Statutory Tort for Serious Invasion of Privacy Now in Force

Statutory Tort for Serious Invasion of Privacy Now in Force

Home » Intellectual Property & Technology

Statutory Tort for Serious Invasion of Privacy Now in Force

}

5 min read

18 Jun 2025

Share:

  • r
    Key Takeaways
  • A new statutory tort for serious invasions of privacy commenced on 10 June 2025
  • Individuals can bring an action against another person for intruding upon their seclusion and/or misusing their information
  • Available remedies include damages, injunctions, an order to apologise, and an order to destroy material obtained through the invasion of privacy
  • Journalists are largely exempt

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

A tort is a civil wrong wherein one party causes loss or harm to another. A cause of action in tort allows the affected party to sue the wrongdoer for damages or other relief.  Whether an action in tort for invasion of privacy exists in Australia has been a topic of contention since the early 2000s.

A new suite of privacy law reforms, contained in the Privacy and Other Legislation Amendment Act 2024 (Cth) (the Act) is being rolled out across the year and brings an end to this uncertainty. On 10 June 2025 a new statutory tort for serious invasions of privacy came into effect.

The Act states that the purpose of these provisions is to:

  • establish a cause of action for serious invasions of privacy;
  • provide for defences, remedies and exemptions;
  • recognise that the protection of privacy is a public interest to be balanced with other public interests; and
  • implement Australia’s international obligations in relation to privacy, specifically under the International Covenant on Civil and Political Rights.

Cause of Action

Under the Act, an individual now has a cause of action in tort against another person where:

(a)        their privacy has been invaded by:
          (i) an intrusion into their seclusion; or
          (ii) the misuse of information relating to them; and

(b)        a person in their position would reasonably have expected privacy in all the circumstances; and
(c)        the invasion of privacy was intentional or reckless; and
(d)        the invasion of privacy was serious; and
(e)        the public interest in the individual’s privacy outweighed any countervailing public interest.

It is not necessary to prove damage for an invasion of privacy to be actionable.

Defences

Some defences include:

(a)        the invasion of privacy was required by law;

(b)        the individual consented to the invasion of privacy; or

(c)        the defendant reasonably believed the invasion of privacy was necessary to prevent or lessen a serious threat to the life, health or safety of a person.

 

Remedies

If it finds that a serious invasion of privacy has occurred, a court may grant one or more of the following remedies:

(a)        an award of damages up to the greater of $478,550, and the maximum amount of damages for non‑economic loss that may be awarded in defamation proceedings in Australia;

(b)        an account of profits;

(c)        an injunction;

(d)        an order requiring the defendant to apologise to the plaintiff;

(e)        a correction order;

(f)        an order:

          (i) that any material (including copies) that is in the defendant’s possession or that the defendant is able to retrieve; and

          (ii) that was obtained or made as a result of the invasion of privacy or was misused during the course of the invasion of privacy;

          be destroyed, be delivered up to the plaintiff or be dealt with as the court directs.

 

(g)        a declaration that the defendant has seriously invaded the plaintiff’s privacy.

 

Exemptions

Notably, an exemption is provided for journalists and other related parties if the invasion of privacy occurs in the collection, preparation for publication or publication of journalistic material.

Application in Other Jurisdictions

Similar torts of privacy have been recognised to varying degrees in the USA, UK and New Zealand, and provide insight into the types of claims that may arise under this new statutory tort. ALRC Report 123 Serious Invasions of Privacy in the Digital Era, published 15 July 2014 (Report), discusses several cases where plaintiffs have successfully sued for invasion of privacy in those jurisdictions.  

In the New Zealand case of C v Holland [2012] 3 NZLR 672, the courts first recognised the existence of a tort of invasion of privacy in New Zealand.  The case involved a man who secretly installed a video camera and recorded his flatmate while she was showering.

According to the Report, intrusion upon seclusion has been found to include not only entry into physical spaces but also ‘watching, listening to, or recording someone’s private activities or private affairs.’ Specific examples include ‘taking a photo of someone in a change room, reading their bank statements, tapping their phone calls, or hacking into their computer.’

The Report notes that, in the USA intrusion upon seclusion cases have typically focused on how private information is obtained, rather than the publication of that information.

