12 August 2020

Critical Infrastructure

Just in case you had not heard the news, "The Government’s commitment to the continued prosperity of our economy and businesses is unwavering". 

It would be disquieting if we saw an official statement that the commitment was wavering or absent.

The ongoing commitment is highlighted in the Department of Home Affairs consultation paper on Protecting Critical Infrastructure and Systems of National Significance. It reflects the much-criticised Australia’s Cyber Security Strategy 2020 announced earlier this month. 

Unsurprisingly, the paper is attracting attention as muddled; less generous readers question whether criticisms will be taken on board, given the Department's history of consultation theatre and the Government's egregious disregard of university financial problems. 

The Department states 

The Australian Government is committed to protecting the essential services all Australians rely on by uplifting the security and resilience of critical infrastructure. 
 
Critical infrastructure is increasingly interconnected and interdependent, delivering efficiencies and economic benefits to operations. However, connectivity without proper safeguards creates vulnerabilities that can deliberately or inadvertently cause disruption that could result in cascading consequences across our economy, security and sovereignty. 
 
To ensure we continue to protect ourselves from such incidents, we are seeking your views on the details of Government’s agreed reforms ... a key initiative of Australia’s Cyber Security Strategy 2020. 

The consultation paper comments 

Who should read this paper? 
 
All Australians rely on critical infrastructure to deliver essential services that are crucial to our way of life, such as electricity, communications, transport and banking. As such, we encourage all Australians to take an active interest in ensuring that Australia’s approach to protecting critical infrastructure is fit for purpose for the modern age. 
 
From a critical infrastructure perspective, we are especially keen to hear from the following sectors, given their fundamental importance to our economy, security and sovereignty:
  • Banking and finance 
  • Communications 
  • Data and the Cloud 
  • Defence industry 
  • Education, research and innovation 
  • Energy 
  • Food and grocery 
  • Health 
  • Space 
  • Transport 
  • Water. 
 Overview 
 
The Australian Government is committed to protecting the essential services all Australians rely on by uplifting the security and resilience of critical infrastructure. Critical infrastructure is increasingly interconnected and interdependent, delivering efficiencies and economic benefits to operations. However, connectivity without proper safeguards creates vulnerabilities that can deliberately or inadvertently cause disruption that could result in cascading consequences across our economy, security and sovereignty. 
 
A range of hazards have the potential to significantly compromise the supply of essential services across Australia; physical, personnel and cyber security are all increasingly interrelated. Recent incidents such as compromises of the Australian parliamentary network, university networks and key corporate entities, natural disasters and the impacts of COVID-19 illustrate that threats to the operation of Australia’s critical infrastructure entities continue to be significant. 
 
We must work together now to ensure Australia’s security practices, policies and laws bolster the security and resilience of our critical infrastructure and position us to act in any future emergency. We need a better shared understanding of the threats we face and how we can combat them. Together, owners and operators of critical infrastructure, academia and all levels of government must collectively take steps to protect Australians from an attack and other disruptions. 
 
Accordingly, Government will introduce an enhanced regulatory framework, building on existing requirements under the Security of Critical Infrastructure Act 2018 (the Act). This will include:
  • a positive security obligation for critical infrastructure entities, supported by sector-specific requirements; 
  • enhanced cyber security obligations for those entities most important to the nation; and 
  • Government assistance to entities in response to significant cyber attacks on Australian systems. 
 These changes will be underpinned by enhancements to Government’s existing education, communication and engagement activities, under a refreshed Critical Infrastructure Resilience Strategy. This will include a range of activities that will improve our collective understanding of risk within and across sectors. The Government’s commitment to the continued prosperity of our economy and businesses is unwavering. The impacts of recent events only reinforce the need for collaboration between and across critical infrastructure sectors and Government to protect our economy, security and sovereignty. 
 
At the same time, Government recognises the additional economic challenges facing many sectors and entities in the wake of the COVID-19 pandemic. The outcome we seek is clear - we want to work in partnership to develop proportionate requirements that strike a balance between uplifting security, and ensuring businesses remain viable and services remain sustainable, accessible and affordable. An uplift in security and resilience across critical infrastructure sectors will mean that all businesses will benefit from strengthened protections to the networks, systems and services we all depend on. 
 
We want to hear from you – owners and operators of critical infrastructure, state and territory governments, academia and the Australian public – to contribute to the design of this framework to deliver a real and meaningful uplift to critical infrastructure security and resilience, while minimising economic impact. 
 
Where we are now 
 
The interconnected nature of our critical infrastructure means that compromise in one essential function can have a domino effect that degrades or disrupts others. 
 
The consequences of a prolonged and widespread failure in the energy sector, for example, could be catastrophic to our economy, security and sovereignty, as well as the Australian way of life, causing: 
  • shortages or destruction of essential medical supplies; 
  • instability in the supply of food and groceries; 
  • impacts to water supply and sanitation; 
  • impacts to telecommunications networks that are dependent on electricity; 
  • the inability of Australians to communicate easily with family and loved ones; 
  • disruptions to transport, traffic management systems and fuel; 
  • reduced services or shutdown of the banking, finance and retail sectors; and 
  • the inability for businesses and governments to function.  
At its most extreme, such catastrophic disruption could cause loss of life. Recent events, particularly COVID-19, have demonstrated how threats can have flow on effects across multiple sectors. A deliberate cyber attack could have farther-reaching, more rapid and less visible causes and effects. 
 
While Australia has not suffered a catastrophic attack on critical infrastructure, we are not immune: • Over the last two years, we have seen several cyber attacks in Australia that have targeted the Federal Parliamentary Network, airports and universities. • Malicious actors have taken advantage of the pressures COVID-19 has put on the health sector by launching cyber attacks on health organisations and medical research facilities. • Key supply chain businesses transporting groceries and medical supplies have also been targeted. 
 
