The Financial Advice Association Australia has raised concerns over its members’ ability to meet a proposed 72-hour window to determine if a data breach should be reported and recommends in a submission to consultation on the Privacy Amendment (Personal Data Protection) Bill that the deadline be reviewed for small businesses.
“Member feedback indicates that the practical difficulty lies not only in preparing a notification, but in determining within 72 hours whether an incident is reportable,” according to the submission. The difficulty lies on the possibility that the information required lies outside of the business and with a third-party provider, technology company or its licensee.
The FAAA recommends clarification of when the 72-hour notification period commences and the guidance is provided around the circumstances in which entities may rely on the incomplete notification provisions.
Financial advisers have access to clients’ most personal and sensitive information and are well placed to identify early signs of potential abuse being experienced by these clients. The FAAA wants further guidance on how this permitted general situation (PGS) will interact with an adviser’s existing legal duties of confidentiality.
The association recommends the development of the Office of the Australian Information Commissioner guidance on “the practical application of the broadened PGS 2 to adviser detection of suspected financial abuse, including its interaction with financial advisers’ legal duties of confidentiality and other safeguarding obligations”.
FAAA members are concerned that de-identification is not necessarily a one-off or practical solution for advice records. If required to review and redact large record sets the technology and compliance costs to small business could be substantial.
“Government should also consider whether privacy risk can be reduced by enabling advisers, with client authority, to verify high-risk information through secure government or trusted digital identity services at the point it is needed, rather than requiring clients and practices to repeatedly transmit and store copies,” the FAAA says.
The association recommends clarification on how data minimisation and the definition of collection apply where information is accessible through a client-controlled portal provided by the adviser but has not been requested or used by the adviser.
Member feedback also highlighted the difficulty of reconciling minimisation and deletion requirements with overlapping retention obligations under financial services, AML/CTF, dispute resolution and evidentiary frameworks. The FAAA recommended proportionate, risk-based guidance on retention, destruction and de-identification of personal information be provided.
The bill is intended to include ways to enhance regulatory powers and efficiency of the OAIC as privacy regulator. The FAAA wants to clarify how the proposed requirement to first raise privacy complaints, and the entity’s 60-day response obligation, are intended to interact with existing obligations, to avoid parallel or conflicting complaint-handling processes for a single client complaint with both advice and privacy dimensions.
The FAAA said it supports the government’s goal of modernising privacy laws but considers that the reforms in the current draft would “benefit from further clarification of how the new principles-based standards are intended to interact with the extensive, preexisting regulatory obligations that already govern the collection, use, disclosure and retention of client information in fields such as financial advice.
“Without this clarity, there is a real risk of unnecessary regulatory duplication and uncertainty, without a commensurate improvement in privacy outcomes for clients.”










Leave a Comment
You must be logged in to post a comment.