• Skip to main content
  • Skip to footer

InfoGovANZ

Information Governance in the AI age

  • Become a Member
  • Member Login
  • Member Account
    • My Account
    • My Courses
    • Webinar Recordings
  •  
  • Home
  • About Us
    • Our Goals
    • Founder & Executive Director
      • Dr Susan Bennett
    • Advisory Board
      • Dr Peter Chapman
      • Matthew Golab
      • Andrew King
    • International Council
      • Dr Susan Bennett
      • Sarah Auva’a
      • Denise Backhouse
      • Barclay T Blair
      • Brynmor Bowen
      • Dr Pietro Brambilla
      • Dr Peter Chapman
      • Dr Ronke Ekwensi
      • Carol Feuerriegel
      • Matthew Golab
      • Mazen Kassis
      • Richard Kessler
      • Andrew King
      • Ilana Lutman
      • Lynne Saunder
      • Tarun Samtani
      • Dr Nichole Sterling
      • Dr Pieter Van Der Walt
      • Patrick E. Zeller
  • AI Governance
    • AI Governance Courses
    • AI Governance for Professionals
    • AI Governance for Directors
    • AI Resources
  • Events & Workshops
    • Upcoming Events
    • AI Governance Training
    • Bespoke Workshops
    • Webinar Recordings
  • Member Resource Hub
    • Latest News
    • Artificial Intelligence (AI)
    • Cyber & Info Security
    • Data – Sharing & Identity
    • eDiscovery
    • Environmental, Social and Governance (ESG)
    • FOI – Access to Information
    • Information Governance
    • Privacy
    • Records Management
    • IGANZ Industry Reports
    • The Governance of Things Monthly Publication
    • Webinar Recordings
  • Join Now
  • My account
    • Courses
    • Webinar Recordings

OAIC Data Breach Report: Key Themes

October 8, 2024 by InfoGovANZ

From January to June 2024, OAIC received 527 data breach notifications, the highest number since July to December 2020. The top five sectors that notified of data breaches in this period, were Health Service Providers, the Australian government, Finance, Education, and Retail.

In a media release accompanying the Notifiable Data Breaches Report on 16 September 2024, Australian Privacy Commissioner Carly Kind said, ‘the high number of data breaches is evidence of the significant threats to Australian’s privacy.’  The reporting period included the MedicSecure data breach notification affecting nearly 13 million Australians.

So far this year, the Information Commissioner has filed civil penalty proceedings in the Federal Court against Medibank arising from its October 2022 data breach. The OAIC has also issued an intention and a direction to notify of an eligible data breach about incidents in previous reporting periods and opened an investigation into the HWL Ebsworth Lawyers 2023 data breach.

OAIC’s Data Breach Report identifies the following key themes and recommendations:

  • Mitigating cyber threats – organisations need to have appropriate and proactive measures in place to mitigate cyber threats and protect the personal information they hold.
  • Addressing the human factor – individuals are a significant threat to the strength of an entity’s privacy practices.  Organisations need to mitigate the potential for individuals to intentionally or inadvertently contribute to the occurrence of data breaches.
  • Extended supply chain risks – organisations that outsource the handling of personal information can reduce the impact of a data breach in the supply chain by implementing a robust supplier risk management framework.
  • Misconfiguration of cloud-based data holdings – organisations need to be aware there is a shared responsibility for the security of data in the cloud.
  • Relevance of a threat actor’s motivation in assessing a data breach – entities should not rely on assumptions. They should weigh in favour of notifying the OAIC and affected individuals when a breach occurs.
  • Data breaches in the Australian Government – of all sectors, the Australian Government reported the most data breaches involving social engineering or impersonation. Organisations need to have access control measures in place to ensure only authorised persons access their systems.

Access the OAIC ‘s Data Breach Report here and the OAIC’s Guide to Securing Personal Information here.

Filed Under: Privacy - Australia and NZ

Footer

Information Governance ANZ Pty Ltd

Level 26, 1 Bligh St, Sydney 2000
Ph: +61 2 8226 8546
E: infogovanz@infogovanz.com

ACN: 611 611 360

Linkedin Information Governance ANZ Twitter Information Governance ANZ

Become a Member
Corporate Partnership Opportunities

Contact

Copyright © 2026 Information Governance ANZ Pty Ltd · Privacy Policy · Terms of Use