• Menu
  • Skip to right header navigation
  • Skip to primary navigation
  • Skip to secondary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Before Header

Call us now  07 4688 2188

  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Clifford Gouldson Lawyers

  • About
    • Our Origin Story
    • Our Future
    • Toowoomba
    • Brisbane
    • Sunshine Coast
    • What our clients say!
  • Careers
  • Supporting our Community
    • Bringing art to the business world
  • Contact Us
  • Search
  • About
    • Our Origin Story
    • Our Future
    • Toowoomba
    • Brisbane
    • Sunshine Coast
    • What our clients say!
  • Careers
  • Supporting our Community
    • Bringing art to the business world
  • Contact Us
  • Search

Mobile Menu

  • Our Team
  • Practice Areas
  • Knowledge
  • Events
  • Industries
  • For Individuals
  • Facebook
  • LinkedIn
  • Twitter
  • YouTube
  • Our Team
  • Practice Areas
  • Knowledge
  • Events
  • Industries
  • For Individuals

Medibank’s mistake is a privacy lesson for all businesses

You are here: Home / News / Medibank’s mistake is a privacy lesson for all businesses

Anyone impacted by the cyber attack on Medibank Private Limited between August and October 2022 will be familiar with the importance of privacy laws in Australia.

And for businesses, both small and large, it’s a good lesson in the importance of keeping your privacy and cyber security compliance standards high.  

The Australian Information Commissioner has recently filed an application in the Federal Court against Medibank in relation to the October 2022 data breach, following an investigation by the Commissioner, after the personal and sensitive information of 9.7 million Australians was stolen and released on the dark web.

The Commissioner alleges that Medibank seriously interfered with the privacy of 9.7 million Australians, exposing them to the likelihood of serious harm, including potential emotional distress, and risk of identity theft, extortion and financial crime.  

Privacy law in Australia

Privacy in Australia is regulated under the Commonwealth Privacy Act 1988, and separate privacy and information legislation in each state and territory.

This legislation governs standards, rights and obligations related to how personal information is collected, used and disclosed. You can learn more about the specifics of the Privacy Act here.

Who does it apply to?

The Privacy Act applies to Australian Government agencies and to organisations with an annual turnover of more than $3 million, which can include a body corporate, a trust, a partnership, an unincorporated association, or a sole trader/individual.

However, some small businesses (with an annual turnover of $3 million or less) are also covered if they operate in the health or financial services sectors, or trade in personal information.

Previously, only companies with an Australian link had responsibilities under the Privacy Act, however, changes made in December 2022 mean that any foreign entity carrying on a business in Australia will be covered under the Privacy Act if they meet the other requirements.

Potential penalties are high!

Following changes in December 2022 the potential penalties for breaches under the Privacy Act have increased significantly. The Federal Court is now empowered to fine a company in breach of the Act:

  • $50 million (up from $2.2million);
  • Three times the value of benefits obtained or attributable to the breach (if this can be determined); or
  • 30% of the company’s adjusted turnover during the breach turnover period.
  • A court may also order an infringement notice, an enforceable undertaking, or award an injunction for a breach of the Privacy Act.

What now for Medibank?

The good news for Medibank is that their cyber attack and data breach occurred prior to the increased penalties coming into place. We’ll be keeping an eye on the Federal Court to see how the matter progresses and will provide updates on anything that may prove valuable for other businesses.

Please contact our Intellectual Property Team if you have any concerns about how the privacy rules may apply in your business and whether you are ensuring your business complies with its obligations.


For further information please contact Ben Gouldson.

The assistance of Amelia Bourke Legal Assistant in researching this article is gratefully acknowledged.

Previous Post: « IP Australia Revises its Fees
Next Post: Government sets policy for its use of AI »

Primary Sidebar

We can help

Ben Gouldson

Managing Director and Trade Marks Attorney*

Melanie Sharpe

Lawyer

Nicola Hayden

Lawyer and Trade Marks Attorney*

Brooke Giblin

Legal Secretary & Personal Assistant

Related Alerts

April 9, 2025
Yes, crypto currency is personal property!

The legal system has taken some time to come to grips with crypto currency,...

Privacy & AI: How much does your AI know?

There have been a number of changes to Australia’s privacy laws recently and businesses...

March 5, 2025
Recent Decision on Copyright Infringement: a Puff Piece

In December 2024, the Federal Court of Australia handed down a judgment on a...

View other alerts

Footer

Clifford Gouldson Lawyers

CLIFFORD GOULDSON LAWYERS
P: 07 4688 2188
F: 07 4688 2199
mail@cglaw.com.au
  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Locations

TOOWOOMBA (Head Office)
259 Ruthven Street,
Toowoomba Q 4350

PO Box 8208,
Toowoomba South Q 4350

Toowoomba Office

BRISBANE
Level 5, 231 George Street,
Brisbane Q 4000

PO Box 12802 George Street,
Brisbane Q 4003

Brisbane Office

 

SUNSHINE COAST
Regatta Corporate Building, Office 3,
Ground Floor, Innovation Parkway,
Birtinya Q 4575

Locked Bag 5010
Caloundra DC Q 4551

Sunshine Coast Office

Practice Areas

  • Property + Business Transactions
  • Workplace
  • Litigation + Dispute Resolution
  • Intellectual Property + Technology
  • Wills, Estates, Planning + Structuring
  • Business + Corporate Advisory
  • Construction
  • Privacy & Disclaimer
  • Terms of Use

Site Footer

CG Law (Trading) Pty Ltd ACN 143 426 028 t/a Clifford Gouldson Lawyers ABN 89 143 426 028 Liability limited by a scheme approved under professional standards legislation.

The contents of this website are provided solely for general information purposes and do not constitute legal or other professional advice. Clifford Gouldson Lawyers expressly disclaims any liability arising from the use or reliance on the information provided. If you require legal or other expert advice or assistance, then you should seek our help or the services of a qualified professional.

Copyright © 2025 Clifford Gouldson Lawyers · Privacy & Disclaimer · Terms of Use · Marketing by John Gray Marketing · Site by Kingfisher