Examples of misuse of information, as identified in the Report, include ‘publishing a person’s medical records in a newspaper or posting sexually explicit photographs of someone on the internet, without their permission.’

Conclusion

This new statutory cause of action ends longstanding uncertainty about the existence of a tort for serious invasion of privacy in Australia. It will be important to watch how the case law develops, and we will continue to provide updates as it does.

If you are unsure about your obligations under the new privacy reforms – or your privacy obligations broadly – please contact Craig Hong or John Davies on (07) 3220 1144 or via email: craig@hillhouse.com.au.

Rising Threat of Sophisticated Intellectual Property Scams

Rising Threat of Sophisticated Intellectual Property Scams

Home » Intellectual Property & Technology

Rising Threat of Sophisticated Intellectual Property Scams

}

3 min read

25 Mar 2025

Share:

  • r
    Key Takeaways
  • Scams relating to IP rights and particularly Trade Marks are increasing and becoming more sophisticated aiming to manipulate businesses into making payments or revealing personal or sensitive information.
  • Always exercise a degree of caution when receiving letters or emails from unknown firms or departments relating to your IP.
  • To stay safe, contact your trusted legal adviser if you are unsure as to the authenticity of any correspondence, or wish to register, or renew Trade Marks and other IP rights.

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

As we enter the new year, businesses are seeing a concerning rise in the sophistication of scams targeting Intellectual Property (IP) rights.

This article serves as a reminder for businesses to stay vigilant against these emerging scams and offers practical guidance on how to identify and deal with them.

The Increasing Threat: How Scams Are Being Presented

It is becoming increasingly common for businesses with registered IP, such as Trade Marks, to receive unsolicited emails from firms offering IP services. These emails often exploit the fact that contact details for registered IP holders are publicly available through IP Australia’s Trade Mark search register.

These communications typically urge businesses to pay for Trade Mark renewal services, often creating a false sense of urgency. While legitimate IP practitioners may use publicly available registers to find new clients or remind businesses of upcoming deadlines, the cost of such services can often be inflated and subject to negotiation.

However, scammers are also targeting these public registers, particularly focusing on new Trade Mark applications or existing registrations nearing important dates, such as renewals. Recently, we’ve seen more sophisticated scams where fraudsters impersonate government agencies or established legal firms, a trend that IP Australia has flagged as a growing concern (Scams related to managing IP Rights, IP Australia).

link: https://ipaustralia.gov.au/about-us/doing-business-with-us/fraud-and-corruption/scams-related-to-managing-ip-rights

Recognising Scam Red Flags

A recent example of a scam involved an individual posing as an IP practitioner, claiming they had been contacted by a third party to file a Trade Mark application. The scammer then offered to file an urgent Trade Mark application for the business – threatening to file the application on behalf of the third party if the business didn’t act quickly. The email also included threats of legal action and cease and desist orders if the business did not pay for IP services.

Common warning signs of IP-related scams include:

  • False or misleading information
  • Documents with watermarks designed to impersonate government bodies or law firms
  • Urgent requests for action, such as filing a Trade Mark application or paying an inflated invoice

Scammers often target businesses during key periods, such as when new IP rights are being filed or when renewals are approaching. Businesses should be especially cautious during these times.

How to Protect Your Business

If you receive a suspicious email, follow these steps to safeguard your business:

  1. Do not respond to unsolicited communications without first verifying the sender. A simple Google search of the claimed firm or checking the IP Australia Trade Mark register can help confirm the legitimacy of the message.
  2. Consult your trusted legal adviser or an official source if you have doubts about any correspondence concerning IP rights.
  3. Be cautious when considering overseas legal services in relation to IP matters, as some scams involve services from international firms.
  4. Exercise caution – always verify before responding to any requests or paying invoices.
  5. Contact your IP solicitor if you’re unsure whether an email is a scam. They can help confirm if the correspondence is legitimate.

How We Can Help

At Hillhouse Legal Partners, we’re here to help you navigate and protect your intellectual property. Whether you have questions about your IP rights, need professional guidance with applications, or are due for a renewal, we’ve got you covered. Reach out today to Zach Sudiro, John Davies, or Craig Hong.  We’re here to provide the support you need to keep your business safe and thriving.

