With Australian Privacy Awareness Week taking place in May 2021, now feels like a good time to look back on the Office of the Australian Information Commissioner’s (OAIC) 2020 Australian Community Attitudes to Privacy Survey (ACAPS). ACAPS is a long-standing study designed to give a longitudinal picture of Australians' views on data privacy.
The previous survey was in 2017. Since that time, the 2020 survey results indicate individuals’ increasing awareness of data privacy and the desire to influence how organisations hold and use data. Certainly, something we suspected was the case is now backed up by the survey.
Key takeaways:
While the research and results are focused towards consumer attitudes, there is still a strong underlying message here for those of us managing and running SAP® environments in the enterprise. We see a strong increase in concern around identity theft and data breaches with a desire for requesting data deletion. When checking the 2017 report’s results, we found that personal data removal and deletion was not even discussed at the time. It is certainly of interest to see a topic not mentioned in the previous survey capture such strong feelings three years later.
In the report, Angelene Falk, Australian Information Commissioner and Privacy Commissioner, discusses the importance of the survey result as input to a review underway on the Australian Privacy Act 1988. Falk stated, “The Australian Government has also committed to a new system of fines and penalties for interference with privacy.”
The desire to think differently about data privacy in Australia is being acknowledged. Of course, it remains to be seen how far the community attitude shift in the survey will drive actual change to the Australian Privacy Act and associated penalties. Regardless, there will continue to be more focus on protecting data and reporting on data loss in the future.
I am reminded here of my colleagues' recent journey around GDPR awareness and compliance across Europe. The strong shift to personal data rights with GDPR’s introduction in 2018 sees not just scrambling of personal data on SAP test systems becoming de facto but also a requirement to locate and redact or remove personal data within production systems as a growing and key need. Three years on from GDPR coming into effect, typical requirements from our clients include:
Where will privacy legislation in Australia be in three years’ time? We do seem to be at the start of an interesting journey, potentially a path taken already by our products and consulting teams. To help understand how your SAP systems and PII data footprint can be managed through reducing, scrambling and redacting please, request a complimentary system analysis.