{"id":3166,"date":"2019-01-09T10:49:57","date_gmt":"2019-01-08T22:49:57","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=3166"},"modified":"2019-01-09T10:49:57","modified_gmt":"2019-01-08T22:49:57","slug":"austgovtaaa","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=3166","title":{"rendered":"Is it ok for the (Australian) government to read your data?"},"content":{"rendered":"<div>Late last year, the Australian Government introduced the Assistance and Access Act.\u00a0 This new legislation makes it mandatory for any organisation whose website or data is hosted in Australia to give Australian authorities access to their IT system if requested.<\/div>\n<div>[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div><strong>Given that a huge amount of data, including ours, is hosted in Australian datacentres (typically by US providers), this is of concern.<\/strong>\u00a0\u00a0 Most NZ businesses use Amazon AWS or Microsoft Azure or 365 tools hosted in Sydney or Melbourne &#8211; because it&#8217;s reliable, cost-effective and secure.\u00a0 We would regard this as being orthodox.\u00a0 In fact the NZ Government uses it extensively, even the Privacy Commission, with 90-95% of NZ government agency data being held in Australian clouds.<\/div>\n<div><\/div>\n<div>[header2 text=&#8221;What does this mean?&#8221; align=&#8221;left&#8221; color=&#8221;#336A40&#8243; margintop=&#8221;&#8221;]<\/div>\n<div><\/div>\n<div>This is a real challenge for us, especially if you consider all those Australian businesses we deal with, or our suppliers deal with that might have information about us.\u00a0 The jury is out though on whether its a theortical problem or a practical one.<\/div>\n<div><a href=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2019\/01\/20190102_125520.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-3164\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2019\/01\/20190102_125520-145x300.jpg\" alt=\"\" width=\"145\" height=\"300\" \/><\/a><\/div>\n<div>\u00a0[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div>Take a look at the New York Times editorial &#8211; they\u00a0 speculate that this is a beachhead and other jurisdictions will impose similar legislation if it is successful in the US.\u00a0\u00a0 Take a look at [wow_colorme]<a href=\"https:\/\/www.nytimes.com\/2018\/12\/06\/world\/australia\/encryption-bill-nauru.html\" target=\"_blank\" rel=\"noopener\"> https:\/\/www.nytimes.com\/2018\/12\/06\/world\/australia\/encryption-bill-nauru.html<\/a>[\/wow_colorme] and [wow_colorme]<a href=\"https:\/\/www.wired.com\/story\/australia-encryption-law-global-impact\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.wired.com\/story\/australia-encryption-law-global-impact\/<\/a>[\/wow_colorme]<\/div>\n<div>\u00a0[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div>So you might well move your data elsewhere, only to have the same problem reassert itself.\u00a0 That might mean that the most private places to hold data become outlier jurisdictions &#8211; I guess like the flags of convenience on ships at sea.\u00a0\u00a0 It&#8217;s more complex than this of course, as the capital investment needed by cloud providers is significant and they will only invest in low-risk, highly stable countries.<\/div>\n<div>\u00a0[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div>Of course, while we have control over where we store data, we don&#8217;t have as much control (notwithstanding legislation like [wow_colorme]<a href=\"http:\/\/kinetics.co.nz\/were-going-to-be-hearing-about-data-privacy-for-a-lot-longer-yet\/\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>[\/wow_colorme] and NZ Privacy Act) over where data about us is stored.\u00a0 I suspect it&#8217;s also going to be less effective than the lawmakers would like, because the rogue elements simply won&#8217;t hand over access to their data, or the data will be wrapped in multiple layers of encryption.<\/div>\n<div>\u00a0[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div>[header2 text=&#8221;We&#8217;re going to have to wait and see what this means in practice.\u00a0&#8221; align=&#8221;left&#8221; color=&#8221;#336A40&#8243; margintop=&#8221;&#8221;]<\/div>\n<div><\/div>\n<div>It&#8217;s clearly not going to stop here.\u00a0 While this seems to be a rash law, it would be unwise to act rashly as a result.\u00a0 There is a lot of water yet to flow under this bridge.<\/div>\n<div>\u00a0[wow_spacing size=&#8221;10px&#8221;]<\/div>\n<div>We know that Microsoft are considering their position, and in the past they have successfully fought this kind of imposition in the courts.\u00a0\u00a0 They won&#8217;t be alone, and I would think that this is where this will wind up &#8211; in a massive legal battle.\u00a0 We&#8217;ll keep you posted as we learn more.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Late last year, the Australian Government introduced the Assistance and Access Act.\u00a0 This new legislation makes it mandatory for any organisation whose website or data is hosted in Australia to give Australian authorities access to their IT system if requested. [wow_spacing size=&#8221;10px&#8221;] Given that a huge amount of data, including ours, is hosted in Australian [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1074,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-3166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/3166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3166"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/3166\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}