New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

Home » Intellectual Property & Technology

New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

}

10 min read

14 Nov 2024

Share:

  • r
    Key Takeaways
  • Recent guidance on Australian privacy laws in the context of AI systems shows that there are many complex issues, and careful controls are necessary to protect businesses from fines and reputational damage.
  • Businesses using AI to make decisions, or as part of important or high-risk work, should be especially careful and should consider blanket prohibitions.
  • Even seemingly innocent uses (e.g., using AI systems to take meeting notes, or as a chatbot to talk to customers) are high risk activities to be done carefully (if at all).

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

Businesses should take careful note of the risks of using artificial intelligence (AI) and should implement controls appropriate to their business to ensure use is careful or prohibited.

A breach of Australian privacy law (for example, the Privacy Act 1988 (the Act) may result in significant fines or reputational damage. Given the recency of AI commercialisation, businesses should be especially careful about their compliance when using AI systems as enough time has not passed for best practice steps to develop.

Ensuring sufficient controls (or ensuring prohibition) is especially important where the AI is exposed to personal information, makes decisions for a business (e.g., reviewing and sorting resumes), or is engaging in impactful work (e.g., drafting court material).

As a general comment, it should also be understood that AI systems are often wrong and that their output should be thoroughly factchecked to confirm accuracy.

Best practice will be to not input personal information (especially not sensitive information) into publicly available AI tools, or indeed any AI system unless appropriate safeguards and restrictions are in place.

OAIC Guidance

The Office of the Australian Information Commissioner (OAIC) has issued guidance regarding the deployment of AI systems within an organisation subject to the Privacy Act (APP Entity) to provide a product or service, particularly in the context of generative AI (OAIC AI Guidance).

This guidance is crucial as AI systems are highly complicated and carry numerous complex privacy risks.

We urge all businesses contemplating the use of AI in their business to read the OAIC’s AI Guidance in detail and particularly note the included checklists before undertaking any use of an AI System.

This article does not propose to summarise or repeat the OAIC’s AI Guidance in detail, however a number of key takeaways should be emphasised.

Due Diligence

Prior to use of any AI system, due diligence will be critical, you must understand:

  1. the terms and conditions for the use of the AI system;
  2. how the AI system has been trained and what information it was trained on;
  3. how the AI system will treat the information included in prompts (e.g., is it used to train the AI in future, is it saved locally or remotely);
  4. whether any information included in a prompt will be accessible by publisher of the system (if so, use of the AI system may constitute a disclosure of personal information which is subject to further rules than a use of personal information);
  5. how the AI system is protected from data breaches; and
  6. whether there have been previous data breaches.

You should regularly check and confirm whether any changes occur in respect of the above during the use of the AI system.

Use of Personal and Sensitive Information in AI Systems

Your privacy policy must clearly state how your business uses AI. In some circumstances e.g., where an AI is used to take meeting notes, this will likely be insufficient on its own and the meeting participants should be given an opportunity to opt out.

APP Entities are required by Australian Privacy Principal 6 to only use or disclose personal information for a particular purpose if the information was obtained for that purpose. There are exceptions that permit a use or disclosure for a secondary purpose (e.g., if consent from the individual was obtained). One such exception is where the individual would reasonably expect the APP Entity to use or disclose the information for that secondary purpose if that purpose is related to the primary purpose (or directly related if the information is sensitive information).

The OAIC Guidance relevantly provides that “[i]f your organisation cannot clearly establish that a secondary use for an AI-related purpose was within reasonable expectations and related to the primary purpose, to avoid regulatory risk you should seek consent for that use and/or offer individuals a meaningful and informed ability to opt-out. Importantly, you should only use or disclose the minimum amount of personal information sufficient for the secondary purpose.”

Controls

Prior to using an AI system, a business should consider the worst case scenario, as some AI systems are black boxes and their “reasoning” cannot be extracted and examined. E.g., the OAIC AI Guidance notes that using AI in recruitment could discriminate against candidates based on perceived biases. For this reason, any commercial use of an AI System should include sufficient controls to analyse and manage risks associated with the black box nature of the software.

These controls are discussed in further detail below in our commentary on a recent report by the OVIC.

Businesses which permit the internal use of AI should perform a privacy impact assessment, implement an AI policy containing express requirements for the use of AI systems, and undertake regular staff training on the use of AI.

