# Notifiable Data Breach (NDB) Response Plan — Template

_Free template by [CATAAM](https://cataam.com/resources/notifiable-data-breach-response-plan/). Aligned to the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme and OAIC guidance. This is a starting template, not legal advice — adapt it to your organisation and have it reviewed._

---

## 1. Purpose & scope

This plan defines how **[Organisation]** detects, assesses, and responds to a data breach involving personal information, and how it meets its obligations under the **Notifiable Data Breaches (NDB) scheme**.

- **Applies to:** all personal information held by [Organisation], across all systems, staff, contractors and third-party processors.
- **Owner:** [Privacy Officer / role]
- **Last reviewed:** [date] · **Review cadence:** at least annually and after any incident.

## 2. Response team & roles

| Role | Name / title | Responsibility |
|---|---|---|
| Breach Response Lead | [ ] | Owns the response end-to-end; makes the notification decision |
| Privacy Officer | [ ] | OAIC liaison; assesses "serious harm" |
| Security / IT Lead | [ ] | Containment, forensics, remediation |
| Legal | [ ] | Legal obligations, privilege, other regulators |
| Communications | [ ] | Individual notifications, media, customer comms |
| Executive sponsor | [ ] | Authorises resourcing and external disclosure |

## 3. The four steps (OAIC model)

### Step 1 — Contain
- Take immediate steps to limit the breach (disable accounts, revoke tokens, isolate systems, recover devices).
- Do **not** destroy evidence — preserve logs and forensic artefacts.
- Record time of detection and initial actions in the incident log (Section 6).

### Step 2 — Assess (target: complete within 30 days)
Assess whether this is an **eligible data breach** — i.e. **both**:
1. There is **unauthorised access to, unauthorised disclosure of, or loss of** personal information you hold; **and**
2. It is **likely to result in serious harm** to one or more individuals.

Consider, when weighing serious harm:
- The **kind and sensitivity** of information (e.g. health, financial, identity documents, credentials).
- Whether information was **encrypted** or otherwise protected, and the likelihood the protection could be overcome.
- The **kinds of harm** that could result (identity theft, financial loss, physical/psychological harm, reputational damage).
- The **number of individuals** affected and who obtained (or could obtain) the information.
- Any **remedial action** taken and whether it removes the likelihood of serious harm.

> If remedial action prevents serious harm before it occurs, notification may not be required — document the reasoning.

### Step 3 — Notify (if an eligible data breach)
If serious harm is likely and remedial action hasn't removed it, notify **as soon as practicable**:
- **The OAIC** — via the online Notifiable Data Breach form.
- **Affected individuals** — the statement must include: your identity and contact details, a description of the breach, the kinds of information involved, and the steps individuals should take in response.
- **Notification method:** notify affected individuals directly where practicable; otherwise publish the statement and take reasonable steps to publicise it.

### Step 4 — Review
- Root-cause analysis; what controls failed and why.
- Remediation actions with owners and dates.
- Update this plan, controls, and staff training. Record lessons learned.

## 4. Notification decision record

| Item | Detail |
|---|---|
| Eligible data breach? (Y/N) | |
| Basis for decision | |
| Serious harm likely? (Y/N) | |
| Remedial action taken | |
| OAIC notified? Date/time | |
| Individuals notified? Date/method | |
| Decision approved by | |

## 5. Key timeframes
- **Assessment:** take all reasonable steps to complete within **30 calendar days** of becoming aware of a possible eligible breach.
- **Notification:** **as soon as practicable** after forming the view that an eligible data breach has occurred.

## 6. Incident log
| Time | Action | By whom |
|---|---|---|
| | Breach detected | |
| | Containment actions | |
| | Assessment started | |
| | Decision reached | |
| | OAIC notified | |
| | Individuals notified | |
| | Review completed | |

## 7. Contacts
- **OAIC:** Office of the Australian Information Commissioner — oaic.gov.au · 1300 363 992
- **Internal escalation:** [24/7 contact]
- **Forensics / IR partner:** [ ]
- **Cyber insurer:** [ ]

---

_Turn this plan into a live capability. [CATAAM](https://cataam.com/compliance/australian-privacy-principles/) operationalises APP 11 security and continuously proves the safeguards behind a defensible breach response._
