In January 2021 a copy of Oxfam Australia's live supporter data sat in a test database that shared logins could reach. Oxfam learned of the breach when up to 1.7 million records were advertised for sale on a public hacking forum. It was a cybersecurity failure with a privacy outcome, and in December 2024 the Privacy Commissioner accepted a binding enforceable undertaking from the charity. This free 3-page briefing covers what the undertaking now asks of the board, the eight control areas to test, and the questions your board should be asking about your own systems.
Written for a board paper. No cost and no obligation.
We will email you the briefing and a short follow-up series on what it means for your charity. Unsubscribe at any time.
Charities copy production data into test environments for the most ordinary reasons: a CRM migration, a database upgrade, a supporter data cleanse, a new fundraising platform. Test, development and migration environments rarely carry production's controls, and a copy of production data inside one is a full copy of the risk. Oxfam's copy sat in a User Acceptance Testing database during a CRM migration. Page 2 of the briefing covers test environments and the board question to ask: does anyone know where every copy of our supporter data sits?
In January 2021, during a CRM migration, an unknown IP address reached Oxfam Australia's User Acceptance Testing database, which held a copy of live supporter data. The database could be reached using shared credentials. In late January, up to 1.7 million Oxfam records were advertised for sale on RaidForums. Oxfam was alerted seven days after the intrusion and formally notified the OAIC on 26 February. On 20 December 2024 the Australian Privacy Commissioner accepted a binding enforceable undertaking from Oxfam Australia. The OAIC raised concerns about live supporter data in a UAT database, shared credentials, and how long supporter information was retained. The obligations are written in privacy language. The work of meeting them is cyber security, and responsibility for it sits with the board.
The Oxfam undertaking gives charity boards a practical warning: privacy obligations can become binding when basic cyber controls are not evidenced. If your organisation holds donor, beneficiary or staff personal information, the same questions apply to your board.
ACNC guidance ties Governance Standard 5's duty of care to how a charity manages people's information and data. Responsibility stays with the charity and its board, even when IT or an MSP does the work. Boards should be able to show adequate preparation in writing.
A three-page executive briefing that breaks down the Oxfam undertaking and what it means for every Australian charity holding personal data. Written for boards, Responsible Persons, CEOs, CFOs and IT and risk leaders.
Applies to charities covered by the Privacy Act (generally over $3M turnover). Max penalty: greater of $50M, 3x benefit or 30% of turnover. Ransom reporting applies once paid.
We are running an upcoming live session where Mark Andersen and a senior privacy lawyer take charity boards and executives through the eight control areas, what adequate evidence looks like, and the questions a Responsible Person should be asking. Dates are being confirmed now.
Pre-register for the upcoming webinar when you download the briefing, and we will send you the date and the registration link before it goes public.
Get early accessThree pages, written for a board paper. It takes five minutes to read and it sets out the questions your board should be able to answer and the controls to test.
Takes 30 seconds. Sent straight to your inbox.