<!--The Official Report of Parliamentary Debates (Hansard) of the Legislative Council and the House of Assembly of the Parliament of South Australia are covered by parliamentary privilege. Republication by others is not afforded the same protection and may result in exposure to legal liability if the material is defamatory. You may copy and make use of excerpts of proceedings where (1) you attribute the Parliament as the source, (2) you assume the risk of liability if the manner of your use is defamatory, (3) you do not use the material for the purpose of advertising, satire or ridicule, or to misrepresent members of Parliament, and (4) your use of the extracts is fair, accurate and not misleading. Copyright in the Official Report of Parliamentary Debates is held by the Attorney-General of South Australia.-->
<hansard id="" tocId="" xml:lang="EN-AU" schemaVersion="1.0" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:xsi="http://www.w3.org/2007/XMLSchema-instance" xmlns:mml="http://www.w3.org/1998/Math/MathML" xsi:noNamespaceSchemaLocation="hansard_1_0.xsd">
  <name>House of Assembly</name>
  <date date="2021-10-13" />
  <sessionName>Fifty-Fourth Parliament, Second Session (54-2)</sessionName>
  <parliamentNum>54</parliamentNum>
  <sessionNum>2</sessionNum>
  <parliamentName>Parliament of South Australia</parliamentName>
  <house>House of Assembly</house>
  <venue></venue>
  <reviewStage>published</reviewStage>
  <startPage num="7706" />
  <endPage num="8127" />
  <dateModified time="2022-08-06T14:30:00+00:00" />
  <proceeding continued="true">
    <name>Question Time</name>
    <subject>
      <name>COVID-19 QR Codes</name>
      <text id="20211013ecbabf7cbdce4732a0000495">
        <heading>COVID-19 QR Codes</heading>
      </text>
      <talker role="member" id="4841" kind="question">
        <name>Mr PICTON</name>
        <house>House of Assembly</house>
        <electorate id="">Kaurna</electorate>
        <questions>
          <question date="2021-10-13">
            <name>COVID-19 QR Codes</name>
          </question>
        </questions>
        <startTime time="2021-10-13T14:32:42" />
        <text id="20211013ecbabf7cbdce4732a0000496">
          <timeStamp time="2021-10-13T14:32:42" />
          <by role="member" id="4841">Mr PICTON (Kaurna) (14:32):</by>  My question is to the Premier. Is the Premier concerned that in spite of his promise that all QR data would be deleted within 28 days, in some instances it is being kept indefinitely and is he concerned it affects public confidence in the scheme? With your leave, sir, and that of the house, I will explain.</text>
        <text id="20211013ecbabf7cbdce4732a0000497">Leave granted.</text>
      </talker>
      <talker role="member" id="4841" kind="question" continued="true">
        <name>Mr PICTON</name>
        <house>House of Assembly</house>
        <text id="20211013ecbabf7cbdce4732a0000498">
          <by role="member" id="4841">Mr PICTON:</by>  In the report tabled yesterday in regard to the COVID-SAfe check-in system, the Auditor-General found that data had been retained by the Department of the Premier and Cabinet indefinitely as a backup for the system but also by the Department for Health indefinitely under its obligations under the Health Care Act.</text>
      </talker>
      <talker role="member" id="4338" kind="answer">
        <name>The Hon. S.S. MARSHALL</name>
        <house>House of Assembly</house>
        <electorate id="">Dunstan</electorate>
        <portfolios>
          <portfolio id="">
            <name>Premier</name>
          </portfolio>
        </portfolios>
        <startTime time="2021-10-13T14:33:26" />
        <text id="20211013ecbabf7cbdce4732a0000499">
          <timeStamp time="2021-10-13T14:33:26" />
          <by role="member" id="4338">The Hon. S.S. MARSHALL (Dunstan—Premier) (14:33):</by>  I think I answered this in the previous question, but I'm happy to go through it again. We have a situation where we are asking people to use the QR code check-in. That gives us some basic information as to who the person checking in is, where they were and what time. This is encrypted. It goes into the Department of the Premier and Cabinet. It's destroyed after 28 days.</text>
        <page num="8004" />
        <text id="20211013ecbabf7cbdce4732a0000500">As part of the overall whole-of-government IT management system, there is a backup which is kept, but there are very strict protocols about the restoration of that data; moreover, the Auditor-General identifies in his report that if there is a restoration of that data any data older than 28 days is again automatically destroyed. I don't think that there is any breach with what we have already said to the people of South Australia. Their data is extraordinarily protected, and I think that's borne out in the Auditor-General's Report.</text>
        <text id="20211013ecbabf7cbdce4732a0000501">I just remind the house that it was actually the government that asked the Auditor-General to do this review so that we could have assurance, the people of South Australia could have assurance. Those opposite might want to run a scare campaign. They may want to undermine what I think is an excellent system. Let me tell you what Grant Stevens, the police commissioner, the State Coordinator during this major emergency declaration, had to say this morning. He said:</text>
        <text id="20211013ecbabf7cbdce4732a0000502">
          <inserted>I am absolutely confident that the intent and commitment that was made to destroy data is being honoured and I think DPC have done an amazing job in developing a system that has withstood the tests that are being put to it in terms of the volume of people who are using the system every single day and maintain that commitment to delete the data, I would remind people that we've probably got the best QR…system in Australia…</inserted>
        </text>
        <text continued="true" id="20211013ecbabf7cbdce4732a0000503">They are the words of the State Coordinator. We also have extraordinarily complimentary words from the Auditor-General, and I quote from page 2:</text>
        <text id="20211013ecbabf7cbdce4732a0000504">
          <inserted>Overall, I concluded that reasonable controls were applied by DPC and SA Health to protect people's contact details obtained through the COVID-SAFE Check-In app. I note this is a point in time review and opinion.</inserted>
        </text>
        <text continued="true" id="20211013ecbabf7cbdce4732a0000505">He goes into quite a lot of detail, and I would encourage all members of the house to take a look at this report. We thank the Auditor-General for his comprehensive review because it is important that people need to know that when they do use the QR code check-in in South Australia there is not unauthorised use of that data. In other jurisdictions, they didn't have a central QR code check-in mechanism. In fact, in some places it was left up to individual venues. It then begs the question: who is going to use that information?</text>
        <text id="20211013ecbabf7cbdce4732a0000506">For example, you go along to a pub. Yes, you are checking in when you go to the pub, but does that pub have the opportunity then to use that information for marketing purposes? That cannot happen with this South Australian system. We respect the fact that we need this information to keep our state safe and our economy strong, and that's why we put in, I think, the very best system in Australia. But don't take my word for it: take the word of the police commissioner, the State Coordinator, Grant Stevens.</text>
      </talker>
    </subject>
  </proceeding>
</hansard>