Skip to content

Evidence request lists

Notifiable Data Breaches Scheme (Australia)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Applicability and Response Plan

AUNDB-A1
Applicability, Scope, and Data Breach Response Plan

Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of the Australian Information Commissioner (OAIC). The scheme applies to APP entities under section 6(1) of the Privacy Act including Australian Government agencies + private sector organisations with annual turnover above the small business threshold (3 million AUD) or otherwise covered (private health providers + credit reporting bodies + tax file number recipients + employee record holders covered for non-employee records). Document scope of personal information held + applicable specific obligations (credit reporting per Part IIIA + tax file number information). Maintain a Data Breach Response Plan covering roles + response team +

Artefacts an auditor will ask for
  • applicability assessment covering APP entity status + carve-outs (health + credit + TFN)
  • Data Breach Response Plan with roles + workflow + templates + contacts + integration with NIST SP 800-61 or ISO 27035
  • annual review evidence + tabletop exercise
Where this commonly fails
  • small business assumed exempt without considering section 6D/6E carve-outs
  • response plan exists but unused / unfamiliar to personnel
  • no tabletop exercise

Containment and Assessment

AUNDB-A2
Containment and 30-Day Assessment of Suspected Eligible Data Breaches

Contain suspected breaches and complete the section 26WH assessment within 30 days per Privacy Act sections 26WH + 26WF. Containment must (a) commence immediately on becoming aware of suspected breach including isolation of affected systems + revocation of compromised credentials + preservation of forensic evidence, (b) integrate with broader incident response runbooks. Assessment per section 26WH must (a) be reasonable and expeditious commencing as soon as practicable after the entity becomes aware that there are reasonable grounds to suspect there may have been an eligible data breach, (b) be completed within 30 days from the day on which the entity becomes aware unless circumstances render that impracticable (rare), (c) determine whether there is unauthorised access or unauthorised disclosure of personal information OR loss of personal information in circumstances where unauthorised a

Artefacts an auditor will ask for
  • containment SOP + integration with broader IR
  • assessment workflow + 30-day clock tracking + status meeting cadence
  • completed assessments with documented section 26WG factor analysis
Where this commonly fails
  • assessment commences late because awareness criterion misunderstood
  • 30-day clock not tracked producing missed regulatory deadline
  • section 26WG factors not analysed in writing

Eligible Data Breach Determination

AUNDB-A3
Eligible Data Breach Determination and Serious Harm Threshold

Determine whether a suspected breach is an eligible data breach per Privacy Act section 26WE + serious harm threshold per section 26WG. An eligible data breach occurs where (a) there is unauthorised access to or unauthorised disclosure of personal information OR a loss of personal information that an entity holds in circumstances where unauthorised access to or unauthorised disclosure of the information is likely to occur, AND (b) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Serious harm assessment per section 26WG considers (a) the kind or kinds of information involved + the sensitivity of the information, (b) whether the information is protected by one or more security measures + the likelihood that any of those security measures could be overcome, (c) the persons or

Artefacts an auditor will ask for
  • determination per breach with section 26WE elements analysed
  • serious harm assessment per section 26WG factors documented
  • remedial action exception (where invoked) per section 26WF with documented decision and evidence
Where this commonly fails
  • serious harm assessed categorically rather than per affected individuals + threat actor
  • remedial action exception claimed but action did not genuinely prevent harm
  • no documented determination so cannot be defended

Exceptions and Joint Handling

AUNDB-A6
Exceptions: Remedial Action, Enforcement, Multiple Entities, Inconsistency with Other Law

Apply the statutory exceptions per Privacy Act sections 26WF + 26WJ + 26WM(3) + 26WP. Remedial action exception per section 26WF: where the entity takes action before the unauthorised access or unauthorised disclosure results in serious harm to any individuals to whom the relevant information relates + a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals as a result of that action, the breach is not an eligible data breach. Document the remedial action + decision + rationale + evidence. Joint handling exception per section 26WJ: where two or more entities jointly and simultaneously hold personal information and the eligible data breach affects all of them, only one entity needs to comply per the documented agreement among them. Enforcement exception per section 26WP: certain enforcement bodies are exemp

Artefacts an auditor will ask for
  • remedial action exception decision per section 26WF with legal advice + evidence
  • joint handling agreement among multiple entities per section 26WJ
  • enforcement exception application per section 26WP where invoked
Where this commonly fails
  • remedial action exception applied without documented evidence harm is no longer likely
  • joint handling agreement absent producing duplicate or contradictory notifications
  • exceptions applied broadly without legal basis

