• About our Cybersecurity Practice
  • Contact Us
  • Disclaimer
  • Home Page
  • Privacy Policy
  • Sample Page
  • Sample Page

Hold the phone…is “metadata” personal information? Who knows?

Feb 12 2016
Browse archives for February 12, 2016
Posted in

Privacy, Data Protection & Information Management

Tagged with Australia, Australian Privacy Principles, customer data, Federal Court, metadata, mobile phones, network, personal information, privacy, Privacy Act, Privacy Commissioner, Telstra
Share
    FacebookX

By Cameron Abbott, Simon McDonald and Meg Aitken

The ongoing debate surrounding what “metadata” actually is, and how it should be characterised under privacy laws has once again resurfaced. This time, the Federal Court will have a chance to decide on the issue, following a decision by the Privacy Commissioner to appeal a finding that denied a journalist access to metadata on the basis that it was not personal information.

Way back in 2013, a then technology journalist for Fairfax, Ben Grubb, asked Telstra to provide him with metadata and other information held by it in relation to his mobile phone on the basis that it constituted ‘personal information’ under the Privacy Act 1988 (Cth) (Privacy Act) and he was therefore entitled to it.

Telstra did provide some information to Mr Grubb (including his outgoing call records, bills and the customer details they had stored for him), however it submitted that the “metadata” produced from his mobile phone use on Telstra’s network was not personal information, as it was not linked to him in a way that made his identity apparent or reasonably ascertainable.

Unsatisfied with this answer, Mr Grubb lodged a complaint with the Privacy Commissioner. In May 2015, the Commissioner held that Telstra ‘cross-matched’ data across its mobile network in such a way that it was possible to determine a customer’s identity and that Telstra was therefore in breach on NPP 6.1 (as it then was) by refusing to provide Mr Grubb with access to his personal information.

Telstra appealed to the Administrative Appeals Tribunal of Australia (AATA). Taking a strangely narrow approach to the issue, Deputy President Forgie ruled that the mobile network data was not personal information for the purpose of the Privacy Act. Instead, she said that the metadata was actually information about the service provided by Telstra and the delivery of that service, rather than about Mr Grubb and his mobile phone use. On that basis, Telstra was not obliged to provide Mr Grubb with access to the information, despite it being generated directly from his use of Telstra’s services.

Seem contrary to the deliberately broad concept of personal information that is designed to protect individuals? We agree, and so does the Privacy Commissioner. ‘Stay on the line’ to see how the Federal Court approaches the issue.

Access the determination and reasons for determination of Privacy Commissioner Timothy Pilgrim in Ben Grubb and Telstra Corporation Limited [2015] AICmr 35 (1 May 2015) here.

Access the AATA decision of Deputy President S A Forgie in Telstra Corporation Limited and Privacy Commissioner [2015] AATA 991 (18 December 2015) here.

Access the Office of the Australian Information Commissioner’s Press Release here.

Privacy concerns over Westfield’s ticketless parking system
Gone in a ‘Flash’ – Google ditches Adobe for HTML5

Recent Posts

  • FTC Issues First Order Prohibiting Sale of Sensitive Location Data
  • FTC Bans Rite Aid from Using AI Facial Recognition Without Reasonable Safeguards
  • CJEU Decides on Use of Automatically Generated Scoring Values
  • CJEU Holds German Provisions for Imposing Fines on Companies for GDPR Violations Invalid
  • Provisional Political Agreement on Landmark AI Regulation in Europe

Recent Comments

  1. California Privacy Protection Agency Proposes Draft Rules for Automated Decision Making, Including Artificial Intelligence – Cyber Law Watch on California Proposes Cybersecurity Requirements for Businesses
  2. Australia’s Privacy Framework set to be Revamped Following the Government’s Response to the Privacy Act Review Report – Cyber Law Watch on The wait is over: The Privacy Act Review Report has been published!
  3. https://www.israelxclub.co.il/ on Privacy Awareness Week Part I- The state of play

Contact Information

Cyber Law Watch
K&L Gates
Level 25, 525 Collins Street
Melbourne VIC 3000
Australia
Phone: +61.3.9205.2000
Fax: +61.3.9205.2055

K&L Gates is a fully integrated global law firm with lawyers and policy professionals located across five continents.

For more information about K&L Gates or its locations, practices, and registrations, visit klgates.com.

This blog is intended for informational purposes and does not contain or convey legal advice. The information herein should not be used or relied upon in regard to any particular facts or circumstances without first consulting a lawyer. Any views expressed herein are those of the author(s) and not necessarily those of the law firm’s clients. By using this blog, you understand that there is no lawyer-client relationship intended or formed between you and the blog publisher or any contributing lawyer. The blog should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.

Portions of this blog may contain attorney advertising under the rules of some states. Prior results do not guarantee a similar outcome.

Follow Us

  • linkedin

Copyright © 2024, K&L Gates LLP. All Rights Reserved.

  • About our Cybersecurity Practice
  • Contact Us
  • Disclaimer
  • Home Page
  • Privacy Policy
  • Sample Page
  • Sample Page