While the Australian Government and industry continually work on responses to incidents impacting our critical infrastructure, there is scope to be more proactive and take preparatory activities to understand, mitigate and prevent threats. A cohesive partnership between the Government and industry, especially through sharing of technical expertise, is a desirable end state. Collective action now will place Australia in the best position to combat both foreseeable and emerging risks. The enhanced framework will meet this need, supported by proportionate sector- specific standards. 
 
What you have told us 
 
The Department of Home Affairs values its ongoing engagement with critical infrastructure entities. Mechanisms like the Trusted Information Sharing Network for Critical Infrastructure Resilience (TISN) are important forums for cross sector dialogue, facilitating ongoing feedback on the security environment facing us all. As outlined in the Cyber Security Strategy 2020, through consultation the Australian Government: • met with more than 1,400 people from across the country in face-to-face consultations, including workshops, roundtables and bilateral meetings; and • received 215 submissions in response to the Discussion Paper. 
 
Government heard that Australia’s critical systems are facing a worsening threat environment and the nation needs to address vulnerabilities in supply chain security, control systems and operational technology. This is consistent with advice from the national intelligence community and other sources. Timely and actionable information sharing was identified as a critical gap. We heard that Government’s role in addressing these threats and gaps should start by: • driving an uplift in resilience across sectors through regulation; • clarifying roles, responsibilities and expectations; and • using its unique capabilities to address serious cyber threats to Australia. 
 
We heard that Government also needs to explain how security risks are managed, how responsibilities are shared across the economy, and how Government and critical infrastructure entities can work together to protect Australia’s critical infrastructure from sophisticated threats. Consultations highlighted that the Australian public looks to both Government and critical infrastructure to secure the delivery of essential services. We need to collaborate and prepare ahead of time, so everyone knows what their role is and what they need to do in an emergency. To do this, Government and critical infrastructure entities need the right processes, authorisations and powers in place to respond rapidly and decisively. 
 
The framework set out in this Consultation Paper is put forward as a starting proposition to position all levels of government – Commonwealth, state, territory and local – and critical infrastructure to identify levels of entity criticality, appropriately minimise the likelihood and impact of significant incidents occurring, and to respond where necessary in the national interest. 
 
Where we need to be – an enhanced critical infrastructure framework 
 
Objective of the enhanced framework 
 
The primary objective of the proposed enhanced framework is to protect Australia’s critical infrastructure from all hazards, including the dynamic and potentially catastrophic cascading threats enabled by cyber attacks. The enhanced framework outlines a need for an uplift in security and resilience in all critical infrastructure sectors, combined with better identification and sharing of threats in order to make Australia’s critical infrastructure – whether industry or government owned and operated – more resilient and secure. This approach will prioritise acting ahead of an incident wherever possible. However, we recognise that one size does not fit all. We need to balance consistent objectives that provide a baseline of cyber, physical, personnel and supply chain protections across all sectors, with the reality that there are sector specific differences in human and financial resources, technology, threats, existing standards and maturity, to name a few. 
 
This is why the framework is proposed to be built around principles-based obligations that will sit in legislation, and underpinned by sector-specific guidance and advice, proportionate to the risks and circumstances faced by each sector. Furthermore, legislative requirements will remain proportionate and collaborative, while avoiding inconsistent application of regulations putting entities at a commercial disadvantage. To ensure these security outcomes, we recognise that uplift is required in all critical infrastructure sectors and that Government must be an exemplar. Accordingly, we will continue to work towards enhanced security for government and democratic institutions, and will work within the Commonwealth and with states and territories to identify the most appropriate mechanisms to ensure governments are held to the same standards as owners and operators of critical infrastructure. 
 
To respond to Australia’s evolving threat environment, we need to build a partnership that benefits all critical infrastructure, as well as the Australian public. It is not enough for owners and operators to uplift their resilience. Government should use its unique position and resources to share aggregated threat information, work with critical infrastructure entities of all levels of maturity to build their capability, and empower entities to appropriately protect themselves when faced with a serious threat. 
 
Features of the enhanced framework 
 
Government has agreed that the proposed enhanced framework will apply to an expanded set of critical infrastructure sectors, comprising of three key elements: 
 
1. Positive Security Obligation, including: a. set and enforced baseline protections against all hazards for critical infrastructure and systems, implemented through sector-specific standards proportionate to risk. 
 
2. Enhanced cyber security obligations that establish: a. the ability for Government to request information to contribute to a near real-time national threat picture; b. owner and operator participation in preparatory activities with Government; and c. the co-development of a scenario based ‘playbook’ that sets out response arrangements. 
 
3. Government assistance for entities that are the target or victim of a cyber attack, through the establishment of a Government capability and authorities to disrupt and respond to threats in an emergency.

These three initiatives will be underpinned by an enhanced Government-industry partnership across all hazards that, among other measures, will focus on:

  • reinvigorating and expanding existing engagement platforms and strategies; 

  • improving coordination across government to provide appropriately classified whole-of- government threat assessments and briefings to entities; 

  • co-designing best practice guidance with critical infrastructure entities, state, territory and Australian Government partners and regulators, as well as international partners; and 

  • delivering a comprehensive, multi-year program of workshops, exercises, information sharing sessions and assessments to complement and inform sector and sub-sector based assessments.

We recognise that there will be a regulatory impost in delivering these reforms. We will work with critical infrastructure entities to ensure that these reforms are developed and implemented in a manner that secures appropriate outcomes without imposing unnecessary or disproportionate regulatory burden, in accordance with guidance from the Department of the Prime Minister and Cabinet’s Office of Best Practice Regulation. ... 
 