Notification to Individuals

AUNDB-A5
Notification to Affected Individuals: Methods and Content

Notify affected individuals per Privacy Act sections 26WL + 26WM. The entity must take steps as are reasonable in the circumstances to notify the contents of the statement to (a) each of the individuals to whom the relevant information relates (option 1 per section 26WL(2)(a)), OR (b) each of the individuals who are at risk from the eligible data breach (option 2 per section 26WL(2)(b)), OR (c) publish the statement on the entitys website + take reasonable steps to publicise the contents of the statement (option 3 per section 26WL(2)(c)) where it is not practicable for the entity to comply with option 1 or option 2. The notification to individuals must contain the same content as the statement to the Commissioner per section 26WK(3) + may include additional steps tailored to individuals (passwords to change + accounts to monitor + credit monitoring offers + support services). Notificatio

Artefacts an auditor will ask for
  • notification method record per breach (option 1/2/3 per section 26WL(2)) with rationale
  • notification content matching section 26WK(3) plus individual-specific guidance
  • delivery evidence + complaint handling + remedial measures uptake
Where this commonly fails
  • option 3 website publication used without documented impracticability of option 1/2
  • notification content omits remediation guidance for individuals
  • delivery method inaccessible for vulnerable persons

Notification to OAIC

AUNDB-A4
Notification to the Commissioner: Statement Content and Timing

Prepare and lodge the statement to the Commissioner per Privacy Act sections 26WK + 26WL. Notification must be (a) prepared as soon as practicable after the entity is aware of reasonable grounds to believe that there has been an eligible data breach, (b) lodged with the OAIC via the OAIC Notifiable Data Breach form covering the required content per section 26WK(3): the identity and contact details of the entity + a description of the eligible data breach that the entity has reasonable grounds to believe has happened + the kind or kinds of information concerned + recommendations about the steps that individuals should take in response to the eligible data breach. Where the breach is a joint eligible data breach per section 26WJ involving more than one entity, only one entity is required to comply with section 26WK provided it does so on behalf of all entities. Notification to the OAIC com

Artefacts an auditor will ask for
  • completed OAIC NDB notification form with section 26WK content
  • as-soon-as-practicable timing rationale documented
  • OAIC engagement log + supplementary correspondence
Where this commonly fails
  • notification delayed beyond as-soon-as-practicable
  • statement content incomplete missing 26WK(3) elements
  • no ongoing OAIC engagement after initial notification

Recordkeeping and Governance

AUNDB-A7
Recordkeeping, Communications Strategy, Post-Incident Review, Board Reporting

Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations. Recordkeeping must capture every suspected breach + assessment + decision + notification + remedial action + outcome with chain of custody appropriate to potential regulatory + civil litigation + criminal investigation use. Communications strategy for high impact breaches must coordinate (a) OAIC engagement, (b) individuals communication, (c) sector regulator engagement (APRA + ASIC + ACMA + state regulators), (d) law enforcement engagement (Australian Federal Police + state police + ACSC), (e) media engagement managed by communications professionals, (f) consumer support (call centre + portal + credit monitoring + identity remediation services), (g) employee communication, (h) shareholder and partner communication, (i) insur

Artefacts an auditor will ask for
  • breach register with assessment + decision + notification + remedial + outcome per breach
  • communications strategy for high-impact breach including OAIC + individuals + regulator + law enforcement + media + consumer support + employees + shareholders
  • post-incident review reports with findings + closure tracking
  • board / audit committee reporting evidence + annual programme report
Where this commonly fails
  • recordkeeping informal and incomplete producing exposure in civil litigation
  • no communications strategy producing chaotic response to high-impact breach
  • post-incident review skipped + recommendations not closed
  • board not informed of material breaches

Specific Categories and Third-Party

AUNDB-A8
Specific Information Categories, Third-Party and Cloud Coordination, OAIC Guidance Updates

Handle specific information categories + third-party and cloud coordination + OAIC guidance updates per Privacy Act + OAIC NDB guidance. Specific information categories with enhanced obligations or considerations: (a) Credit reporting information per Part IIIA + section 26WD has supplementary notification obligations and the Commissioner can be notified per the Credit Reporting Code, (b) Tax File Number information has supplementary considerations under the Privacy (Tax File Number) Rule 2015, (c) Health information per the Privacy Act + state health records legislation may invoke parallel obligations under state regulators (Health Records Privacy Commissioner Victoria + Health Care Complaints Commission NSW + similar), (d) My Health Record information has separate obligations under the My Health Records Act 2012, (e) Children information requires sensitivity in notification and remedial

Artefacts an auditor will ask for
  • specific category handling (credit + TFN + health + My Health Record + children) with supplementary notification process
  • third-party / cloud provider breach notification clauses + supplier breach register + escalation path
  • OAIC guidance monitoring + update incorporation into response plan + workforce communications
Where this commonly fails
  • specific categories handled generically missing supplementary obligations
  • supplier breach notification SLAs absent producing late entity-level notification
  • OAIC guidance updates not monitored producing stale response practice
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Notifiable Data Breaches Scheme (Australia) framework page.