Catagory:Privacy, Data Protection & Information Management

1
“Breaches Will Occur. Preparedness Helps You Contain Them”: Five Eyes Releases Statement on AI and Cyber Risk
2
Capture the Flag, Capture the Company Data
3
OAIC Publishes Updated Guidance on Facial Recognition Technology for Australia
4
EU-US Data Privacy Framework Under the Spotlight Following FTC Independence Ruling
5
EU Digital Omnibus on AI Enters Into Force
6
An AFS Licensee First: Receiving an Order to Pay AU$2.5 Million for Cybersecurity Failures
7
Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology
8
Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep
9
Australian Clinical Labs fined AU$5.8 Million for 2022 Medlab Data Breach in an Australian First
10
New Zealand Privacy Law Amendment Act Passes

“Breaches Will Occur. Preparedness Helps You Contain Them”: Five Eyes Releases Statement on AI and Cyber Risk

By: Cameron AbbottDaniel KnightRob Pulham and Emre Cakmakcioglu

Western intelligence alliance Five Eyes has issued a strong warning to business leaders: AI-driven transformation of cyber risk is already here, and the time to act is now.

Read More

Capture the Flag, Capture the Company Data

By: Cameron Abbott, Daniel Knight, Rob Pulham and Emre Cakmakcioglu

Mere days after an AI firm’s model hacked into Hugging Face, a separate AI company has now revealed that three of its models have hacked into three external companies during testing.

Read More

OAIC Publishes Updated Guidance on Facial Recognition Technology for Australia

By: Cameron Abbott, Rob Pulham, and Emre Cakmakcioglu

The Office of the Australian Information Commissioner (OAIC) has published updated guidance for entities considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces, like retail shopfronts.

Read More

EU-US Data Privacy Framework Under the Spotlight Following FTC Independence Ruling

By: Sarah Pearce and Sophie Verstraeten

The European Data Protection Board (EDPB) has called on the European Commission to assess the implications of the recent US Supreme Court decision in Trump v. Slaughter for the EU-US Data Privacy Framework (DPF), the mechanism that facilitates transfers of personal data between the EU and participating US organisations.

Read More

EU Digital Omnibus on AI Enters Into Force

By: Sarah Pearce and Thomas Nietsch

The EU has adopted its first substantive amendment to the AI Act. Regulation (EU) 2026/1744, commonly referred to as the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. While the legislation postpones certain aspects of the AI Act’s compliance timetable, it would be a mistake for organisations to view the Omnibus as a broad pause on AI regulation in Europe.

Read More

An AFS Licensee First: Receiving an Order to Pay AU$2.5 Million for Cybersecurity Failures

By: Cameron Abbott, Daniel Knight, Rob Pulham, Alex Parker, Madison Jeffreys, Emre Cakmakcioglu and Annaliese Filippis

In a key decision against an Australian financial services licence (AFSL) holder, the Federal Court of Australia has ordered the AFSL holder to pay AU$2.5 million in penalties for inadequate cybersecurity measures. The Australian Securities and Investments Commission (ASIC) took action following a cyberattack on the AFSL holder’s IT systems, resulting in approximately 385GB of data being downloaded from its servers. 

Read More

Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology

By: Cameron Abbott and Rob Pulham

The Administrative Review Tribunal of Australia (Tribunal) has partially overturned the findings of the Privacy Commissioner on Bunnings’ use of facial recognition technology (FRT) in its stores.

Read More

Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep

By: Rob Pulham, Cameron Abbott, and Annaliese Filippis (Graduate, Melbourne)

The Office of the Australian Information Commissioner (OAIC), Australia’s privacy regulator, is conducting its first ever privacy compliance sweep, as of this January. The compliance sweep will include a review of the privacy policies of businesses that collect information in person.

Read More

Australian Clinical Labs fined AU$5.8 Million for 2022 Medlab Data Breach in an Australian First

By Cameron Abbott, Rob Pulham and Stephanie Mayhew

The Federal Court has ordered Australian Clinical Labs (ACL) to pay AU$5.8 million in civil penalties following a 2022 data breach involving its then-newly acquired Medlab Pathology business. The breach affected over 223,000 individuals whose data was accessed and infiltrated by malicious actors and is one of Australia’s most significant healthcare cyber incidents.

Read More

Copyright © 2026, K&L Gates LLP. All Rights Reserved.