If your business holds personal information about its customers, clients or staff, the law already requires you to protect it. Under Australian Privacy Principle 11 of the Privacy Act 1988 (Cth) (the Act), an APP entity must take such steps as are reasonable in the circumstances to keep that information safe from misuse, interference, loss, and unauthorised access, modification or disclosure. A data breach response plan is one of the practical tools the regulator expects you to have in place to meet that duty, and it becomes critical the moment something goes wrong.
Since 22 February 2018 the Act has also contained a Notifiable Data Breaches (NDB) scheme in Part IIIC, which forces certain entities to tell affected individuals and the Office of the Australian Information Commissioner (OAIC) when a breach is likely to cause them serious harm. In this guide we set out who those obligations fall on, what a data breach response plan must actually do, how to assess and notify a breach, and what is at stake if you get it wrong.
Who the obligation falls on
The NDB scheme applies to APP entities covered by the Act. That is, entities that already have an obligation under APP 11 to secure personal information. In practice that means:
- Australian Government agencies;
- businesses and not-for-profit organisations with an annual turnover of more than $3 million;
- private sector health service providers, regardless of turnover;
- credit reporting bodies and credit providers;
- entities that trade in personal information; and
- tax file number (TFN) recipients, so far as TFN information is concerned.
An entity generally has to have an "Australian link", which it will usually have if it is incorporated or formed in Australia, or carries on business in Australia.
Small business operators are usually excluded from the APP obligations unless an exception applies. A business is a small business operator for this purpose if its annual turnover for the previous financial year was $3 million or less under section 6D of the Act. However, a small business can still be caught where, for example, it provides a health service and holds health information, trades in personal information, is a credit reporting body, holds accreditation under the Consumer Data Right system, or has opted in to APP coverage under section 6EA. It may also be required to comply in relation to particular activities, such as providing services to the Commonwealth under a contract. If you are a director or operator of a small business, the affordable way to check is to work out your last financial year's turnover and whether any of those exceptions or activities apply to you.
The duty to secure personal information
APP 11 is the foundation obligation. If your entity holds personal information, you must take such steps as are reasonable in the circumstances to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those reasonable steps expressly include both technical and organisational measures.
What is "reasonable" depends on the size of your business, the nature and sensitivity of the information you hold, and the risk of harm to individuals. A business holding a few hundred customer contact details is not held to the same standard as a bank holding millions of financial records.
The plan as part of reasonable steps
A data breach response plan is not expressly required by the wording of the Act. Instead, the OAIC has made clear that, depending on the circumstances, the reasonable steps you must take under APP 11 can include preparing and implementing a data breach policy and response plan. In effect, a response plan is the practical way you demonstrate to the regulator that your security obligations are being taken seriously before an incident occurs.
The OAIC describes a data breach response plan as a framework that sets out the roles and responsibilities for managing an appropriate response to a data breach, and the steps an entity will take to manage a breach if one occurs. Its recommended contents include:
- what a data breach is and how staff should recognise one;
- clear escalation procedures and reporting lines for a suspected breach;
- who sits on the data breach response team, with roles and responsibilities;
- what external expertise should be engaged and in what circumstances;
- how the plan applies to different types of breach and different risk profiles;
- an approach to assessing whether a breach is eligible for notification;
- the process for notifying affected individuals, the OAIC and other bodies;
- how to respond where the incident involves another entity;
- a record keeping policy so breaches are documented;
- requirements under third party agreements such as insurance or services contracts;
- a strategy for fixing weaknesses in how data is handled; and
- regular review and testing of the plan, plus a post-breach review.
The plan matters most at the moment a breach is suspected, because the Act imposes specific and time-sensitive duties from that point.
Assessing a suspected breach
The first legal trigger is a suspicion that there may have been an eligible data breach. Under section 26WH, once an entity is aware there are reasonable grounds to suspect that an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment of whether there really are reasonable grounds to believe an eligible data breach has happened. It must take all reasonable steps to complete that assessment within 30 days of becoming aware.
