Regu Report
Monday, October 6, 2025
  • Finance
    • Financial Services
    • Insurance
    • Superannuation
    • Economy
    • Productivity
  • Legal
    • Competition
    • Privacy
    • Intellectual Property
    • Employment & Workplace Relations
    • Communications
    • Human Rights
    • Law Reform
  • Corporate
  • Property
  • Science
    • Environment
    • Technology
  • Agriculture
  • Transport
  • Sport
No Result
View All Result
  • Finance
    • Financial Services
    • Insurance
    • Superannuation
    • Economy
    • Productivity
  • Legal
    • Competition
    • Privacy
    • Intellectual Property
    • Employment & Workplace Relations
    • Communications
    • Human Rights
    • Law Reform
  • Corporate
  • Property
  • Science
    • Environment
    • Technology
  • Agriculture
  • Transport
  • Sport
No Result
View All Result
Regu Report
No Result
View All Result
Home Legal

OAIC approves Oxfam Australia’s enforceable undertaking

Tony Lee by Tony Lee
27 August 2025
in Legal, Privacy
Reading Time: 2 mins read
0
12
SHARES
105
VIEWS
Share on LinkedInShare on FacebookShare on X

Privacy Commissioner Carly Kind has accepted an enforceable undertaking (EU) from Oxfam Australia following a significant data breach that took place in January 2021. The breach, discovered and reported to the Office of the Australian Information Commissioner (OAIC) by Oxfam in February 2021, resulted in the loss of up to 1.7 million records.

While the acceptance of the EU does not constitute a finding that Oxfam violated the Privacy Act or the Australian Privacy Principles, it underscores the imperative for charities and not-for-profits to maintain rigorous privacy practices.

RELATED POSTS

Beacon Minerals insider trading: Darryl Mapleson sentenced

Australia and New Zealand information access commissioners (AIAC) issue communiqué, 2–3 October 2025

Oxfam has outlined a comprehensive set of measures in the EU. These include not storing personal information for longer than seven years, implementing password security controls, avoiding the use of shared credentials, and enhancing staff training and procedures. The not-for-profit has also committed to using privacy threshold assessments for projects involving personal information.

Throughout the investigation period, Oxfam has collaborated closely with the OAIC and has launched an awareness campaign aimed at other organisations within the not-for-profit sector to share insights from the breach and its subsequent response.

The OAIC has leveraged lessons from its investigation into Oxfam’s experience, as well as a separate data breach involving telemarketing firm Pareto, to update its guidance for not-for-profits. The revised guidance, released in October 2024, provides expanded advice regarding information security and compliance with retention and destruction obligations.

A timeline of key events surrounding the data breach illustrates a series of immediate responses from Oxfam, including notifying the OAIC and the Australian Cyber Security Centre, as well as alerting supporters about the potential risks associated with their personal information.

The incident serves as a critical reminder for not-for-profits about their obligations under the Privacy Act. Key points highlighted in the guidance stress the importance of collecting only necessary personal information, ensuring its secure storage, and having a robust data breach response plan in place. Additionally, when engaging with third-party providers, not-for-profits are encouraged to ensure that those providers adhere to acceptable privacy practices.

For further insights and guidance specific to not-for-profits, Commissioner Kind has shared her perspectives in a blog post available on the OAIC website.

Tags: Australian Cyber Security CentreAustralian Information CommissionerAustralian Privacy PrinciplesCarly KindData BreachEnforceable UndertakingOAICPersonal InformationPrivacy
Share1Share5Tweet3ShareSend
Tony Lee

Tony Lee

Tony Lee is a senior journalist reporting on data, privacy, security and compliance. He is interested in how technology, regulation and consumer rights intersect in an increasingly digital world.

Related Posts

Federal Court extends asset freeze on First Mutual Private Equity and director Gregory Cotton to safeguard investor funds

Beacon Minerals insider trading: Darryl Mapleson sentenced

by Maddie Crawley
4 October 2025
0

Geological services provider Darryl Brian Mapleson has been sentenced to 12 months’ imprisonment for insider trading, with the Supreme Court...

Australia and New Zealand information access commissioners (AIAC) issue communiqué, 2–3 October 2025

Australia and New Zealand information access commissioners (AIAC) issue communiqué, 2–3 October 2025

by Tony Lee
3 October 2025
0

Australia’s information watchdogs have urged public sector leaders to treat access to information as a cornerstone of innovation, environmental sustainability...

ACCC clears acquisition of BGC Cementitious after changes to deal

Telstra fined $18 million for misleading Belong customers about broadband speeds

by Catarina Brooks
3 October 2025
0

The Federal Court has ordered Telstra to pay an $18 million penalty after the company moved almost 9,000 Belong customers...

Federal Court extends asset freeze on First Mutual Private Equity and director Gregory Cotton to safeguard investor funds

ASIC cancels Velos Global Markets’ financial services licence

by Maddie Crawley
3 October 2025
0

The corporate regulator has cancelled the Australian Financial Services licence of Velos Global Markets Pty Ltd (ACN 604 251 416),...

Queensland potato farm hit with penalties for unlawfully docking visa workers' pay

Sydney valet parking operator to face court

by Elena Marlowe
2 October 2025
0

The Fair Work Ombudsman has launched court proceedings against the operator of a Sydney valet parking business over an alleged...

Next Post
New dashboard enhances accessibility of Australian FOI data

New dashboard enhances accessibility of Australian FOI data

ASIC unveils plan to counter threats across the financial ecosystem

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED

CSIRO launches R&D program for critical minerals SMEs

CSIRO launches R&D program for critical minerals SMEs

4 October 2025
Federal Court extends asset freeze on First Mutual Private Equity and director Gregory Cotton to safeguard investor funds

ASIC wins travel ban and asset freeze in First Guardian probe

4 October 2025
  • 100 Followers

MOST VIEWED

  • Glass repair operators hit with $116,550 in penalties

    12 shares
    Share 5 Tweet 3
  • TAB hit with $4m penalty for spamming VIP customers

    12 shares
    Share 5 Tweet 3
  • Western Sydney café’s former operators appear in court

    12 shares
    Share 5 Tweet 3
  • Power bank recalls surge amid reports of severe burns and property damage

    12 shares
    Share 5 Tweet 3
  • Home values up 1.9% in June

    12 shares
    Share 5 Tweet 3
Regu Report

Bringing you the latest news from the world of regulation, compliance, corporate governance and industry in Australia.

TOPICS

  • Agriculture
  • Communications
  • Competition
  • Corporate
  • Economy
  • Employment & Workplace Relations
  • Environment
  • Finance
  • Financial Services
  • Human Rights
  • Insurance
  • Law Reform
  • Legal
  • Privacy
  • Property
  • Science
  • Superannuation
  • Technology

INFORMATION

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us

© 2025 Regu Report.

No Result
View All Result
  • Homepages
    • Homepage Layout 1
    • Homepage Layout 2

© 2025 Regu Report.