Principles-based outcomes 
 
We want to work with critical infrastructure entities to clearly define the high level, sector- agnostic principles that will form the basis for the PSO. We consider that at a minimum, owners and operators of critical infrastructure should be legally obliged to manage risks that may impact business continuity and Australia’s economy, security and sovereignty, by meeting the following PSO principles-based outcomes. 
 
1. Identify and understand risks 
 
Entities will have a responsibility to take an all-hazards approach when identifying and understanding risks. This will consider both natural and human induced hazards. This may include understanding how these risks might accumulate throughout the supply chain, understanding the way systems are interacting, and outlining which of these risks may have a significant consequence to core service provision. 
 
2. Mitigate risks to prevent incidents 
 
Entities will be required to have appropriate risk mitigations in place to manage identified risks applicable to their sector. Risk mitigation should consider both proactive risk management as well as having processes in place: to detect and respond to threats as they are being realised; and plan for disasters and have a way to lessen the negative impact were it to actually occur. The regulated entity will be responsible for engaging with the regulator to ensure that identified risks and proposed mitigations are proportionate to the risks, while also considering the business, societal and economic impacts. 
 
3. Minimise the impact of realised incidents 
 
Entities will be required to have robust procedures in place to recover as quickly as possible in the event a threat has been realised. This may include ensuring plans are in place for a variety of incidents, such as having back-ups of key systems, adequate stock on hand (such as medicines), redundancies for key inputs, out-of-hours processes and procedures, and the ability to communicate with affected customers. 
 
4. Effective governance 
 
Entities will be required to have appropriate risk management oversight and responsibilities in place, including evaluation and testing. This will involve strong governance with clear lines of accountability, demonstrated comprehensive planning, and a robust assurance and review process in place that is proportionate to the identified risks. Compliance will be assessed by the relevant regulator noting that what is appropriate may be unique to each entity. Regulators will focus on outcomes and seek to avoid compliance burden. 
 
Security Obligations 
 
We consider that the new framework should clearly set out in legislation the high-level security obligations that critical infrastructure entities should meet. At a minimum, we consider these to be: 
 
Physical security 
 
Critical infrastructure entities will be required to protect their systems and networks by considering and mitigating natural, and human induced threats. This may include:
  • Implementing proportionate physical security measures that lessen the risk of harm to people, information and physical asset resources being made unlawfully inoperable or inaccessible, or being accessed, used or removed without appropriate authorisation. 
  • Integrating protective security into the process of planning, selecting, designing and modifying facilities for the protection of people, information and physical assets. 
  • Securing physical spaces where sensitive information and assets are used, transmitted, stored or discussed. 
Cyber security 
 
Critical infrastructure entities will protect their systems and information from cyber threats. This may include:
  • Identifying and assessing sensitive information and implementing proportionate controls. 
  • Understanding access to an entity’s sensitive information, with need to know principles applied. 
  • Endeavouring to safeguard information from common and emerging cyber threats and adhering to best practice guidelines. 
  • Implementing robust security measures during all stages of ICT systems development. 
  • Aiming to ensure systems and personnel can detect, understand and respond to cyber security incidents.  
Personnel security 
 
Critical infrastructure entities will implement policies and procedures which seek to mitigate the risk of employees (insider threats) exploiting their legitimate access to an organisation’s assets for unauthorised purposes. This may include:
  • Ensuring only suitable employees and contractors access the entity’s resources and are aware of, and meet, appropriate standards of conduct. 
  • Assessing and managing the ongoing suitability of its personnel to access resources throughout their engagement. 
  • Promoting a positive and collaborative security culture of continual improvement and engagement across sectors, ensuring lessons learnt are shared. 
Supply chain security 
 
Critical infrastructure entities will protect their operations by understanding supply chain risk. Supply chains can be compromised or disrupted from a variety of natural or man-made activities.

Facebook

'What if Facebook goes down? Ethical and legal considerations for the demise of big tech' by Carl Öhman and Nikita Aggarwal in (2020) 9(3) Internet Policy Review comments 

Society is becoming increasingly dependent on data-rich, “Big Tech” platforms and social networks, such as Facebook and Google. But what happens to our data when these companies close or fail? Despite the high stakes involved, this topic has received only limited attention to date. In this article, we use the hypothetical failure of Facebook as a case study to analyse legal and ethical risks related to the closure of data-rich, Big Tech platforms. Focusing on the EU, we argue that existing governance frameworks are inadequate for addressing these risks and make preliminary recommendations with a view to setting an agenda for future research and policymaking on the demise of Big Tech platforms and data-rich companies more broadly. 

The authors argue 

Facebook has, in large parts of the world, become the de facto online platform for communication and social interaction. In 2017, the main platform reached the milestone of two billion monthly active users (Facebook, 2017), and global user growth since then has continued, reaching 2.6 billion in April 2020 (Facebook, 2020). Moreover, in many countries Facebook has become an essential infrastructure for maintaining social relations (Fife et al., 2013), commerce (Aguilar, 2015) and political organisation (Howard and Hussain, 2013). However, recent changes in Facebook’s regulatory and user landscape stand to challenge its pre-eminent position, making its future demise if not plausible, then at least less implausible over the long-term. 
 
Indeed, the closure of an online social network would not in itself be unprecedented. Over the last two decades, we have seen a number of social networks come and go — including Friendster, Yik Yak and, more recently, Google+ and Yahoo Groups. Others, such as MySpace, continue to languish in a state of decline. Although Facebook is arguably more resilient to the kind of user flight that brought down Friendster (Garcia et al., 2013; Seki and Nakamura, 2016; York and Turcotte, 2015) and MySpace (boyd, 2013), it is not immune to it. These precedents are important for understanding Facebook’s possible decline. Critically, they demonstrate that the closure of Facebook’s main platform does not depend on the exit of all users; Friendster, Google+ and others continued to have users when they were sold or shut down. 
 
