2015 the Office of the Australian Information Commission will have a standalone FOI Commissioner, Privacy Commissioner and Information Commissioner, as Parliament originally enacted. Congratulations to Ms Elizabeth Tydd who has been appointed as the Freedom of Information (FOI) Commissioner. Ms Tydd has been the Information […]
Responsible AI
This collection of short papers developed by the Australian Academy of Technological Sciences and Engineering (ATSE) and the Australian Institute for Machine Learning (AIML) at The University of Adelaide offers an insight into the world of responsible artificial intelligence and the opportunities this presents to Australia. Read the report here
Lawfest 24 – Auckland
Join us at LawFest 24 the premier legal innovation and technology event in New Zealand taking place on 7 March 2024. With 20+ amazing speakers from New Zealand and abroad, the interactive programme will deliver practical insights of how to innovate and leverage technology to help you deliver legal services for today […]
NSW MNDB Scheme starts 28 November
The Mandatory Notification of Data Breach (MNDB) Scheme will come into effect on 28 November 2023. It requires public sector agencies bound by the PPIP Act to notify the Privacy Commissioner and affected individuals of data breaches involving personal or health information likely to result in serious harm. It also applies to […]
Compliance and Enforcement Policy for the Consumer Data Right
The Office of the Australian Information Commissioner and the Australian Competition and Consumer Commission have updated their joint Compliance and Enforcement Policy for the Consumer Data Right (CDR). The policy outlines the priorities, how the agencies encourage compliance and their approach to enforcement of matters. The Policy sets out that where OAIC […]


















