Notifiable Data Breaches Scheme (Australia)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Applicability and Response Plan
Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of the Australian Information Commissioner (OAIC). The scheme applies to APP entities under section 6(1) of the Privacy Act including Australian Government agencies + private sector organisations with annual turnover above the small business threshold (3 million AUD) or otherwise covered (private health providers + credit reporting bodies + tax file number recipients + employee record holders covered for non-employee records). Document scope of personal information held + applicable specific obligations (credit reporting per Part IIIA + tax file number information). Maintain a Data Breach Response Plan covering roles + response team +
- applicability assessment covering APP entity status + carve-outs (health + credit + TFN)
- Data Breach Response Plan with roles + workflow + templates + contacts + integration with NIST SP 800-61 or ISO 27035
- annual review evidence + tabletop exercise
- small business assumed exempt without considering section 6D/6E carve-outs
- response plan exists but unused / unfamiliar to personnel
- no tabletop exercise
Containment and Assessment
Contain suspected breaches and complete the section 26WH assessment within 30 days per Privacy Act sections 26WH + 26WF. Containment must (a) commence immediately on becoming aware of suspected breach including isolation of affected systems + revocation of compromised credentials + preservation of forensic evidence, (b) integrate with broader incident response runbooks. Assessment per section 26WH must (a) be reasonable and expeditious commencing as soon as practicable after the entity becomes aware that there are reasonable grounds to suspect there may have been an eligible data breach, (b) be completed within 30 days from the day on which the entity becomes aware unless circumstances render that impracticable (rare), (c) determine whether there is unauthorised access or unauthorised disclosure of personal information OR loss of personal information in circumstances where unauthorised a
- containment SOP + integration with broader IR
- assessment workflow + 30-day clock tracking + status meeting cadence
- completed assessments with documented section 26WG factor analysis
- assessment commences late because awareness criterion misunderstood
- 30-day clock not tracked producing missed regulatory deadline
- section 26WG factors not analysed in writing
Eligible Data Breach Determination
Determine whether a suspected breach is an eligible data breach per Privacy Act section 26WE + serious harm threshold per section 26WG. An eligible data breach occurs where (a) there is unauthorised access to or unauthorised disclosure of personal information OR a loss of personal information that an entity holds in circumstances where unauthorised access to or unauthorised disclosure of the information is likely to occur, AND (b) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Serious harm assessment per section 26WG considers (a) the kind or kinds of information involved + the sensitivity of the information, (b) whether the information is protected by one or more security measures + the likelihood that any of those security measures could be overcome, (c) the persons or
- determination per breach with section 26WE elements analysed
- serious harm assessment per section 26WG factors documented
- remedial action exception (where invoked) per section 26WF with documented decision and evidence
- serious harm assessed categorically rather than per affected individuals + threat actor
- remedial action exception claimed but action did not genuinely prevent harm
- no documented determination so cannot be defended
Exceptions and Joint Handling
Apply the statutory exceptions per Privacy Act sections 26WF + 26WJ + 26WM(3) + 26WP. Remedial action exception per section 26WF: where the entity takes action before the unauthorised access or unauthorised disclosure results in serious harm to any individuals to whom the relevant information relates + a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals as a result of that action, the breach is not an eligible data breach. Document the remedial action + decision + rationale + evidence. Joint handling exception per section 26WJ: where two or more entities jointly and simultaneously hold personal information and the eligible data breach affects all of them, only one entity needs to comply per the documented agreement among them. Enforcement exception per section 26WP: certain enforcement bodies are exemp
- remedial action exception decision per section 26WF with legal advice + evidence
- joint handling agreement among multiple entities per section 26WJ
- enforcement exception application per section 26WP where invoked
- remedial action exception applied without documented evidence harm is no longer likely
- joint handling agreement absent producing duplicate or contradictory notifications
- exceptions applied broadly without legal basis
Notification to Individuals