Furthermore, as we examine below, any user flight that precedes Facebook’s closure would probably be geographically asymmetrical, meaning that the platform remains a critical infrastructure in some (less profitable) regions, whilst becoming less critical in others. For example, whilst Friendster started to lose users rapidly in North America, its user numbers were simultaneously growing, exponentially, in South East Asia. It was eventually sold to a Filipino internet company and remained active as a popular social networking and gaming platform until 2015. The closure of Yahoo! GeoCities, the web hosting service, was similarly asymmetrical: although most sites were closed in 2009, the Japanese site (which was managed by a separate subsidiary) remained open until 2019. It is also important to note that, in several of these cases, a key reason for user flight was the greater popularity of another social network platform: namely, MySpace (Piskorski and Knoop, 2006) and Facebook (Torkjazi et al., 2009). Young, white demographics, in particular, fled MySpace to join Facebook (boyd, 2013). 
 
These precedents suggest that changing user demographics and preferences, and competition from other social networks such as Snapchat or a new platform (discussed further below) could be key drivers of Facebook’s decline. However, given Facebook’s pre-eminence as the world’s largest social networking platform, the ethical, legal and social repercussions of its closure would have far graver consequences than these precedents. Rather, the demise of a global online communication platform such as Facebook could have catastrophic social and economic consequences for innumerable communities that rely on the platform on a daily basis (Kovach, 2018), as well as the users whose personal data Facebook collects and stores. 
 
Despite the high stakes involved in Facebook’s demise, there is little research or public discourse addressing the legal and ethical consequences of such a scenario. The aim of this article is therefore to foster dialogue on the subject. Pursuing this goal, the article provides an overview of the main ethical and legal concerns that would arise from Facebook’s demise and sets out an agenda for future research in this area. First, we identify the headwinds buffeting Facebook, and outline the most plausible scenarios in which the company — specifically, its main platform — might close down. Second, we identify four key ethical stakeholders in Facebook’s demise based on the types of harm to which they are susceptible. We further examine how various scenarios might lead to these harms, and whether existing legal frameworks are adequate to mitigate them. Finally, we provide a set of recommendations for future research and policy intervention. 
 
It should be noted that the legal and ethical considerations discussed in this article are by no means limited to the demise of Facebook, social media, or even “Big Tech”. In particular, to the extent that most sectors in today’s economy are already, or will soon become, data-driven and data-rich, these considerations, many of which relate to the handling of Facebook’s user data, are ultimately relevant to the failure or closure of any company handling large volumes of personal data. Likewise, as human interaction becomes increasingly mediated by social networks and Big Tech platforms, the legal and ethical considerations that we address are also relevant to the potential demise of other social networks, such as Google or Twitter. However, focusing on the demise of Facebook — one of the most data rich, social networks in today’s economy — offers a fertile case study for the analysis of these critical legal and ethical questions.

11 August 2020

TGA and therapeutic goods advertising

The Therapeutic Goods Administration, the inward-looking arm of the Health Department that is the Australian counterpart of the US FDA, will need to lift its game after the Health Minister's announcement that the national government has accepted all 22 recommendations in the Sinclair Review of the therapeutic goods advertising regime. 

In line with the Government's commitment made in 2018 to review the reforms to the therapeutic goods advertising framework within two years from implementation, the review examined the impact of the new advertising measures regarding the commencement of the Therapeutic Goods Amendment (2017 Measures No. 1) Act 2018, with reference to the advertising reforms from the Expert Panel Review of Medicines and Medical Devices Regulation (MMDR Review) and other initiatives announced by the Minister.

Sinclair's report states

The Review assessed the impact of the:

A. new advertising measures as included in the Therapeutic Goods Act 1989 (the Act), in particular, the effectiveness of: 

i. the amendments to the Therapeutic Advertising Code (No. 2) 2018 i.e. whether they have increased clarity and objectivity to support the compliance and enforcement powers in the Act and improved consistency between the requirements for medicines and medical devices; 

ii. the TGA as the single body responsible for implementing a complaints management process about the advertising of therapeutic goods to the public; and iii. broadened sanctions and penalties to deter inappropriate and misleading advertising of therapeutic goods. 

B. other initiatives announced by the Minister in February 2018, namely:

iv. a comprehensive industry and consumer education program of the new advertising measures; 

v. public performance measures for advertising complaints management, i.e. an assessment of the suitability of the TGA’s key performance indicators for managing advertising complaints; and 

vi. stakeholder engagement activities on therapeutic goods advertising with a particular focus on the effectiveness of the Therapeutic Goods Advertising Consultative Committee (TGACC).

It notes 

The Therapeutic Goods Administration (the TGA) is Australia’s regulatory authority for therapeutic goods. The TGA is part of the Australian Government Department of Health (the Department). On 24 October 2014, the Australian Government announced the Expert Panel Review of Medicines and Medical Devices Regulation (MMDR) (‘the MMDR Review’). 

The objective of that Review was to make recommendations to assist the Government to enhance the regulatory framework for medicines and medical devices so that: ▪ Australia continues to be well positioned to respond effectively to global trends in the development, manufacture, marketing and regulation of therapeutic goods, and ▪ areas of unnecessary, duplicative or ineffective regulation are removed or streamlined without undermining the safety or quality of therapeutic goods available in Australia. 

