Some of Australia’s most popular websites are also those that pose the greatest privacy threat, a new index created by University of Canberra cyber security experts has found.
In an Australian first, the University’s Centre for Internet Safety has produced the 2013 Australian Online Privacy Index to rate the websites most visited by Australians.
While Australian-based sites rank among the best, the majority are not compliant with changes to the Privacy Act which comes into force in March 2014.
Australian Online Privacy Index
University of Canberra cyber experts have created Australia's first online privacy index that rates how compliant websites are of privacy policies. Photo: Michelle McAulay.
Nigel Phair, co-director of the Centre, said the list examined 76 of the most popular websites ranging from e-commerce and search engines to banking and mainstream media. The list excluded pornographic and torrent sites, as well as those capturing clicks from the sites on the list.
“We reviewed privacy policies along with the number and duration of tracking cookies. Government websites ranked the best, followed by those from the banking & finance sector. The worst was a US-based photo sharing website,” Mr Phair said.
The top sites with best privacy policies:
*nine websites tied for equal ninth place.
The 10 websites with the highest tracking cookie count:
Mr Phair said there were a few surprises along the way. “We were impressed, for example, that Virgin Australia explained how it would act in case of a data breach.”
Co-director Alastair MacGibbon explained that to develop the index, the researchers looked at how websites collect, use, disclose, transfer and store customers’ personally identifying information.
“Many are ignoring basic privacy principles. And most of the privacy policies we analysed were below the standard necessary to explain the way the service will handle personal information,” Mr MacGibbon said.
He warned that the privacy regulatory environment is changing. On 12 March 2014, Australia will see a significant change in the way organisations are required to deal with sensitive private information collected in the course of their activities.
“This report demonstrates the majority of organisations are not ready for these regulatory changes,” he said.
The new index will allow consumers and regulators to assess the privacy implications of interacting with popular websites. It will also allow businesses to compare themselves with peers in their own sector, as well as to know how their sector fares against others.