Cyber Insurance Subjectivity Tracker

Rules

Privacy Act lines: Australia

Notifiable Data Breaches Scheme (Australia)

Only when the Privacy Act 1988 applies to the business (the entities APP 11 binds).

edition Privacy Act 1988, Part IIIC, read with the regulator's scheme guide. 5 requirements cited here. Every Notifiable Data Breaches scheme clause we hold.

A data breach response plan exists, and a suspected data breach is assessed within the 30 days the Notifiable Data Breaches scheme sets

ClauseThe held text, and the evidence an assessor asks for
NDB A1
Notifiable Data Breaches scheme
Applicability, Scope, and Data Breach Response Plan

Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of the Australian Information Commissioner (OAIC). The scheme applies to APP entities under section 6(1) of the Privacy Act including Australian Government agencies + private sector organisations with annual turnover above the small business threshold (3 million AUD) or otherwise covered (private health providers + credit reporting bodies + tax file number recipients + employee record holders covered for non-employee records). Document scope of personal information held + applicable specific obligations (credit reporting per Part IIIA + tax file number information). Maintain a Data Breach Response Plan covering roles + response team + decision authority for breach assessment and notification + workflow + templates + contact lists + integration with broader incident response per NIST SP 800-61 or ISO/IEC 27035 + post-incident review + plan testing.

evidence an assessor asks for applicability assessment covering APP entity status + carve-outs (health + credit + TFN); Data Breach Response Plan with roles + workflow + templates + contacts + integration with NIST SP 800-61 or ISO 27035; annual review evidence + tabletop exercise

NDB A2
Notifiable Data Breaches scheme
Containment and 30-Day Assessment of Suspected Eligible Data Breaches

Contain suspected breaches and complete the section 26WH assessment within 30 days per Privacy Act sections 26WH + 26WF. Containment must (a) commence immediately on becoming aware of suspected breach including isolation of affected systems + revocation of compromised credentials + preservation of forensic evidence, (b) integrate with broader incident response runbooks. Assessment per section 26WH must (a) be reasonable and expeditious commencing as soon as practicable after the entity becomes aware that there are reasonable grounds to suspect there may have been an eligible data breach, (b) be completed within 30 days from the day on which the entity becomes aware unless circumstances render that impracticable (rare), (c) determine whether there is unauthorised access or unauthorised disclosure of personal information OR loss of personal information in circumstances where unauthorised access or unauthorised disclosure is likely to occur, AND a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, (d) consider the section 26WG factors for serious harm: kind or kinds of information + sensitivity + protections + persons or kinds of persons who have obtained or could obtain the information + nature of the harm + any other relevant matters. Document the assessment + decision + rationale + evidence in support.

The requirement's own words: within 30 days

evidence an assessor asks for containment SOP + integration with broader IR; assessment workflow + 30-day clock tracking + status meeting cadence; completed assessments with documented section 26WG factor analysis

NDB A3
Notifiable Data Breaches scheme
Eligible Data Breach Determination and Serious Harm Threshold

Determine whether a suspected breach is an eligible data breach per Privacy Act section 26WE + serious harm threshold per section 26WG. An eligible data breach occurs where (a) there is unauthorised access to or unauthorised disclosure of personal information OR a loss of personal information that an entity holds in circumstances where unauthorised access to or unauthorised disclosure of the information is likely to occur, AND (b) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Serious harm assessment per section 26WG considers (a) the kind or kinds of information involved + the sensitivity of the information, (b) whether the information is protected by one or more security measures + the likelihood that any of those security measures could be overcome, (c) the persons or kinds of persons who have obtained or could obtain the information, (d) the nature of the harm including physical + psychological + emotional + financial + reputational + other harm, (e) any other relevant matters. Apply OAIC guidance + community standards + sector-specific considerations (health information + financial information + credentials enabling further harm). Document the determination + rationale + evidence in the breach record. Note the section 26WF exception where remedial action effectively prevents serious harm before unauthorised access or disclosure produces consequences.

evidence an assessor asks for determination per breach with section 26WE elements analysed; serious harm assessment per section 26WG factors documented; remedial action exception (where invoked) per section 26WF with documented decision and evidence

The business knows when and how to notify the Commissioner and the people affected by a data breach the scheme covers

ClauseThe held text, and the evidence an assessor asks for
NDB A4
Notifiable Data Breaches scheme
Notification to the Commissioner: Statement Content and Timing

Prepare and lodge the statement to the Commissioner per Privacy Act sections 26WK + 26WL. Notification must be (a) prepared as soon as practicable after the entity is aware of reasonable grounds to believe that there has been an eligible data breach, (b) lodged with the OAIC via the OAIC Notifiable Data Breach form covering the required content per section 26WK(3): the identity and contact details of the entity + a description of the eligible data breach that the entity has reasonable grounds to believe has happened + the kind or kinds of information concerned + recommendations about the steps that individuals should take in response to the eligible data breach. Where the breach is a joint eligible data breach per section 26WJ involving more than one entity, only one entity is required to comply with section 26WK provided it does so on behalf of all entities. Notification to the OAIC commences the OAIC engagement which may include further requests for information + investigation + remedial action expectations + public commentary. Maintain working liaison with OAIC throughout the response period.

evidence an assessor asks for completed OAIC NDB notification form with section 26WK content; as-soon-as-practicable timing rationale documented; OAIC engagement log + supplementary correspondence

NDB A5
Notifiable Data Breaches scheme
Notification to Affected Individuals: Methods and Content

Notify affected individuals per Privacy Act sections 26WL + 26WM. The entity must take steps as are reasonable in the circumstances to notify the contents of the statement to (a) each of the individuals to whom the relevant information relates (option 1 per section 26WL(2)(a)), OR (b) each of the individuals who are at risk from the eligible data breach (option 2 per section 26WL(2)(b)), OR (c) publish the statement on the entitys website + take reasonable steps to publicise the contents of the statement (option 3 per section 26WL(2)(c)) where it is not practicable for the entity to comply with option 1 or option 2. The notification to individuals must contain the same content as the statement to the Commissioner per section 26WK(3) + may include additional steps tailored to individuals (passwords to change + accounts to monitor + credit monitoring offers + support services). Notification method must be appropriate to the individuals + the breach (email + post + SMS + telephone + secure portal message) with consideration for accessibility + language + vulnerable persons. Document the notification method + content + reach + responses + complaints + remedial measures.

evidence an assessor asks for notification method record per breach (option 1/2/3 per section 26WL(2)) with rationale; notification content matching section 26WK(3) plus individual-specific guidance; delivery evidence + complaint handling + remedial measures uptake

Questions

When does Notifiable Data Breaches scheme apply here?
Only when the Privacy Act 1988 applies to the business (the entities APP 11 binds).
Which edition is held?
Privacy Act 1988, Part IIIC, read with the regulator's scheme guide
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.