A breach becomes "eligible" under section 26WE if there has been unauthorised access to, or unauthorised disclosure of, personal information and a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals concerned. It can also arise where information is lost in circumstances where unauthorised access or disclosure is likely and serious harm would follow. In working out whether serious harm is likely, the Act directs you to consider the kind and sensitivity of the information, the security measures protecting it, who obtained or could obtain it, and so on under section 26WG.
Notifying an eligible data breach
If the assessment concludes there are reasonable grounds to believe an eligible data breach has occurred, the scheme then bites. Under section 26WK the entity must prepare a statement setting out its identity and contact details, a description of the breach, the kinds of information concerned, and recommendations about the steps affected individuals should take. It must give that statement to the OAIC, and it must do so as soon as practicable after becoming aware.
Under section 26WL the entity must also notify affected individuals, either by taking reasonable steps to tell each individual or persons at risk, or, where neither is practicable, by publishing a copy of the statement on its website. The OAIC's position is that an affected individual should be notified when they are at real risk of serious harm. There is an important exception in section 26WF: if you take remedial action before serious harm occurs so that a reasonable person would conclude serious harm is no longer likely, the breach is not eligible and notification is not required. That is why a plan built around rapid containment and assessment is valuable. The OAIC may also direct an entity to notify where the Commissioner is aware of reasonable grounds to believe an eligible data breach has occurred.
Consequences of non-compliance
The consequences of failing to meet these obligations are serious and have been substantially increased. An act or practice of an APP entity that breaches an Australian Privacy Principle is an interference with the privacy of an individual under section 13. Where that interference is serious, section 13G provides that a body corporate faces a maximum civil penalty of the greatest of $50 million, three times the value of the benefit it obtained from the conduct, or 30% of its adjusted turnover during the breach turnover period. For a person who is not a body corporate, the maximum is $2.5 million.
The OAIC can investigate complaints, conduct its own investigations, and make determinations that can require a business to compensate an affected individual. It can also issue infringement notices and, more broadly, seek civil penalty orders in court. Beyond penalties, a serious breach that is handled badly carries reputational cost and can trigger claims from the affected individuals themselves.
A compliance checklist
If you operate an entity covered by the Act, the practical steps to be prepared are:
- [ ] Confirm whether your entity is an APP entity or otherwise covered by the NDB scheme, including checking your turnover and any exceptions.
- [ ] Prepare and implement a written data breach response plan covering the contents listed above.
- [ ] Appoint a response team and document who does what and who escalates to whom.
- [ ] Train staff to recognise and report a suspected breach immediately, because the 30 day assessment clock and notification duties start from awareness.
- [ ] Keep a record of how you tested the plan and of any breaches and assessments carried out.
- [ ] Review and test the plan regularly, not just when an incident occurs.
When you need professional help
Preparing a data breach response plan is a task a competent business can begin itself, but legal advice is worth obtaining where the stakes are high. A lawyer can help you work out whether your entity is actually covered, tailor the plan to the specific kinds of personal information you hold, and draft the contractual provisions with third parties such as cloud providers and insurers. If a breach does occur, a lawyer experienced in privacy law can guide the assessment, advise on whether serious harm is likely, and make sure your notification to the OAIC and affected individuals meets the statutory requirements while protecting your position.
The duty most often missed
The obligation that catches most businesses by surprise is not the plan itself, it is the discipline of acting on a suspicion within the 30 day assessment period and notifying as soon as practicable once an eligible breach is confirmed. Time spent arguing internally about whether a breach counts, or waiting to see if the problem goes away, is time the Act does not give you, and delay is exactly what turns an ordinary breach into a serious interference attracting the higher penalties. If you take only one action this week, start or update your data breach response plan so that the moment a breach is suspected, the clock is already managing you rather than the other way around.