New obligations regarding privacy breaches

26 February 2018 by

From 22 February 2018 there are new obligations under the Privacy Act 1988. The new Notifiable Data Breaches (NDB) scheme under established requirements for entities in responding to data breaches. Entities have data breach notification obligations when a data breach is likely to result in serious harm to any individuals whose personal information is involved in the breach.

The Office of the Australian Information Commissioner website has a page with information to help entities comply with the NDB scheme. Their guide, Data breach preparation and response, provides a comprehensive overview of the NDB scheme, as well as a general framework to help you prepare for, and respond to, data breaches. An overview of the scheme, including a summary diagram, is set out below, and links are provided to additional resources that may be helpful for entities regulated by the Privacy Act.