The Expert Panel reported in two stages and made a total of 58 recommendations, which reflected an overarching intention to remove unnecessary regulatory burden and support the regulator and industry transition towards a more self-regulatory regime, without compromising the safety or quality of therapeutic goods or diminishing protections for the Australian public. The principles underpinning that Review are relevant to the consideration of progress on the seven recommendations which related to the advertising of therapeutic goods:

1 The role of regulation is to manage risk in order to protect public health and safety; 

2 The level of regulation should be commensurate with the risk posed by the regulated products; 

3 A risk-benefit approach to the regulation of therapeutic goods is appropriate; 

4 The regulation of therapeutic goods should take a whole-of-lifecycle approach; and 

5 The ultimate responsibility for medicines and medical devices regulation should remain with the Commonwealth.

Of the 58 recommendations seven related to the advertising of therapejutic goods. The recommendations reflected the Panel’s view that “...controls on advertising provide an important assurance that consumers have access to accurate information in making health choices”. The Australian Government Response to the Review (‘Government Response’) was released on 15 September 2016, following consultation with stakeholders including consumers, healthcare professionals and industry:

“This response presents a strategic and systems-based approach to achieve long-term sustainable reform to the regulation of therapeutic goods in Australia. It identifies ways to improve access to therapeutic goods for consumers and remove unnecessary red tape for industry whilst maintaining the safety of therapeutic goods in Australia.” 

Of the total 58 recommendations, 56 of the recommendations were supported by the Government. All the recommendations relating to the regulation of therapeutic goods advertising were accepted. This resulted in a suite of changes to the therapeutic goods advertising framework, with reforms led by the Department and more specifically, the TGA. 

This Review of the Therapeutic Goods Advertising Framework (‘the Review’) was intended to examine the impact and effectiveness of key changes to the advertising framework catalysed by the MMDR Review. The advertising framework components to be considered in this Review included the relevant changes to the Therapeutic Goods Act 1989 (Cth) (‘the Act’), which establishes the legal requirements for the import, export, manufacture and supply of therapeutic goods in Australia. 

Specifically, the Review considered amendments to:

  •  the Therapeutic Goods Advertising Code, as the instrument made under the Act that sets out the legislative requirements for therapeutic goods advertising; 

  • disband the Complaints Resolution Panel and nominate a single-body to be responsible for the management of public complaints about the advertising of therapeutic goods; and 

  • broaden the sanctions and penalties available to respond to breaches of advertising requirements.

The Review also examined a number of other initiatives announced by the Minister for Health (‘the Minister) that supported the intent of the MMDR recommendations and implementation of changes to the advertising framework. These initiatives are led by the TGA and included: ▪ a comprehensive industry and consumer education program regarding the new advertising framework; ▪ development of public performance measures for the reformed complaints management function; and ▪ engaging with stakeholders regarding therapeutic goods advertising, particularly through a forum of relevant stakeholder representatives in the Therapeutic Goods Advertising Consultative Committee (TGACC). 

Most of the changes regarding the therapeutic goods advertising framework noted above, have occurred within the last 12-18 months, with the TGA taking an approach of continuous improvement to implementing the reforms.

The Review's 'overall assessment' is 

The changes to the therapeutic goods advertising framework within scope of this Review have been implemented in the last 12-18 months. In this regard, the Review has taken place at a timely crossroads, to reflect on the early experiences of implementation of the reforms, and to inform further improvement to the effectiveness of the regulatory framework for therapeutic goods advertising and a strengthened strategic focus on implementation. 

The Review involved extensive stakeholder consultation, both with key stakeholder groups represented on the TGACC, and with a selection of Departmental staff members and senior executives. In undertaking these consultations, the Review noted a high degree of openness and highly thoughtful responses, which reflected an invested stakeholder base and a commitment to continuous improvement by the TGA. All stakeholders understood the importance of consumers having accurate information in making health choices. This was reflected in stakeholder commitment to supporting effective regulation of advertising in the interest of public health and safety. 

Conducting the Review in the COVID-19 environment posed some interesting challenges, leading to innovative and amended ways of completing the Review. As a result, most consultations were held via teleconference, and the work conducted by the review team mostly occurred online and offsite. The COVID-19 crisis required the TGA to develop and execute new strategies and approaches to cope with a public health emergency and as a result, the Review was able to identify some pertinent and significant changes in the operation of the TGA. A number of observations regarding this response have been captured in this review report. The COVID-19 environment provided an opportunity for the TGA to demonstrate the value to consumers of focusing on compliance priorities, taking a strategic approach to communication and education tasks, and adopting an agile approach to the use of its enhanced powers. The Review suggests there is much for the regulator and industry to learn from this recent experience. The Review noted that across all reform elements examined, the TGA has implemented the changes with a clear understanding of its accountability for public health and safety. The TGA has also demonstrated a positive and open-minded approach to continuous improvement to the regulatory framework and associated processes, such as through seeking feedback from stakeholders and reflecting on its approach in an iterative way. 

Overall, the changes that have been implemented by the TGA have moved in the right direction in giving effect to the intended outcomes and benefits noted in the MMDR Review and Government Response. In initiating and implementing the reforms to the therapeutic goods advertising framework, the TGA efforts to date have emphasised an approach of informing and assisting industry with regards to the advertising framework. This is a natural course given the shift to a self-regulatory landscape and the large suite of reforms to the rules and processes that regulate therapeutic goods advertising. In this way, the TGA has taken on a role of assisting industry to understand the new framework as the first step to enabling improved self-compliance. 

The Review notes that in some areas, such as with enforcement responses and developing educational materials, the TGA has gone to great lengths to support industry. The Review suggests that the TGA, with the regulatory framework and supporting processes for therapeutic goods advertising in place, is now well-placed to shift its approach and focus to achieve the aims of the reform program. For industry, the next phase will involve more responsibility, with industry further developing their practices for self-compliance, becoming responsible and accountable ‘partners’ in achieving the aims of the regulatory framework and the intended consumer protection outcomes. 

The Recommendations made as part of this Review are intended to facilitate this approach. For the TGA, the next phase will involve a more strategic approach to its responsibilities as the regulator of therapeutic goods advertising. The TGA should focus more directly on the intended outcomes and priorities of its compliance functions. A clearer vision of the outcomes and priorities of compliance activities should guide the TGA in updating its processes, performance measures, and aligning resources. The Recommendations made as part of this Review are intended to facilitate a more strategic and outcomes-focused approach to the TGA’s regulatory framework for therapeutic goods advertising. 