Generation of personal Information

You should consider that AI systems are trained on a wide range of information, which means they are capable of generating personal information. The OAIC AI Guidance references an example where workplace psychosocial hazard training was partially created with AI and the AI generated a real situation using the real names of the persons involved (who were involved in an ongoing court matter at the time). This event may be considered collecting personal information under the Act and the information collected would need to be treated accordingly as unsolicited personal information.

Meeting minute making

While seemingly innocuous, the risks of using an AI system to record a meeting are substantial – meetings can veer off topic, in which case any personal and sensitive information discussed may well be information the business is not permitted to collect. In that case, that information should be erased or deidentified. Without proper systems in place, this can be easily overlooked from time to time.

AI and images

You also need to be aware that any images generated by an AI may copy part (or all) of an image it was trained on. Such generated images may reproduce personal or sensitive information and may breach copyright laws.

Uploading of images to AI systems should generally be avoided even where no personal or sensitive information is apparent, as the image may contain metadata or sufficient information to identify a location or other personal information may be present to identify a location.

Chatbots

Our view is that any business seeking to use an AI chatbot should seek legal advice beforehand as such activity may result in collection of improper personal and sensitive information. Chatbots also raise particular risks regarding Australian Privacy Principal 10 (ensuring the accuracy of personal information collected) and Australian Privacy Principal 3 which requires that unless unreasonable or impractical to do so, personal information must be collected from the individual directly.

OVIC decision

A deputy Commissioner of the OVIC recently performed an investigation into the use by a child protection worker (the Worker) employed in the Victorian Department of Families, Fairness and Housing (DFFH).

This example is an illustrative example of what controls may or may not be sufficient to guard against the risks of using AI systems.

Conduct

In this example, the Worker used ChatGPT to assist in the drafting of a protection application report, which is submitted to the Children’s Court to assist the court in deciding whether a child needs protection.

The use by ChatGPT of the Worker was plainly inappropriate and dangerous as “the Protection Application Report mistakenly described a child’s doll, that was used by the child’s father for sexual purposes, as a mitigating factor, in that the parents had provided the child with “age appropriate toys””.[1]

Of some interest is the 9 factors identified by the DFFH in their investigation which indicated ChatGPT involvement:[2]

  1. sophisticated language;
  2. overly positive descriptors;
  3. inaccurate information;
  4. unusual content;
  5. unusual terminology;
  6. unusual reference to legal intervention;
  7. unusual Child Protection intervention;
  8. nonsensical references; and
  9. American spelling and/or phrasing.

Any business that, as part of its AI controls, audits work for evidence of AI use, should take note of these examples.

Breach

It was determined that this conduct constituted a breach of Information Privacy Principals 3.1 and 4.1.

Information Privacy Principal 3.1

An organisation must take reasonable steps to make sure that the personal information it collects, uses or discloses is accurate, complete and up to date.

Information Privacy Principal 4.1

An organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.

Controls

The DFFH had the following controls in place at the time of the conduct:

  1. “an acceptable Use of Technology Policy;
  2. eLearning modules on privacy awareness and security awareness;
  3. the DFFH values;
  4. the VPS code of conduct;
  5. Human Rights legislation and associated eLearning module;
  6. communications to leadership and management by way of three education sessions in May 2023 that referred to data security, privacy and other risks associated with GenAI.”[3]

The OVIC decided that these controls were insufficient and there was a need to train all employees, not only management staff.[4]

Since the conduct took place the DFFH created specific “Generative Artificial Intelligence Guidance” (which was circulated on several instances to all DFFH staff), which included two “critical rules”:

  1. “Employees should be able to explain, justify and take ownership of their advice and decisions;”[5] and
  • “Employees should assume that any information they input into public GenAI tools could become public. They must not input anything that could reveal classified, personal or otherwise sensitive information.”[6]

However, the report noted that:

  1. “DFFH has almost no visibility on how GenAI tools are being used by staff. It has no way of ascertaining whether personal information is being entered into GenAI tools and how GenAI-generated content is being applied. Further, as is always the case with policy and guidance, there is no way of guaranteeing that all staff will properly read, understand, and apply these.” [7]
  • “The risks of harm from using GenAI tools are too great to be managed by policy and guidance alone. At present, there are insufficient controls in place regarding staff access to GenAI tools coupled with a lack of assurance capabilities to verify that such use is appropriate. In other words, these controls are insufficient to prevent a re-occurrence of incidents like the PA Report incident.”[8]

