Data Breach Response Plan for Australian Organisations
A data breach response plan tells your team what to do in the first hours after personal information is exposed. This guide covers the four response steps, the OAIC notification rules and how to document the plan.
Contain, Assess, Notify, Review
The four steps the OAIC expects every organisation to follow.
Read SectionWhen You Must Report
How the 30-day assessment window and serious harm test work.
Read SectionWhat the Plan Contains
The roles, contacts and records to prepare before an incident.
Read SectionA data breach response plan is a short, written procedure for handling the loss, theft or unauthorised access of personal information. Under the Privacy Act, many Australian organisations must notify affected people and the OAIC when a breach is likely to cause serious harm, so a plan is the practical way to meet that duty on time.
The steps below follow the framework the OAIC publishes. They also fit alongside a wider cyber incident response plan and procedure, which covers the technical side of the same event.
The Four Steps of a Data Breach Response Plan
The OAIC describes four steps. Each one should have a named owner in your plan.
- Contain: Stop the breach from spreading. Isolate affected systems, revoke stolen credentials and recover any data you can.
- Assess: Work out what was exposed, who is affected and whether serious harm is likely. Record the evidence you used.
- Notify: Tell affected individuals and the OAIC where the law requires it, and consider others such as insurers and banks.
- Review: Find the root cause, fix it and update the plan so the same event cannot repeat.
In real incidents, steps overlap. Containment is often still running when assessment begins, so the plan should let both happen at once.
What Counts as an Eligible Data Breach
The Notifiable Data Breaches scheme applies to an eligible data breach. That means unauthorised access to, or disclosure or loss of, personal information that is likely to result in serious harm to the people involved.
Examples include a phishing attack that exposes customer records, a laptop with unencrypted client files that is stolen, or an email with sensitive attachments sent to the wrong recipient. Harm can be financial, physical, emotional or reputational, and the likelihood is judged from the viewpoint of a reasonable person.
If remedial action removes the likelihood of serious harm, notification may not be required. However, your plan should say who makes that call and how it is recorded.
Handling personal information? Our privacy risk and compliance service helps you test whether your plan meets Privacy Act expectations.
OAIC Data Breach Response Plan Timelines and Notification
When you suspect an eligible breach, you must carry out a reasonable assessment within 30 days. If the assessment confirms the breach, notify the OAIC and affected individuals as soon as practicable.
The statement you give should include your contact details, a description of the breach, the kinds of information involved and the steps people should take. The Office of the Australian Information Commissioner publishes the form and detailed guidance. A good plan includes a draft notification template so nobody writes one from scratch under pressure.
Some entities have extra duties. Regulated financial institutions, for instance, face reporting expectations under APRA CPS 234, and critical infrastructure owners may need to report cyber incidents under the SOCI Act.
What to Put in Your Data Breach Response Plan
First, keep the document short enough to read during a crisis. Most effective plans cover the same core items.
- A response team with names, backups and out-of-hours contact details
- A simple severity scale and the point at which staff must escalate
- Steps for containment and for preserving evidence
- The assessment process and who decides whether harm is likely
- Notification templates for individuals, the OAIC and other parties
- A log for recording decisions, times and evidence
Store at least one copy outside your main network. If ransomware locks your files, the plan must still be reachable.
Testing and Improving the Plan
A plan that has never been tested usually fails on the details. Run a tabletop exercise once a year using a realistic scenario, such as a supplier breach that exposes customer data. Check that people know who decides, who writes the notification and who speaks to the media.
After the exercise, update the document and record the lessons. If you want a structure to start from, our cyber incident response plan template lists the sections most plans need, and privacy impact assessments help you reduce the amount of personal data at risk in the first place.
Need a data breach response plan that matches your systems and obligations?
Get in TouchFrequently Asked Questions
It is a written procedure that sets out how your organisation will contain, assess, notify and review a breach of personal information, with named owners for each step.
The Privacy Act does not require a plan by name, but organisations covered by the Notifiable Data Breaches scheme must assess and report eligible breaches, and a plan is the practical way to do that.
You must complete a reasonable assessment within 30 days of becoming aware of reasonable grounds to suspect an eligible breach, and act as quickly as you can.
Affected individuals and the OAIC, where the breach is likely to cause serious harm. Insurers, banks and regulators may also need to hear from you.
Review it at least yearly, and after any incident, major system change or change in key response staff.