Summary assessment against Terms of Reference items 

The key observation to report is that while good progress has been made implementing the Government’s response to the MMDR Report, the focus has necessarily been tactical given the timeframes for implementation. With the benefit of the experience now gained over the last 12-18 months, and the need for rapid response in the early days of the COVID-19 pandemic, this Review finds that there has been progress in achieving the aims of the framework. The next phase in achieving further effectiveness and impact from the Therapeutic Good Advertising Framework will depend on a more strategic approach to a number of the review scope items. It should be noted based on stakeholder consultations, that the Department’s approach is already one of continuous improvement and that stakeholders are also committed to contribute to further improving the regulation advertising of therapeutic goods to the public. 

1.5.1 The amendments to the Therapeutic Advertising Code (No. 2) 2018 i.e. whether they have increased clarity and objectivity to support the compliance and enforcement powers in the Act and improved consistency between the requirements for medicines and medical devices 

The Review finds that the changes to the Code have resulted in improvement, with the new Code being clearer and easier to understand. Compliance is more straightforward for industry and advertisers and supports progress to a more self-regulatory regime. Assessment of advertising breaches is more straightforward for the TGA. There are opportunities for further refinement which are identified in the recommendations. 

1.5.2 The TGA as the single body responsible for implementing a complaints management process about the advertising of therapeutic goods to the public The Review finds that the TGA is well-placed to be the single-body for managing complaints about the advertising of therapeutic goods. Stakeholders reported that TGA has the relevant scientific and regulatory knowledge to effectively regulate the quality and safety of therapeutic goods. The single body has reduced complexity and potential confusion in making complaints about advertising of therapeutic goods. A complaints management process has been implemented. There are opportunities for a more strategic approach to using complaints within the regulatory framework which are identified in the recommendations. 

1.5.3 Broadened sanctions and penalties to deter inappropriate and misleading advertising of therapeutic goods 

The Review finds that the broadened sanctions and penalties provide an appropriate breadth of responses for the TGA in deterring misleading advertising and achieving compliance outcomes for consumer protection in a self-regulatory environment. There are opportunities for the TGA, having focused on its role to inform and educate industry, to build on its experience in using the full range of broadened sanctions and penalties. 

1.5.4 A comprehensive industry and consumer education program of the new advertising measures The Review finds the TGA has been effective in developing and distributing information about the advertising framework and Code requirements. The TGA has been very responsive to industry requests for further information. There are opportunities for the TGA to move to a more strategic approach to providing information and education for both industry and consumers including setting priorities based on key regulatory outcomes and working with industry as responsible and accountable partners in achieving better consumer outcomes. 

1.5.5 Public performance measures for advertising complaints management, i.e. an assessment of the suitability of the TGA’s key performance indicators for managing advertising complaints 

The Review finds significant opportunity for the TGA to revise its performance measures and key performance indicators to include a focus on priorities and outcomes for consumers rather than the current emphasis on timeliness of processes. The Review notes that the TGA has already begun work in this area through a focused concurrent management initiated review into the complaints management function. 

1.5.6 Stakeholder engagement activities on therapeutic goods advertising with a particular focus on the effectiveness of the TGACC 

The Review found that the TGA applies considerable effort to stakeholder engagement with a very broad range of stakeholders. There is opportunity to engage more strategically with stakeholders, to provide focused opportunities for engagement and to shift from informing stakeholders to engaging them more effectively to build shared responsibility for achieving improved compliance outcomes.

Sinclair's  Summary of Recommendations for Further Improvement is

Regarding amendments to the Therapeutic Advertising Code (No. 2) 2018 

Recommendation 1: Case Studies To further increase clarity and objectivity of the Code, the TGA should consider using emerging case experience and decisions to create examples of the application and interpretation of the Code, including cases where provisions are considered by stakeholders to be ambiguous. 

The selection of case studies to publish may also be informed by the TGA’s compliance priorities (Recommendation 5) and education priorities (Recommendation 12). 

Recommendation 2: Focus Issues 

The TGA should maintain and share a log of Code issues that stakeholders confirm after discussions in TGACC sub-groups (Recommendation 20) as being unclear, inconsistent, or difficult to work with. Where case examples and educational materials are not sufficient to improve clarity and objectivity, the TGA should consider publishing policy clarification. 

Regarding the TGA as the single body responsible for implementing a complaints management process about the advertising of therapeutic goods 

Recommendation 3: Maintain TGA as the single body 

The Government should maintain the TGA as the single body responsible for implementing a complaints management process about the advertising of therapeutic goods to the public. The TGA should continue to build its complaints handling capability and systems as outlined in Recommendations 4 to 7. 

Recommendation 4: Strategic Re-set 

The TGA should use the recommendations made in the concurrent management initiated review to reset the complaints management system to focus on achieving improved compliance outcomes through intelligence gathering, strategic triaging and integrated response. 

Recommendation 5: Compliance Priorities 

The TGA should develop and publish Compliance Priorities which are reviewed annually. In setting these priorities the TGA should develop factors to be considered, consult with stakeholders, and focus on consumer benefit. The Compliance Priorities should inform key performance indicators (KPIs) and reporting (Recommendations 14 and 15). 

Recommendation 6: Integrated Information - TGA 

The TGA should work to further integrate the management of complaints about advertising of therapeutic goods with other relevant areas within the TGA. This could be achieved by developing information-sharing practices across the TGA, to support: ▪ the compliance priorities across the TGA’s regulatory areas; and ▪ identification of trends identified across high-volume complaints regarding products, types of therapeutic claims made, manufacturers, or suppliers. 

