Notifiable Data Breach

Purpose
This policy sets out how Provider Assist (PA) identifies, contains, assesses and responds to data breaches, including obligations under the Notifiable Data Breaches (NDB) scheme (Privacy Act 1988, as amended) and under PA’s client contractual obligations.

 

What is a Data Breach?
A data breach occurs when personal information or client data held by PA is lost, accessed, modified, disclosed or misused without authorisation. There are two tiers:

  • Notifiable breach — likely to cause serious harm to one or more individuals; triggers OAIC notification obligations

  • Client Data Security Breach — any unauthorised loss, disclosure or circumvention of security measures involving a client’s data or confidential information (including introduction of harmful code); triggers client notification obligations regardless of whether the NDB threshold is met


Client contractual obligations apply at a lower threshold than the NDB scheme. When in doubt, treat it as a Client Data Security Breach and notify.

 

Roles & Responsibilities

  • All PA staff and contractors — report suspected breaches immediately to their manager
  • Information & Systems Team — initial triage, containment and technical response
  • CEO (or nominated deputy) — overall accountability, OAIC notification, client notification, breach register, remediation coordination

 


Response Process
Follow these five steps for any suspected or confirmed breach:

  1. Report
    Any employee or contractor who suspects a breach must notify their manager immediately. The manager escalates to the Information & Systems Team and CEO within 24 hours.

  1. Contain
    Take immediate steps to limit the breach. This may include:
    • Shutting down or isolating affected systems
    • Revoking compromised access credentials
    • Recovering lost or misdirected records
    • Alerting building security if physical records are involved

  1. Assess
    The CEO (or response team) must complete a breach assessment within 30 days of becoming aware of a suspected eligible breach. The assessment determines:
    • What information was involved and who is affected
    • Whether the breach involves client data (triggering contractual obligations)
    • Whether individuals are at serious risk of harm (triggering NDB obligations)
    • What remedial action has been or can be taken


If remedial action fully eliminates the risk of serious harm, OAIC notification may not be required. Document this decision.

  1. Notify
    Notification obligations depend on breach type:


Client Data Security Breach:

    • Notify the affected client within 72 hours of confirming the breach
    • Provide known details of the breach and remedial steps taken
    • Assist the client with reasonable remediation activities within PA’s systems and control


“Immediately” in client contracts is interpreted as within 72 hours of confirmation. PA is only obliged to disclose known details at the time of notification; updates should follow as further information becomes available.

Notifiable Data Breach (NDB):

    • Notify affected individuals as soon as practicable
    • Notify the OAIC within 30 days of completing the assessment
    • Publish notification on PA’s website if direct notification is not practicable

Other reporting (where applicable):

    • Australian Federal Police — criminal activity or hacking
    • Australian Cyber Security Centre — significant cyber incidents
    • ASIC, APRA or ATO — where financially regulated data is involved

  1. Review
    Following every breach, the CEO must ensure:
    • Root cause is fully investigated and documented
    • A prevention plan is developed and implemented
    • Security policies, procedures and staff training are updated as required
    • The breach register entry is finalised with all outcomes and actions

 

Record Keeping
All breaches (including those below the NDB threshold) must be recorded in PA’s breach register. Each entry must capture: nature of breach, data and systems involved, date occurred, date discovered, date of notifications, remedial steps taken and outcome.

 

Interaction with Other Laws
A data breach may engage overlapping legal obligations. The CEO will determine the appropriate response with legal advice as necessary, taking into account Privacy Act 1988, contractual obligations, and any applicable state or sector-specific legislation.

 

Policy Review
This policy will be reviewed annually or following any material data breach or change in applicable law.