In today’s digital age, data is more than just a commodity; it’s the backbone of modern economies. As artificial intelligence (AI) evolves and cyber threats grow more sophisticated, data security is becoming increasingly critical.
Australia’s recent review and approval of its Privacy Act highlights this critical need for change, particularly for businesses handling consumer information. The new regulations significantly enhance consumer powers and, as a result, will place increased pressure on businesses to step up their data security efforts.
The Growing Risk of E-Criminals in the Age of AI
With the rise of AI, the landscape of cybercrime has shifted. No longer are cybercriminals only highly skilled hackers; thanks to advanced AI-powered tools, even unskilled individuals can launch attacks that would have previously been impossible (CrowdStrike, 2024, p. 9).
A recent report by CrowdStrike highlights how these tools are making it easier for cybercriminals to penetrate networks, steal data, and exploit vulnerabilities. This poses a direct threat to businesses handling sensitive consumer information.
The new Privacy Act gives consumers more power to hold companies accountable. Businesses that fail to protect data may face legal actions, fines, and lasting reputational damage.
Cloud-Based Attacks on the Rise
Cloud-based attacks have become increasingly frequent. Cybercriminals are becoming more adept at exploiting vulnerabilities in cloud environments, learning to leverage legitimate cloud processes to obfuscate their actions, making it harder to detect and respond to breaches (CrowdStrike, 2024).
What Businesses Must Do
1. Implement a Data Retention Policy
Document and implement a solid data retention policy that defines:
- How long customer data will be retained
- How it will be securely stored
- When and how it will be deleted or anonymised (Cole, 2024)
Keeping only the data needed for business operations minimises exposure to cyberattacks and legal liabilities.
2. Invest in Employee Training
Employees are often the first line of defence. Train them to:
- Understand the new Privacy Act regulations
- Handle data securely
- Respond to consumer queries and privacy requests in a timely, compliant manner (Hollingworth, 2025)
3. Review and Strengthen Data Security
The new Act isn’t optional. Organisations must assess their current data security posture against the requirements of the updated Privacy Act and act swiftly to close gaps.
Conclusion
As Australia’s Privacy Act undergoes significant changes, businesses of all sizes must act immediately. The risks of not doing so are substantial, not just in terms of legal consequences, but also in the erosion of consumer trust.
The new Privacy Act is not just a challenge; it’s an opportunity for businesses to demonstrate their commitment to protecting consumer privacy and building long-term trust.
References
- CrowdStrike. (2024). CrowdStrike 2024 Global Threat Report. https://go.crowdstrike.com/global-threat-report-2024-thank-you.html
- Cole. (2024). The Risks of Excessive Data Retention and Tips for Information Security. National Law Review.
- Department of Home Affairs. (2023). 2023-2030 Australian Cyber Security Strategy.
- Hollingworth, D. (2025). Experts demand Australian businesses focus on data security and privacy. Cyber Daily.
- OAIC. (2024). Passing of bill a significant step for Australia’s privacy law. https://www.oaic.gov.au/
- RMS. (2024). Cyber storm rising: Navigate the path to resilience for Australian business. RSM Australia.