Recommendation 7: Integrated Information – other Regulators 

The TGA should co-develop information-sharing protocols to facilitate active information-sharing with relevant regulators, including Food Standards Australia New Zealand (FSANZ) and the Australian Competition and Consumer Commission (ACCC) regarding complaints and trends on relevant cross- sector products or issues. This should be supported by focused engagement with regulators (Recommendation 21) to define information-sharing needs and priorities. 

Regarding broadened sanctions and penalties to deter inappropriate and misleading advertising of therapeutic goods 

Recommendation 8: Regulatory Posture 

The TGA should develop and promote a clear regulatory position on its approach to the use of the broadened sanctions and penalties to protect public health and safety. This should include the balance of focus between educative and punitive responses, and the principles that guide the use of more punitive compliance tools. The position should be clearly communicated to Departmental staff involved in advertising compliance and other stakeholders. 

Recommendation 9: Skill development 

The TGA should provide focused skills development on compliance and enforcement practice to support the advertising compliance team in implementing the TGA’s regulatory position. This may include developing an understanding of case management and enforcement response at other regulators, and sharing lessons learned. 

Recommendation 10: COVID-19 Response 

The TGA should reflect on the lessons learned from the COVID-19 experience in responding to non- compliant advertising with sanctions and penalties in a timely manner. The COVID-19 experience also has useful learnings regarding the use of media and publicising the compliance actions taken by the TGA to raise awareness of the negative consequences of using non-compliant advertising. 

Regarding the industry and consumer education program of the new advertising measures 

Recommendation 11: Education Strategy 

The TGA should develop an Advertising Framework Education Strategy with clearly defined priorities that are aligned to Compliance Priorities and consumer outcomes. 

Recommendation 12: Education Priorities 

The TGA should develop Education Priorities to more effectively target educational activities. In setting these priorities the TGA should develop factors to be considered, consult with stakeholders and focus on consumer and industry benefit. The education priorities should be publicised and clearly communicated to stakeholders. The priorities should be reviewed annually. 

Recommendation 13: COVID-19 Communications 

The Review recommends that the TGA use the COVID-19 experience, particularly in priority-setting and developing activities and mobilising the media in support of agreed priorities, as part of developing a more strategic approach to its education program. 

Regarding the public performance measures for advertising complaints management 

Recommendation 14: Indicators for Outcomes 

The TGA should redevelop a suite of advertising compliance performance measures and indicators which focus on priorities and outcomes rather than processes and deadlines. In considering a new approach to measures and indicators, the TGA should use the recommendations made in the concurrent management initiated review of the complaints handling process. 

Recommendation 15: Performance Reporting 

Once the TGA has developed new performance indicators for advertising compliance and complaints management, the TGA should publicise the measures, and report performance against the measures using the TGA website and annual reporting and media channels. 

Regarding stakeholder engagement activities on therapeutic goods advertising 

Recommendation 16: Stakeholder Engagement Plan 

The TGA should ensure its Stakeholder Engagement Plan includes a focus on supporting effective regulation of therapeutic goods advertising. The stakeholder engagement plan should consider the TGA’s compliance priorities (in line with Recommendation 5) and education priorities (in line with Recommendation 12). The plan would define purpose and objectives, priorities, and engagement methods specific to TGA’s advertising compliance role. 

Recommendation 17: Communications Plan 

The TGA should ensure its Communications Plan reflects a strategic approach to communications including use of external channels (particularly media) to support its advertising framework compliance priorities, education strategy goals and stakeholder engagement strategy goals. Use of media and external channels should focus on increasing both consumer and industry awareness of the TGA’s regulatory position in regard to advertising compliance. Well-targeted consumer information and regular public reporting on regulatory decisions made and outcomes achieved would be elements of effective communication. 

Recommendation 18: TGACC Ways of Working 

The TGACC should be refocused to enhance its effectiveness as a collaborative forum focused on better outcomes for consumers through effective advertising compliance by industry. This may be achieved by updating the Governance Arrangements or developing an accountability charter which details: ▪ the refreshed objectives of the TGACC; ▪ roles and responsibilities of the TGA and members, which may include more opportunity for members to share their experiences, concerns or recent activities such as member education activities; and ▪ expectations of both the TGA and members. 

Recommendation 19: TGACC Work Plan 

The TGA should develop a list of key tasks and associated timeframes that require the input of the TGACC to finalise. This would include: ▪ developing annual compliance priorities; ▪ developing annual education priorities; and ▪ identifying significant case studies for use in the education program or media. 

Recommendation 20: TGACC Focus Sub-groups 

The TGA should consider hosting focused sub-groups with representation from the most relevant sector members from the TGACC. These should be hosted on an as-needed basis. A summary of key considerations and outcomes from these focused roundtables should be reported back to the wider TGACC group. 

Recommendation 21: Regulator Meetings 

The TGA should continue to hold regular meetings with other regulators to develop approaches and actions to address regulatory interface issues. A summary of key considerations and outcomes from the regulator meetings should be reported back to the wider TGACC group. 

Recommendation 22: Stakeholder Survey 

The TGA should develop a periodic (e.g. every two years) stakeholder survey to evaluate stakeholder satisfaction with stakeholder engagement efforts. The survey may also be used to gauge perceptions of the effectiveness of the TGA’s compliance framework, which may inform performance reporting. The survey should include input from key stakeholders consulted with and other partnering regulators. Areas of weakness or opportunities for improvement identified from the survey should inform updates to the TGACC Ways of Working, stakeholder engagement plan and communications plan.