Decision

The OVIC decided to issue a compliance notice, with 6 specified actions required (some of which DFFH can apply to amend), including:

  1. DFFH must direct child protection staff to not use any generative AI tools as part of their duties;
  2. DFFH must block access to 15 specified generative AI tools between 5 November 2024 and 5 November 2026;
  3. DFFH must between 5 November 2024 and 5 November 2026 “implement and maintain a program to regularly scan for web-based or external” generative AI tools similar to those directed to be blocked; and
  4. “DFFH must implement and maintain controls to prevent Child Protection staff from using Microsoft365 Copilot” between 5 November 2024 and 5 November 2026.[9]

Takeaway

Businesses which handle important or high risk personal information should be on notice they may not be able to implement sufficient controls around AI systems to prevent breaches of Australian privacy laws and should consider blanket prohibitions to avoid fines or reputational damage.

Hillhouse Legal Partners can assist if you have any questions about treatment of personal or sensitive information, you require the preparation of a privacy policy, or you have experienced a data breach. Feel free to reach out to John Davies, Lawyer or Craig Hong, Director to discuss.


[1] Office of the Victorian Information Commissioner, Investigation into the use of ChatGPT by a Child Protection Worker, available: https://ovic.vic.gov.au/wp-content/uploads/2024/09/DFFH-ChatGPT-investigation-report-20240924.pdf p5.

[2] Ibid p21.

[3] Ibid p23.

[4] Ibid p24 – 25.

[5] Ibid p26.

[6] Ibid p26.

[7] Ibid p28.

[8] Ibid p28.

[9] Ibid p29-30.

New Privacy Law Guidance about AI Highlights the Need for a Cautious Approach

Are You on Top of Your Practice’s Privacy Law Obligations?

Home » Intellectual Property & Technology

Are You on Top of Your Practice’s Privacy Law Obligations?

Authors: Craig Hong

}

5 min read

28 Oct 2024

Share:

  • r
    Key Takeaways
  • Understanding Privacy Obligations: Staff in medical practices must be knowledgeable about privacy laws to manage personal and sensitive information responsibly, safeguarding the practice against reputational damage and potential penalties.
  • Data Collection and Storage Compliance: The "Privacy Act 1988" (Cth) mandates that APP Entities, such as medical practices, gather personal information only with consent, protect it rigorously, and follow strict protocols for destroying or de-identifying data when no longer needed.
  • Breach Notification Procedures: In the event of a data breach, medical practices are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals promptly, unless actions are taken to prevent serious harm.

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

Privacy law is constantly evolving, and it is crucial for all staff working in a medical practice to understand their legal obligations to ensure personal and sensitive information is appropriately collected, used, and stored, to protect their practice from reputational damage and costly penalties.

In this article, we cover privacy requirements, breach protocols, and safe data collection and storage to help you navigate this complex area.

What information is regulated?

In Australia, any data that is “personal information” falls within the scope of Australia’s privacy law framework. Personal information is defined as ‘information or an opinion about an identified individual, or an individual who is reasonably identifiable.’ This can include a person’s:

  1. name;
  2. phone numbers;
  3. drivers licence details;
  4. health information; and
  5. religious beliefs.

Sensitive information, which includes medical information, is subject to more strict requirements than other personal information and greater care should be taken with this information.

The Privacy Act 1988 (Cth) sets out requirements surrounding personal information and sensitive information. All medical businesses must be compliant with this law.

What is a Privacy Policy?

Currently all medical businesses, and entities classified as an Australia Privacy Principle Entity (APP Entities) are required by law to have a privacy policy. This policy must be freely available, most commonly on a website, and must be tailored to reflect the operations and practices of the business.

A privacy policy informs third parties of:

  1. what personal information you collect;
  2. how that information is held;
  3. what you use that information for;
  4. whether you will disclose personal information to any overseas recipients; and
  5. other required matters.

Collection and Storage of personal information

The Privacy Act 1988 (Cth) includes a number of requirements around the collection and storage of personal and sensitive information. Unless an exemption applies, APP Entities should only collect personal and sensitive information with consent and only if collection of that information is reasonably necessary for or directly related to its functions or activities.

