Data Breach, Cyber Security and Privacy Law Update – Sept 2025

From 30 May 2025 all businesses that have an annual turnover of $3 million in a financial year, must report a ransomware or cyber extortion within 72 hours of making or having a payment made on its behalf. This is in addition to existing reporting obligations under the Notifiable Data Breach scheme. This article explores these reporting obligations and offers guidance on some strategies to consider for data protection and privacy law compliance.

Read more

Compensation & Penalties for Privacy Data Breaches under the Privacy Act 1988 (Cth) – Updated – March 2020

The Australian privacy law provides for an individual affected by a data privacy breach to seek compensation from the organisation involved in the breach. In this article, Stephens Lawyers & Consultants also provides a review and summary of the compensation awarded in determinations made during the years 2016-30 June 2020 by the Office of the Australian Information Privacy Commissioner in relation to privacy breaches and some of the factors taken into account by the Privacy Commissioner in awarding compensation and costs.

Read more