Data breaches and privacy complaints across Queensland's public sector on the rise - ABC News & Headlines – Australian Broadcasting Corporation
The public sector is required to tell the Information Commissioner's Office when there has been an eligible breach. (Blogtrepreneur/flickr.com/(CC BY 2.0))
Queensland's Office of the Information Commissioner received 82 data breach notifications from the public sector last financial year.
The independent regulator also received 353 privacy complaints, more than double the previous year.
Cybersecurity consultant Luke Irwin says data breaches are massively under-reported.
The number of data breaches across Queensland's public sector is increasing, including some deemed malicious and intentional, the state's privacy watchdog says.
Queensland's Office of the Information Commissioner's annual report revealed it received a total of 82 data breach notifications last financial year, compared with 53 in the previous year.
The office is an independent privacy regulator tasked with overseeing how government agencies handle personal information.
In its latest annual report, Information Commissioner Joanne Kummrow wrote that its services had "reached unprecedented levels" in the last financial year.
Most of the data breaches were caused by accident or human error. (Supplied: Unsplash/ Chris Yang)
It was the first year of a mandatory data breach notification scheme that began in July 2025.
A spokesperson from the office said most data breaches were caused by accident or human error, and most involved unauthorised disclosure.
That could have included a misdirected email, text message or system notification sent to the wrong recipient, or one that included unintended personal information, they said.
They said an example was the major cybersecurity incident involving the online learning platform Canvas, which affected an education technology provider in May.
Under a voluntary scheme, the commissioner received 53 notifications in 2024-25 and 41 in the previous year.
The mandatory scheme requires ministers, departments, and public authorities to notify the Information Commissioner and impacted individuals of an eligible data breach.
An eligible breach occurs when personal information held by an agency is compromised and is likely to result in serious harm to at least one individual.
This obligation was extended to local governments in July this year.
"An agency must give a statement to the Information Commissioner about an eligible data breach, but ultimate responsibility for meeting obligations under the [Information Privacy] Act remains with the agency," the spokesperson said.
Cybersecurity consultant Luke Irwin said data breaches were still "massively" under-reported.
"There are cases where they should be reporting, but they're making a choice not to," he said.
Cybersecurity expert Luke Irwin says many organisations treat online privacy as a second thought. (ABC News: Mark Leonardi)
Mr Irwin, who has worked in the industry for more than two decades, said the scheme was not mandatory enough and would like to see breaches reported first, before a privacy impact assessment.
Mr Irwin was also concerned about the qualifications of individuals assessing the harm that could occur if someone's data is breached.
"If somebody is a victim survivor of domestic violence and their address gets leaked, that's a major problem," he said.
Ms Kummrow said her office had received a "record" number of privacy complaints.
In 2025–26, the commissioner received 353 privacy complaints, more than double the previous year.
Of the complaints handled within the last financial year, 16 were referred to the Queensland Civil and Administrative Tribunal.
The spokesperson said an individual may make a privacy complaint if they believe that an agency has not handled their personal information in accordance with the law.
"This includes an agency not meeting its obligations in relation to a data breach notification," they said.
Mr Irwin said the increase in complaints could be due to people becoming more aware of their privacy.
He said many organisations were collecting too much unnecessary information, such as birthdays.
