PropoDoc provides self-help document templates and tools. It is not a law firm and does not provide legal advice. Learn more.
Skip to main content

Data Breach Notification Plan

A Data Breach Notification Plan is a document that outlines the steps a business must take to respond to a data security incident. In Australia, it helps you comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.

A step by step plan for Australian businesses to manage and report data breaches. It helps you meet legal obligations under the Privacy Act.

Use Free Template
Create your custom version — free to start

20 free credits on signup — no card needed

guide
moderate
high Risk

About this Document

A Data Breach Notification Plan is a written document that outlines exactly what your business must do if you lose personal information. In Australia, the Privacy Act 1988 (Cth) sets strict rules about how businesses handle personal data. If your business has an annual turnover of more than $3 million, or if you trade in personal information, you are likely bound by these rules. However, even smaller tradespeople and contractors handle sensitive data like client names, addresses, phone numbers, and bank details. If this information falls into the wrong hands, it can cause serious harm to your clients and damage your reputation. This plan is your insurance policy against that chaos. It tells your staff who to call, how to contain the breach, and how to notify the people affected. This guide will walk you through why you need this document, the laws you must follow, and how to create a plan for your specific industry. We will look at the Notifiable Data Breaches (NDB) scheme. The NDB scheme requires eligible organisations to notify individuals whose personal information is involved in a data breach that is likely to result in serious harm. This notification must happen as soon as practicable. You must also notify the Office of the Australian Information Commissioner (OAIC). Serious harm can include physical, psychological, financial, or reputational harm. For example, if a tradie loses a notebook with client credit card details, that client could suffer financial loss. This meets the threshold for serious harm. If you do not have a plan, you will waste valuable time figuring out what to do during a crisis. This delay can lead to bigger fines and angry clients. Your plan needs to be simple and practical. It should not be a complex legal document that sits in a drawer. It should be a checklist that you and your team can follow immediately. This guide is written for Australian business owners, tradespeople, and contractors who may not have a dedicated IT team. It uses plain English to explain your obligations. We will reference the Privacy Act 1988, the Notifiable Data Breaches (NDB) scheme, and the Australian Privacy Principles (APPs). We will also touch on the Competition and Consumer Act 2010 regarding misleading conduct if you try to hide a breach. While this plan focuses on privacy, it also relates to the Spam Act 2003 if the breach involves email lists. When you sit down to write your Data Breach Notification Plan, you need to consider the types of data you hold. A plumber might hold different data than an accountant, but the risk is real for both. You need to identify your data assets. This means listing where you keep client information. Is it on a laptop in your ute? Is it in a cloud accounting software like Xero or MYOB? Is it in a filing cabinet at the office? Once you know where the data is, you can secure it. Your plan must include steps for containment. This is the first action you take after discovering a breach. You might need to change passwords, shut down a server, or remotely wipe a stolen phone. The next step is assessment. You need to work out if the breach is likely to result in serious harm. This is a legal test under the NDB scheme. You should consult this plan to see who makes that decision. Usually, it is the business owner or a designated Privacy Officer. If the assessment shows serious harm is likely, you must notify. The plan must have a template for notification. You must tell the OAIC and the affected individuals. The notification must include specific details. You must describe the breach, the kind of information concerned, and the steps you recommend they take to protect themselves. You should also include your contact details. The longDescription must also cover common mistakes. A common mistake is thinking a breach is too small to worry about. Even one lost record can be a breach. Another mistake is failing to document the breach. You must keep records of your assessment. The OAIC can ask for these records. If you cannot prove you assessed the risk, you may be fined. The Privacy Act allows for significant penalties. For serious or repeated interferences with privacy, the fines can be millions of dollars. Do not take this lightly. Another mistake is not training staff. Your plan is useless if your employees do not know it exists. You must include staff training in your plan. This document also helps you comply with the Australian Privacy Principles. APP 11 requires you to take reasonable steps to protect personal information you hold from misuse, interference, and loss. Having a response plan is a reasonable step. It shows regulators you take privacy seriously. If you work in the building and construction industry, you might also deal with the Security of Payment Act. While not directly related to data, losing project data or client financials can impact your payment claims. This plan helps safeguard that business intelligence. For sole traders, the risk feels personal. If your laptop is stolen, you lose your tools and your client list. This plan helps you recover. It forces you to back up your data. It forces you to think about cyber security basics like two-factor authentication and strong passwords. These are practical steps that save you time and money. We will now detail how to complete the document. You should start by appointing a response team. For a small business, this might just be you and a senior staff member. List their names and phone numbers clearly at the top of the plan. Next, list the types of data you hold. Be specific. Tax file numbers, credit card details, medical records, and home addresses are all high risk. Next, outline your containment strategies. If a device is lost, what do you do? If you are hacked, what do you do? Write these steps down. Next, draft your notification templates. Prepare a letter for clients and a form for the OAIC. Have them ready in a draft format. You do not want to write them from scratch while you are stressed. Finally, set a review date. Laws change. Technology changes. Review your plan every year. This ensures it stays relevant. This document is a vital part of your business governance. It sits alongside your workplace health and safety policies and your contracts. It protects your business, your clients, and your reputation. Do not operate without one.

