Controls / Privacy Act (Australia)
The business knows when and how to notify the Commissioner and the people affected by a data breach the scheme covers
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write down when and how you notify the Commissioner and the people affected by a data breach the scheme covers.
In Australia
Only when the Privacy Act 1988 applies to the business.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| NDB A4 Notifiable Data Breaches scheme | Notification to the Commissioner: Statement Content and Timing Prepare and lodge the statement to the Commissioner per Privacy Act sections 26WK + 26WL. Notification must be (a) prepared as soon as practicable after the entity is aware of reasonable grounds to believe that there has been an eligible data breach, (b) lodged with the OAIC via the OAIC Notifiable Data Breach form covering the required content per section 26WK(3): the identity and contact details of the entity + a description of the eligible data breach that the entity has reasonable grounds to believe has happened + the kind or kinds of information concerned + recommendations about the steps that individuals should take in response to the eligible data breach. Where the breach is a joint eligible data breach per section 26WJ involving more than one entity, only one entity is required to comply with section 26WK provided it does so on behalf of all entities. Notification to the OAIC commences the OAIC engagement which may include further requests for information + investigation + remedial action expectations + public commentary. Maintain working liaison with OAIC throughout the response period. evidence an assessor asks for completed OAIC NDB notification form with section 26WK content; as-soon-as-practicable timing rationale documented; OAIC engagement log + supplementary correspondence |
| NDB A5 Notifiable Data Breaches scheme | Notification to Affected Individuals: Methods and Content Notify affected individuals per Privacy Act sections 26WL + 26WM. The entity must take steps as are reasonable in the circumstances to notify the contents of the statement to (a) each of the individuals to whom the relevant information relates (option 1 per section 26WL(2)(a)), OR (b) each of the individuals who are at risk from the eligible data breach (option 2 per section 26WL(2)(b)), OR (c) publish the statement on the entitys website + take reasonable steps to publicise the contents of the statement (option 3 per section 26WL(2)(c)) where it is not practicable for the entity to comply with option 1 or option 2. The notification to individuals must contain the same content as the statement to the Commissioner per section 26WK(3) + may include additional steps tailored to individuals (passwords to change + accounts to monitor + credit monitoring offers + support services). Notification method must be appropriate to the individuals + the breach (email + post + SMS + telephone + secure portal message) with consideration for accessibility + language + vulnerable persons. Document the notification method + content + reach + responses + complaints + remedial measures. evidence an assessor asks for notification method record per breach (option 1/2/3 per section 26WL(2)) with rationale; notification content matching section 26WK(3) plus individual-specific guidance; delivery evidence + complaint handling + remedial measures uptake |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 90 by the default rule: a Privacy Act line. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.