The Australian Privacy Commissioner, Karen Curtis, has called for compulsory notification of major data security breaches by
Australian organisations.
In a submission by her Office to the Australian Law Reform Commission (ALRC)
in response to its Discussion Paper 72: Review of Australian Privacy
Law, she proposes that reporting would need to be proportional to the severity of the
breach.