Key Facts

  • The NDB scheme requires organisations to notify the OAIC and affected individuals of eligible data breaches.Privacy Act 1988 (Cth)
  • Businesses with an annual turnover of more than $3 million are subject to the Privacy Act.Privacy Act 1988 (Cth)
  • An eligible data breach is one that is likely to result in serious harm to any individual whose information is involved.Notifiable Data Breaches (NDB) scheme
  • You must notify affected individuals as soon as practicable after becoming aware of the breach.Office of the Australian Information Commissioner
  • Serious harm can include physical, psychological, financial, or reputational harm.Privacy Act 1988 (Cth)
  • The OAIC can investigate organisations that fail to notify an eligible data breach.Notifiable Data Breaches (NDB) scheme

Sources

Required Sections

Incident Response Team

Defines who is responsible for managing a data breach.

Incident Response Team

An effective response relies on knowing exactly who to call when things go wrong. You must have a list of key people and external advisors ready to act immediately. Under the Privacy Act 1988 (Cth), the Notifiable Data Breaches (NDB) scheme requires organisations to take reasonable steps to contain a data breach and assess whether it is likely to result in serious harm. Having a dedicated team is a critical part of meeting this obligation.

Internal Roles and Responsibilities

Business Owner or Managing Director The business owner holds ultimate responsibility for the data breach response. They must make the final decision on whether to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals. They also manage the broader business reputation and customer communications.

Privacy Officer A designated staff member must act as the Privacy Officer. This person coordinates the response and ensures the team follows the plan. Their job is to gather facts, document the timeline of events, and report progress to the business owner. They act as the central point of contact to prevent confusion.

IT or Systems Manager This person handles the technical side of the breach. They work to stop the attack, recover lost data, and secure systems against further access. If you do not have an internal IT department, you must list an external managed service provider (MSP) here.

External Advisors

Legal Counsel You must engage a lawyer experienced in Australian privacy law to assist with complex breaches. Legal privilege protects your early discussions with a lawyer, which helps keep your assessment of the breach confidential. Your lawyer will advise on whether you meet the legal threshold for notification under the NDB scheme. They can also help draft customer notifications to ensure they are accurate and comply with the law.

Cyber Security Specialist For serious incidents like ransomware or hacking, you need a certified cyber security expert. They perform forensic analysis to determine how the breach happened, what data was taken, and how to fix the security gap.

Contact Details List

Maintain a separate, secure sheet with the following details for every team member. Keep a printed copy offline in case your computer systems are locked down during an incident.

  • Full Name
  • Position title
  • Mobile phone number
  • Personal email address (in case the business server is down)
  • Specific role in the response (Decision Maker, Technical Lead, Coordinator)

Review this list every six months. Update it immediately when staff leave or change roles. A slow response due to outdated contact numbers can lead to greater data loss and regulatory penalties.

Required

Data Inventory

Lists the types of personal data held and where it is stored.

Knowing exactly what data you hold and where it sits is the first step in managing a data breach. If you lose track of customer files or you do not know where your employee records are kept, you cannot respond quickly when things go wrong. Under the Privacy Act 1988 (Cth), Australian businesses have specific obligations regarding personal information. If you are unsure whether this law applies to you, check if your business has an annual turnover of more than $3 million or if you trade in personal information. Compliance with the Notifiable Data Breaches (NDB) scheme is mandatory for those entities, meaning you must report eligible data breaches to the Office of the Australian Information Commissioner (OAIC) and affected individuals.

Start by listing every type of information your business collects. Do not limit this to just names and addresses. Think about tax file numbers, bank details, credit card information, medical history, and even photos of job sites that might show licence plates or street addresses. Once you have identified the data, write down exactly where it is stored. This includes obvious places like your accountant's laptop or your office server, but you must also include less obvious locations. Do you have paper files in a ute? Do you use cloud storage like Google Drive or Dropbox? Do customer details sit on a tablet used by staff in the field?

Next, look at the security measures you currently have in place. This allows you to see where your weak spots are. Simple locks on filing cabinets might not be enough. Consider whether your digital files are password protected and if that password is complex. Check if you have two-factor authentication turned on for cloud accounts. Review who actually has access to sensitive data. It is good practice to limit access to only those staff members who need the information to do their job. If you share data with third parties, such as payroll companies or subcontractors, list them as well. Understanding your data inventory makes it much easier to follow the steps in this plan if a breach occurs. Use the table below to map out your business data.