AAP Entities must take reasonable steps to ensure the personal information (including sensitive information) they hold is protected from misuse, interference, loss, unauthorised access, modification, and disclosure. Good data hygiene and regularly updated policies and procedures around collecting and storing personal information are necessary to ensure compliance.

An APP Entity is required to destroy or de-identify information when it holds personal information about an individual, and

  1. the business no longer needs the information for any purpose for which the information may be used or disclosed by the business under the Privacy Act;
  2. the information is not contained in a Commonwealth record; and
  3. the business is not required by or under an Australian law, or a court/tribunal order, to retain the information.

What do you do if there is a data breach?

APP Entities must notify the Office of the Australian Information Commissioner (OAIC) if they have reasonable grounds to suspect that an Eligible Data Breach has taken place. An Eligible Data Breach is where there is unauthorised access to, disclosure of, or loss of, personal information held by an APP Entity and such access, disclosure, or loss is likely to result in serious harm to individuals the information relates to.

Between July 2023 and December 2023 more than 20% of data breach notifications were made by Health Service Providers, more than double every other sector (Australian Government, 2024). It is vital for health and medical practices to have a carefully considered procedure in place for dealing with a data breach before it happens.

A report to the OAIC does not need to be made if the entity takes action which reasonably prevents the serious harm. This can include reaching out to any persons affected and informing them of the scope of the breach and what actions they should take to protect themselves. However, a decision not to report a data breach on this basis must be made carefully.

In the event of a data breach, the business must as soon as practicable provide a statement to the Privacy Commissioner sharing:

  1. the identity and contact details of the business;
  2. a description of the eligible data breach that the business has reasonable grounds to believe has happened;
  3. the particular information concerned;
  4. recommendations about the steps that individuals should take in response to the eligible data breach that the business has reasonable grounds to believe has happened; and
  5. any other required information.

(Data Breach Statement)

Businesses need to take reasonable steps to provide the information in the Data Breach Statement as soon as practicable after it is prepared:

  1. to either all individuals whose personal information was the subject of the data breach;
  2. to either all individuals who are at risk from the eligible data breach; or
  3. if neither option above is practicable, by publishing a copy of the Statement on its website and taking reasonable steps to publicise the contents of the Statement.

Next Steps

Ensuring you are compliant with privacy laws is a proactive and crucial step in safeguarding your business. 

We note that the Australian Government has recently introduced privacy reforms, to be implemented in tranches, focusing on enhancing the protection of personal information and establishing new privacy related offences. It is important that these be considered in addition to the current privacy compliance obligations.

We encourage you to seek professional legal advice around your practice’s needs with regard to privacy.

Hillhouse Legal Partners has extensive industry knowledge and expertise in the medical sector working with clients on these issues. To discuss your practice’s privacy requirements, please contact Craig Hong, Hillhouse Legal Partners, Director on (07) 3220 1144 or email craig@hillhouse.com.au.

References

Australian Government. (2024, February 22). Notifiable data breaches report July to December 2023. Retrieved from Australian Government Office of the Australian Information Commissioner

Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

Home » Intellectual Property & Technology

Privacy Awareness Week (6-12 May 2024) – What You Need To Consider

Author: John Davies

}

3 min read

8 May 2024

Share:

  • r
    Key Takeaways
  • Audit your business privacy practices.
  • Be aware that non-compliance with the Privacy Act carries significant reputation and financial risks.
  • Consider whether your businesses treats your client’s and/or customer’s personal information in a transparent, accountable, and secure way.

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

It’s Privacy Awareness Week (6-12 May 2024), which makes NOW a great time for businesses to review their privacy practices. 

The theme for PAW 2024 is “Power Up Your Privacy”. 

In line with this theme, the Office of the Australian Information Commissioner (OAIC), is urging businesses to:

  1. be transparent about how they handle personal information;
  2. be accountable for how they treat personal information; and
  3. securely hold personal information. 

The Australian Privacy Commissioner, Carly Kind has said “while individuals can all do our bit by having sound personal data practices, the biggest onus is on businesses and other organisations that hold data to make the right decisions to adequately protect and respect it, and not collect or keep what is not needed.” 

What happens if you don’t comply?

