Notifiable Data Breach Response Plan
A ready-to-adapt template aligned to the Privacy Act 1988 and OAIC guidance — the four steps, response-team roles, the 30-day timeframes, and a notification decision record.
Contain
Limit the breach immediately — disable accounts, revoke tokens, isolate systems, recover devices. Preserve logs and evidence; record the time of detection.
Assess
Decide whether it is an eligible data breach: unauthorised access, disclosure or loss of personal information that is likely to result in serious harm. Weigh sensitivity, encryption, likely harm, and numbers affected. Target: complete within 30 days.
Notify
If serious harm is likely and remedial action hasn’t removed it, notify the OAIC and affected individuals as soon as practicable — with the breach description, the information involved, and what individuals should do.
Review
Root-cause analysis, remediation with owners and dates, and updates to controls, training and this plan. Capture lessons learned.
Key timeframes: take all reasonable steps to complete your assessment within 30 days of becoming aware of a possible eligible breach; notify the OAIC and affected individuals as soon as practicable once you form the view that an eligible data breach has occurred.
The full template includes response-team roles, the serious-harm assessment factors, a notification decision record, an incident log and key contacts. Summarised from the Privacy Act 1988 (Cth) and OAIC guidance — not legal advice.
NDB response plan FAQ
- What is a Notifiable Data Breach response plan?
- It is the documented process an organisation follows when personal information may have been breached — how you contain the incident, assess whether it is an eligible data breach under the Notifiable Data Breaches (NDB) scheme, notify the OAIC and affected individuals if required, and review afterwards. Having one ready is what lets you meet the scheme’s timeframes under pressure.
- When must you notify under the NDB scheme?
- You must notify when there is an eligible data breach — unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm, and remedial action has not removed that likelihood. Notify the OAIC and affected individuals as soon as practicable; you should take all reasonable steps to complete your assessment within 30 days of becoming aware of a possible breach.
- What counts as "serious harm"?
- Serious harm can include identity theft, financial loss, physical or psychological harm, and reputational damage. Whether it is likely depends on the kind and sensitivity of the information, whether it was encrypted or otherwise protected, who accessed it, and what remedial action you took. The template includes the factors to weigh and a decision record to document your reasoning.
- Is this template legal advice?
- No — it is a free starting template aligned to the Privacy Act 1988 and OAIC guidance, to be adapted to your organisation and reviewed by a privacy professional. What CATAAM adds is the operational side: proving the APP 11 security safeguards continuously so a breach is less likely and your response is evidence-backed.
Fewer breaches to notify in the first place
CATAAM operationalises the APP 11 security safeguards and proves them continuously — so your breach response is backed by evidence, not scrambled together on the day.