Skip to content

ACL's privacy lawsuit highlights cyber confidentiality concerns

Australian Clinical Labs appeared in court for the first time in its privacy law legal battle linked to its handling of a 2022 data breach.

OAIC v Australian Clinical Labs sees first case management hearing in Sydney. Shutterstock

The privacy regulator's lawsuit against ASX-listed pathology operator Australian Clinical Labs over its handling of a 2022 data breach was already shaping up as an important test case for how the agency might pursue legal action off the back of mass-data breaches.

But the first administrative hearing in the case in the Federal Court in Sydney on Thursday also highlighted the ways cyberattacks leave companies so nervous about security risks it can impact how they approach subsequent lawsuits.

In Thursday's hearing ACL requested a gag order over aspects of the concise statement laying out the lawsuit. The reason: its concerns that if was made public, the information contained in the document could provide a guide for a future hack.

ACL's request echoes a similar move by Optus in another data-breach lawsuit under way. The telecom provider earlier this month raised cybersecurity concerns in response to document requests by the class action plaintiffs taking legal action over its 2022 mass-data breach.