"The Commissioner considered that the risk of re-identifying medical providers whose information was in the dataset was not sufficiently low, and that the Department’s processes for assessing the risks associated with publication were inadequate. The Commissioner’s view was that, in the course of publishing the dataset, the Department breached the Privacy Act 1988 (Cth).
In accepting an enforceable undertaking, the Commissioner acknowledged that the breaches were unintentional, and that the Department’s decision to publish the dataset was made on the understanding that the privacy interests of all relevant individuals were protected. The Commissioner noted the cooperative manner in which the Department approached the investigation, the quick and comprehensive steps it took to minimise the privacy impact of the incident once it was alerted to the risk of re-identification, and the improvements it has since put in place to enhance its data governance and release processes."
"This incident holds important lessons for custodians of valuable datasets containing personal information. Determining whether information has been appropriately de-identified requires careful, expert, and likely independent evaluation. Who the information is released to must also be considered.
Appropriate processes should sit behind any decision to release de-identified personal information. This incident offers an opportunity for Australian Government agencies to strengthen their approach to publishing data derived from personal information. Since this incident, the Australian Government has developed a Process for Publishing Sensitive Unit Record Level Public Data as Open Data, providing guidance on releasing datasets related to personal information."
"Realising the value of public data to the benefit of the community is dependent on the public’s confidence that privacy is protected. The OAIC continues to work with Australian Government agencies to enhance privacy protection in published datasets. Recently the OAIC and CSIRO’s Data61 jointly published the De-identification Decision-Making Framework (DDF). This provides guidance to Australian organisations that handle personal information on meeting their ethical responsibilities and legal obligations (such as those under the Privacy Act) when considering how datasets may be shared or released. The OAIC has also recently released an updated guide on De-identification and the Privacy Act, and a Guide to Data Analytics and the Australian Privacy Principles."
.... and some analysis and context for this https://www.themandarin.com.au/90624-health-breached-privacy-act-open-data-risk-patients-dismissed-oaic/
.... and some analysis and context for this https://www.themandarin.com.au/90624-health-breached-privacy-act-open-data-risk-patients-dismissed-oaic/
No comments:
Post a Comment