Notify affected individuals per Privacy Act sections 26WL + 26WM. The entity must take steps as are reasonable in the circumstances to notify the contents of the statement to (a) each of the individuals to whom the relevant information relates (option 1 per section 26WL(2)(a)), OR (b) each of the individuals who are at risk from the eligible data breach (option 2 per section 26WL(2)(b)), OR (c) publish the statement on the entitys website + take reasonable steps to publicise the contents of the statement (option 3 per section 26WL(2)(c)) where it is not practicable for the entity to comply with option 1 or option 2. The notification to individuals must contain the same content as the statement to the Commissioner per section 26WK(3) + may include additional steps tailored to individuals (passwords to change + accounts to monitor + credit monitoring offers + support services). Notificatio
- notification method record per breach (option 1/2/3 per section 26WL(2)) with rationale
- notification content matching section 26WK(3) plus individual-specific guidance
- delivery evidence + complaint handling + remedial measures uptake
- option 3 website publication used without documented impracticability of option 1/2
- notification content omits remediation guidance for individuals
- delivery method inaccessible for vulnerable persons
Notification to OAIC
Prepare and lodge the statement to the Commissioner per Privacy Act sections 26WK + 26WL. Notification must be (a) prepared as soon as practicable after the entity is aware of reasonable grounds to believe that there has been an eligible data breach, (b) lodged with the OAIC via the OAIC Notifiable Data Breach form covering the required content per section 26WK(3): the identity and contact details of the entity + a description of the eligible data breach that the entity has reasonable grounds to believe has happened + the kind or kinds of information concerned + recommendations about the steps that individuals should take in response to the eligible data breach. Where the breach is a joint eligible data breach per section 26WJ involving more than one entity, only one entity is required to comply with section 26WK provided it does so on behalf of all entities. Notification to the OAIC com
- completed OAIC NDB notification form with section 26WK content
- as-soon-as-practicable timing rationale documented
- OAIC engagement log + supplementary correspondence
- notification delayed beyond as-soon-as-practicable
- statement content incomplete missing 26WK(3) elements
- no ongoing OAIC engagement after initial notification
Recordkeeping and Governance
Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations. Recordkeeping must capture every suspected breach + assessment + decision + notification + remedial action + outcome with chain of custody appropriate to potential regulatory + civil litigation + criminal investigation use. Communications strategy for high impact breaches must coordinate (a) OAIC engagement, (b) individuals communication, (c) sector regulator engagement (APRA + ASIC + ACMA + state regulators), (d) law enforcement engagement (Australian Federal Police + state police + ACSC), (e) media engagement managed by communications professionals, (f) consumer support (call centre + portal + credit monitoring + identity remediation services), (g) employee communication, (h) shareholder and partner communication, (i) insur
- breach register with assessment + decision + notification + remedial + outcome per breach
- communications strategy for high-impact breach including OAIC + individuals + regulator + law enforcement + media + consumer support + employees + shareholders
- post-incident review reports with findings + closure tracking
- board / audit committee reporting evidence + annual programme report
- recordkeeping informal and incomplete producing exposure in civil litigation
- no communications strategy producing chaotic response to high-impact breach
- post-incident review skipped + recommendations not closed
- board not informed of material breaches
Specific Categories and Third-Party
Handle specific information categories + third-party and cloud coordination + OAIC guidance updates per Privacy Act + OAIC NDB guidance. Specific information categories with enhanced obligations or considerations: (a) Credit reporting information per Part IIIA + section 26WD has supplementary notification obligations and the Commissioner can be notified per the Credit Reporting Code, (b) Tax File Number information has supplementary considerations under the Privacy (Tax File Number) Rule 2015, (c) Health information per the Privacy Act + state health records legislation may invoke parallel obligations under state regulators (Health Records Privacy Commissioner Victoria + Health Care Complaints Commission NSW + similar), (d) My Health Record information has separate obligations under the My Health Records Act 2012, (e) Children information requires sensitivity in notification and remedial
- specific category handling (credit + TFN + health + My Health Record + children) with supplementary notification process
- third-party / cloud provider breach notification clauses + supplier breach register + escalation path
- OAIC guidance monitoring + update incorporation into response plan + workforce communications
- specific categories handled generically missing supplementary obligations
- supplier breach notification SLAs absent producing late entity-level notification
- OAIC guidance updates not monitored producing stale response practice
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Notifiable Data Breaches Scheme (Australia) framework page.