It is critically important that businesses covered by Privacy Act 1988 (Cth) (the Act) comply with the Act including all Australian Privacy Principles. Breach of the Act can incur significant financial penalties (potentially $50 million or more in fines) and reputational loss. 

If your business is covered by the Act (for example if it provides health services, or has an annual turnover of more than $3 million), PAW is a great opportunity to consider whether you are complying with best principle privacy practices. 

What should businesses consider?

Key privacy awareness action items to consider include:

  • Seek informed consent before collecting personal information;
  • Have an up to date and accurate privacy policy;
  • Ensure good housekeeping measures are in place to ensure unnecessary personal data is not being collected or stored;
  • Have a plan in place in the event of a data breach, including a plan to report that breach to the OAIC if required;
  • Staff trained appropriately on cybersecurity and privacy issues;
  • Systems in place to guard against bad actors and human error; and
  • Ensure outsourced handling of personal information to third parties is handled with care. 

Businesses can visit https://paw.gov.au/ to learn more about Privacy Awareness Week and access OAIC resources. 

Hillhouse Legal Partners can help you with questions relating to the treatment of personal or sensitive information, the preparation of a privacy policy, or if you have experienced a data breach how to manage this. 

Contact Craig Hong or John Davies to discuss your situation further.

The roles within your Will and Enduring Power of Attorney – Part 3 (Guardian)

The roles within your Will and Enduring Power of Attorney – Part 3 (Guardian)

Home » Intellectual Property & Technology

The roles within your Will and Enduring Power of Attorney – Part 3 (Guardian)

Author: Tracy Pratt

}

3 min read

27 Mar 2023

Share:

  • r
    Key Takeaways
  • The role of guardian is an extremely important role as they are appointed to be the substitute parent for your children.
  • Who you chose to be the guardian for your children is a very personal decision and should be made after consultation with the proposed guardian and potentially your children.
  • You can also establish various trusts within your estate for the benefit of your children and direct the management of those trusts to include appropriate contributions towards the upbringing of your children.

Stay Up-To-Date

Subscribe to receive updates specific to your preferences

In the third part of this series, we look at the role of the guardian in your Will.

The guardian’s role is to be the substitute parent for your children until they turn 18.

An alternate guardian may also be appointed to act if the first guardian cannot act or continue to act for any reason (e.g. due to death, incapacity or bankruptcy).

You should speak to any family and friends you are considering appointing as guardian/s and perhaps to your children, particularly if they are older.

As with the roles of the executor and trustee, the decision as to who you wish to be the guardian of your children in your Will is ultimately a very personal decision for you.  Your guardian should be a person you intimately trust with your children, who your children know, is usually related to you and is usually around your age as their role may last for up to 18 years.

While ultimately a matter for you, we recommend not appointing spouses as joint guardians. It is a sad fact that about 50% of marriages in Australia end in divorce and there may then be a custody battle over your children.

As we mentioned in the second part of this series, you may wish to give consideration as to whether the guardian should be someone different from the trustee, so that the trustee can offer some oversight on the guardian’s actions during what might be a long time (and vice versa).

You may also wish to consider directing the guardian caring for your infant children be paid a remuneration from the residue of your estate for the guardian’s time in the course of such care.

You can also direct via a Statement of Wishes and/or Guidelines for the Guardians, which are non-binding documents that give directions and wishes to your trustee and guardian about the upbringing of your children.  Apart from lifestyle, personal development and education decisions, you may wish for your children to remain in your home until the youngest of them reaches a certain age or for the guardian to either erect house extensions or to purchase a larger house in order to comfortably accommodate your children, with the trustee making an appropriate contribution from trust assets towards such extensions or purchase.

In the uncertain times today surrounding COVID-19, if your intended guardian resides overseas, you may also wish to particularly consider appointing a temporary guardian in Australia until such time as your permanent guardian is able to travel to Australia or your children are able to leave Australia to travel to the permanent guardian’s country.

These are all very personal decisions and we appreciate there is a lot to get through during the difficult task of administering and distributing an estate. We are professionals who have done this many times, and are happy to assist throughout the entire process to make it as easy as possible.

To discuss an estate plan for your individual circumstances, please contact Tracy Pratt, Lawyer from our Wills, Estates & Trusts team for a free initial consultation on 07 3220 1144 or email.

Areas of Expertise