Controls / Privacy Act (Australia)
A data breach response plan exists, and a suspected data breach is assessed within the 30 days the Notifiable Data Breaches scheme sets
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write a data breach response plan, including how a suspected data breach is assessed within 30 days.
In Australia
Only when the Privacy Act 1988 applies to the business.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| NDB A1 Notifiable Data Breaches scheme | Applicability, Scope, and Data Breach Response Plan Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of the Australian Information Commissioner (OAIC). The scheme applies to APP entities under section 6(1) of the Privacy Act including Australian Government agencies + private sector organisations with annual turnover above the small business threshold (3 million AUD) or otherwise covered (private health providers + credit reporting bodies + tax file number recipients + employee record holders covered for non-employee records). Document scope of personal information held + applicable specific obligations (credit reporting per Part IIIA + tax file number information). Maintain a Data Breach Response Plan covering roles + response team + decision authority for breach assessment and notification + workflow + templates + contact lists + integration with broader incident response per NIST SP 800-61 or ISO/IEC 27035 + post-incident review + plan testing. evidence an assessor asks for applicability assessment covering APP entity status + carve-outs (health + credit + TFN); Data Breach Response Plan with roles + workflow + templates + contacts + integration with NIST SP 800-61 or ISO 27035; annual review evidence + tabletop exercise |
| NDB A2 Notifiable Data Breaches scheme | Containment and 30-Day Assessment of Suspected Eligible Data Breaches Contain suspected breaches and complete the section 26WH assessment within 30 days per Privacy Act sections 26WH + 26WF. Containment must (a) commence immediately on becoming aware of suspected breach including isolation of affected systems + revocation of compromised credentials + preservation of forensic evidence, (b) integrate with broader incident response runbooks. Assessment per section 26WH must (a) be reasonable and expeditious commencing as soon as practicable after the entity becomes aware that there are reasonable grounds to suspect there may have been an eligible data breach, (b) be completed within 30 days from the day on which the entity becomes aware unless circumstances render that impracticable (rare), (c) determine whether there is unauthorised access or unauthorised disclosure of personal information OR loss of personal information in circumstances where unauthorised access or unauthorised disclosure is likely to occur, AND a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, (d) consider the section 26WG factors for serious harm: kind or kinds of information + sensitivity + protections + persons or kinds of persons who have obtained or could obtain the information + nature of the harm + any other relevant matters. Document the assessment + decision + rationale + evidence in support. The requirement's own words: within 30 days evidence an assessor asks for containment SOP + integration with broader IR; assessment workflow + 30-day clock tracking + status meeting cadence; completed assessments with documented section 26WG factor analysis |
| NDB A3 Notifiable Data Breaches scheme | Eligible Data Breach Determination and Serious Harm Threshold Determine whether a suspected breach is an eligible data breach per Privacy Act section 26WE + serious harm threshold per section 26WG. An eligible data breach occurs where (a) there is unauthorised access to or unauthorised disclosure of personal information OR a loss of personal information that an entity holds in circumstances where unauthorised access to or unauthorised disclosure of the information is likely to occur, AND (b) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Serious harm assessment per section 26WG considers (a) the kind or kinds of information involved + the sensitivity of the information, (b) whether the information is protected by one or more security measures + the likelihood that any of those security measures could be overcome, (c) the persons or kinds of persons who have obtained or could obtain the information, (d) the nature of the harm including physical + psychological + emotional + financial + reputational + other harm, (e) any other relevant matters. Apply OAIC guidance + community standards + sector-specific considerations (health information + financial information + credentials enabling further harm). Document the determination + rationale + evidence in the breach record. Note the section 26WF exception where remedial action effectively prevents serious harm before unauthorised access or disclosure produces consequences. evidence an assessor asks for determination per breach with section 26WE elements analysed; serious harm assessment per section 26WG factors documented; remedial action exception (where invoked) per section 26WF with documented decision and evidence |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 90 by the default rule: a Privacy Act line. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.