10 August 2020

Empirical Legal Analysis

‘What’s Plainly Wrong in Australian Law? An Empirical Analysis of the Rule in Farah’ by Antonia Glover in (2020) 43(3) University of New South Wales Law Journal comments 

In Australian Securities Commission v Marlborough Gold Mines Ltd (1993) 177 CLR 485, and again in Farah Constructions Pty Ltd v Say-Dee Pty Ltd (2007) 230 CLR 89, the High Court pronounced that Australian courts must follow the decisions of appellate courts across Australia unless convinced that those decisions are ‘plainly wrong’. This article seeks to track the development and application of this rule in both a historical and modern context. It first examines the state of the law prior to Marlborough and then engages in an empirical analysis of the use of the rule since Marlborough in 1993, tracking how often the rule has been used and where divergence between jurisdictions has emerged. The results confirm the existence of a judicial system with an increased focus on, and practice of, internal consistency. This replaces the 20th century paradigm in which loyalty to Britain was prioritised over intra-Australian uniformity.

Glover argues 

 In what has become a seminal statement, in Farah Constructions Pty Ltd v Say-Dee Pty Ltd (‘Farah’), the High Court directed that on questions of law of national operation (ie the common law, uniform national legislation and Commonwealth legislation), the decisions of intermediate appellate courts (‘IACs’) must be followed by courts in other Australian jurisdictions unless the latter court is convinced that the IAC decision in question is plainly wrong (the ‘Farah plainly wrong rule’). 

The statement in Farah was in large part a restatement of the High Court’s earlier pronouncement in Australian Securities Commission v Marlborough Gold Mines Ltd (‘Marlborough’), where the High Court expounded an identical rule but omitted reference to the common law. Marlborough was the first instance in Australia’s history where the High Court had sought to clearly address the question of inter-jurisdictional Australian precedent. The preceding 92 years of a federated Australia had been marked by a quiet uncertainty on the subject. 

The Farah plainly wrong rule has significant implications for the nature of Australia’s judicial federation. It creates formal and tight bonds between Australia’s numerous, distinct judicial hierarchies in respect of the increasingly broad domain of law of national operation. Despite its importance, there is a degree of uncertainty and confusion as to whether Farah marks a significant departure from the past, and how exactly it is being applied in the present. This article seeks to address that gap by tracking the development and practical application of the to address that gap by tracking the development and practical application of the rule in both a historical and modern context. It proceeds in two primary parts. The first part is qualitative. It examines how the complex question of inter- jurisdictional precedent was approached in the century which preceded Marlborough. An analysis of this history demonstrates that the standardisation of the rules of precedent for extra-hierarchical Australian authority evident in Marlborough and Farah is the culmination of, and a product of, the severance of judicial ties with Britain and the abandonment of the ideal of pan-British Commonwealth uniformity. 

The second part is quantitative. It examines exactly how courts have applied and relied on the Farah plainly wrong rule since Marlborough was handed down in 1993. The empirical analysis conducted examines how frequently courts have made reference to the rule, how frequently they have elected to diverge from prior authority on the basis that it is ‘plainly wrong’, and where exactly that divergence has emerged. The results show, as one would expect from a rule which imposes a general standard of uniformity with a limited exception, that the practice of courts has been to largely follow each other’s decisions except in restricted and careful circumstances. Only 20 decisions over the 25 years surveyed involved a court deeming a prior IAC decision to be plainly wrong. These decisions emanated from both single judges and IACs, and stemmed most strongly from the New South Wales (‘NSW’) Supreme Court (with 50% of the cases involving a finding that a prior decision was plainly wrong coming from NSW). The rate at which courts engaged with the language of the rule rose considerably over the studied period. 

Taken cumulatively, this article seeks to demonstrate how, as Australia has severed ties with Britain and its Commonwealth neighbours, it has developed a new focus on, and practice of, internal consistency, with internal divergence carefully regulated by a High Court which sees jurisdiction-specific innovation as contrary to the system devised by the Constitution. The corollary of that trend has been, as James Stellios has remarked, the amplification of the national features of the federal judicial system and a marginalisation of the features that preserve the distinctiveness of the state and territory judicial systems. This in turn has allowed courts such as the NSW Supreme Court to gain an even greater voice within the national judicial conversation. 

Part II of the article provides background to the Farah plainly wrong rule and an explanation of its scope. Part III sets out the history of inter-jurisdictional precedent pre-Marlborough and Part IV sets out the results of the empirical study. Part V then offers some overarching conclusions.

Petitions

'Petitions, Parliament and Political Culture: Petitioning the House of Commons, 1780–1918' by Richard Huzzey and Henry Miller in (2020) 248(1) Past and Present 123–164 analyses 

nearly one million petitions received by the House of Commons to reveal a culture of petitioning that recast the political culture of modern Britain and Ireland. It argues, first, that petitions provided a much more regular and continuous form of interaction between people and Parliament than elections. Second, petitioning–meaning the practices associated with the drafting, signing and presentation of petitions–enabled a vibrant, performative public politics. Third, petitions and petitioning were relatively open, inclusive forms of political participation since all British subjects enjoyed the formal right to petition. We examine the role of formidable campaigns of mass mobilisation, but also humble appeals of marginalised individuals.   
Our data has significant implications for our understanding of the nationalisation, organisation, and popularisation of politics in this period. We argue that attention to petitions helps us to decentre parliamentary elections as the principal connection between local and national politics. Indeed, petitioners responded to the shifting boundaries between the central and devolved state in deciding to which authorities they would direct petitions. 
Petitioning campaigns pioneered the mass, organised, national movements that would gradually emerge as the hallmark of stronger political parties. This did not undermine petitioning. However, the consequent growth of disciplined parties strengthened executive power, at the expense of parliamentary government, redirected petitions from the Commons. Furthermore, the continuing expansion of petitioning alongside extensions of the franchise suggests that petitions did not function as an ersatz ballot. Rather, petitions and debates between parliamentarians and petitioners over the meaning of growing lists of signatories suggest that petitioning catalysed a range of other forms of participation and hence forged an ever more popular politics.