Preventative controls
Reasonable security under APP 11 to prevent eligible data breaches in the first place.
Mandatory notification of eligible data breaches likely to result in serious harm to any affected individual.
The NDB scheme sits inside the Privacy Act 1988 and applies to all APP entities. When an entity has reasonable grounds to believe there has been an eligible data breach - unauthorised access, disclosure or loss of personal information likely to result in serious harm - it must promptly notify the individuals at risk and the OAIC. Where the entity is only suspicious, it has 30 days to assess whether the breach is notifiable. Practical cybersecurity programs tie detection, containment and decision-making inside this 30-day window.
Any entity covered by the Privacy Act 1988, including APP entities, credit reporting bodies, credit providers, TFN recipients and health service providers.
Reasonable security under APP 11 to prevent eligible data breaches in the first place.
Assessment of whether a suspected breach is likely to result in serious harm.
Steps taken to contain the breach and mitigate harm before notification may not be required.
Prompt notification to affected individuals and a statement to the OAIC describing the breach, information involved, and steps being taken.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.