Thursday, 12 April 2018

Human error (not hackers) behind most data breaches: NDB’s first report

https://www.themandarin.com.au/91151-human-error-not-hackers-behind-data-breaches-ndbs-first-report/

"In just six weeks, there were 63 data breach notifications to the Office of the Australian Information Commissioner since the Notifiable Data Breaches scheme came into force in February this year."

"Key statistics from the first quarterly report include:

  • Top five sectors that notified the OAIC of eligible data breaches included health service providers (24% of notifications), legal, accounting and management services (16%), finance (13%), private education (10%), and charities (6%).
  • 78% of eligible data breaches were reported to involve individual’s contact information. 33% were reported to involve health information and 30% to involve financial details.
  • 51% of the eligible data breach notifications received indicated that the cause of the breach was human error. 44% of breaches were reported to be the result of malicious or criminal attack, and 3% the result of system faults.
  • 59% of data breach notifications reported that the personal information of between one and nine individuals was affected. 90% of data breach notifications related to breaches involving the personal information of less than 1000 individuals."

The Open Science Training Handbook 1.0

The Open Science Training Handbook 1.0 is now available as a Gitbook at https://book.fosteropenscience.eu.

The handbook is available under Creative Commons Public Domain Dedication (CC0 1.0 Universal) and is oriented to practical teaching of open science principles. It was written by 14 experts during a book sprint organized by FOSTER and the TIB Hannover in February 2018.

After including suggestions from the community the handbook was moved to Github and released as version 1.0. The OSTH is meant to be a living handbook and the authors are very happy to receive your contributions and feedback about its use in practice, which they will consider while working towards version 2.0.

Thursday, 5 April 2018

Multi-Agency Data Integration Project has gone through an independent privacy impact assessment

https://www.themandarin.com.au/90851-giant-federal-data-integration-project-accepts-14-ways-to-improve-privacy-and-security/

"The federal government’s Multi-Agency Data Integration Project has gone through an independent privacy impact assessment, and the six big agencies involved have agreed to 14 recommendations for improvement.
The Australian Bureau of Statistics has been combining data from the Tax Office, Human Services, Social Services, Education and Health for several years already, as consulting firm Galexia notes in the new PIA, under the banner of testing the system:
“Since 2015 MADIP has been operating as an evaluation – testing the technical capability of the Partner Agencies to share data in a way that delivers useful outputs, whilst preserving privacy. The evaluation phase is expected to draw to a close in 2018.”

This work is the “core component” of the more recently announced Data Integration Partnership for Australia and the data will be shared with approved researchers via “highly secure ABS systems” according to the project website."

Wednesday, 4 April 2018

Privacy Commissioner finding from investigation into published MBS / PBS dataset

https://www.oaic.gov.au/media-and-speeches/statements/australian-privacy-commissioner-s-investigation-into-published-mbs-and-pbs-data-sets

"The Commissioner considered that the risk of re-identifying medical providers whose information was in the dataset was not sufficiently low, and that the Department’s processes for assessing the risks associated with publication were inadequate. The Commissioner’s view was that, in the course of publishing the dataset, the Department breached the Privacy Act 1988 (Cth).
In accepting an enforceable undertaking, the Commissioner acknowledged that the breaches were unintentional, and that the Department’s decision to publish the dataset was made on the understanding that the privacy interests of all relevant individuals were protected. The Commissioner noted the cooperative manner in which the Department approached the investigation, the quick and comprehensive steps it took to minimise the privacy impact of the incident once it was alerted to the risk of re-identification, and the improvements it has since put in place to enhance its data governance and release processes."
"This incident holds important lessons for custodians of valuable datasets containing personal information. Determining whether information has been appropriately de-identified requires careful, expert, and likely independent evaluation. Who the information is released to must also be considered.
Appropriate processes should sit behind any decision to release de-identified personal information. This incident offers an opportunity for Australian Government agencies to strengthen their approach to publishing data derived from personal information. Since this incident, the Australian Government has developed a Process for Publishing Sensitive Unit Record Level Public Data as Open Data, providing guidance on releasing datasets related to personal information."
"Realising the value of public data to the benefit of the community is dependent on the public’s confidence that privacy is protected. The OAIC continues to work with Australian Government agencies to enhance privacy protection in published datasets. Recently the OAIC and CSIRO’s Data61 jointly published the De-identification Decision-Making Framework (DDF). This provides guidance to Australian organisations that handle personal information on meeting their ethical responsibilities and legal obligations (such as those under the Privacy Act) when considering how datasets may be shared or released. The OAIC has also recently released an updated guide on De-identification and the Privacy Act, and a Guide to Data Analytics and the Australian Privacy Principles."


.... and some analysis and context for this https://www.themandarin.com.au/90624-health-breached-privacy-act-open-data-risk-patients-dismissed-oaic/