Data Inventory Register

Data TypeDescription and SensitivityStorage LocationCurrent Security MeasuresThird Party Access
Customer Personal DetailsNames, phone numbers, addresses, email historyOffice server (CRM software)Password protected access, unique user loginsNone
Employee RecordsTFNs, bank details, performance reviews, contractsLocked filing cabinet in Manager's officePhysical lock and key, manager holds key onlyPayroll service provider
Financial RecordsInvoices, receipts, purchase orders, EFTPOS recordsCloud storage (Xero/Myob) + Cloud backupTwo-factor authentication, 256-bit encryptionAccountant and Bookkeeper
Site Photos / PlansImages of work sites, architectural plans, client signaturesCompany iPad and USB driveDevice passcode, USB drive kept in safe safeSubcontractors via email
Supplier InformationABNs, contact details, contract termsPaper files in onsite ute toolboxToolbox padlock, vehicle central lockingNone
Required

Immediate Containment Steps

Actionable checklist to secure data immediately after discovery.

Immediate Containment Checklist

Technical Actions

  • Disconnect Affected Devices: Unplug the ethernet cable or disable the Wi-Fi and mobile data connection on any computer, tablet, or phone involved in the breach. This stops the data from leaving your network or malware from spreading to other devices.
  • Reset Privileged Credentials: Immediately change passwords for administrator accounts and any compromised user accounts. If you use a central system, force a password reset for all staff who had access to the lost data. Ensure new passwords are strong and unique.
  • Disable Remote Access: Turn off remote desktop protocols and VPN access for your business. If the attacker used a remote channel, closing it stops them from getting back in while you investigate.
  • Change Website or Banking Logins: If the breach involves website hosting files or internet banking details, change those specific passwords straight away.
  • Do Not Reconnect Yet: Keep devices offline until your IT support confirms the threat is removed. Turning a compromised machine back on too quickly can allow the breach to continue or restart.

Physical Actions

  • Secure the Physical Site: Lock your office, ute, or storage sheds. If a device was stolen, check who has keys and consider changing locks if spare keys are missing.
  • Stop Using Affected Hardware: If a specific laptop or server is the problem, power it down and do not use it for any other work.
  • Preserve Evidence: Do not delete files, reformat drives, or wipe devices. You need to keep the system exactly as it is to help your IT provider or authorities work out how the breach happened. If you must turn a machine off, unplug it rather than performing a standard shutdown.
  • Collect Logs: If you have physical access to your router or server, write down the exact times you noticed the issue. Take photos of screen messages if they appear.

Legal Note These steps help you meet your obligations under the Privacy Act 1988 (Cth). The Notifiable Data Breaches (NDB) scheme requires you to take reasonable steps to contain a breach once you are aware of it. Acting quickly is a key part of showing the Office of the Australian Information Commissioner (OAIC) that your response was appropriate. Failure to contain a breach swiftly can lead to greater data loss and higher regulatory penalties.

Required

Risk of Serious Harm Assessment

Guidance on determining if the breach meets the legal threshold for notification.

To decide if a data breach is likely to result in serious harm, you must look closely at the type of information involved and who has access to it. Serious harm is not minor. It includes physical injury, serious financial loss, or serious damage to reputation. Under the Privacy Act 1988, you must assess this risk quickly. Use the following questions to guide your assessment.

What kind of data is involved? You must identify if the lost or stolen data includes sensitive information. This is a major risk factor. Examples include medical records, health information, or criminal records. You should also check for financial details like bank account numbers, credit card numbers, or superannuation information. Even basic personal identifiers like a Tax File Number, Medicare number, or driver's licence number can create a high risk of identity theft. If the breach involves only a name or a work phone number, the risk of serious harm is usually lower.

Who has the data? Consider who might hold the data now. If an unknown criminal has the information, the risk is much higher than if an employee accidentally sent it to a trusted business partner. Ask yourself if the person who has the data intends to cause harm. If the data is published on the public internet, the risk is immediate and widespread.

Is the data protected? Check if the lost data is encrypted or password protected. If a stolen laptop requires a strong password to access, or if files are encrypted, the risk of serious harm is reduced. However, if the password is written on a sticker attached to the laptop, the data is not secure. You must assess if the security measures are actually effective.

Could the data be used for fraud? Evaluate if the information helps someone commit identity fraud. A combination of details is dangerous. For example, a full name plus a date of birth and address is very useful for a scammer. If tradespeople have client credit card details, scammers can use these to make unauthorised transactions. If criminals can access a client's MyGov account using stolen details, the harm is serious.

What are the consequences for the individual? Think about the specific impact on your clients. If their private medical history becomes public, it could damage their reputation or relationships. If their banking details are stolen, they could lose significant savings. Consider if the individuals are vulnerable. For example, if the data belongs to elderly clients or children, the risk of serious harm may be higher.

Review these questions carefully. If you answer yes to the high-risk indicators, you must assume there is a likelihood of serious harm. Under the Notifiable Data Breaches (NDB) scheme, this triggers your obligation to notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals.

Required

Notification Procedures

Templates and instructions for notifying the OAIC and affected individuals.

Customer Notification Letter Template

[Date]

[Customer Name]

[Customer Address]

Dear [Customer Name],

We are writing to let you know about a data breach involving your personal information. We take the security of your data seriously and we wanted to explain what happened, what we are doing, and what steps you might need to take.

What happened On [date], we discovered that [brief description of the incident, e.g. a laptop was left in a vehicle / a file was emailed to the wrong person]. This incident may have exposed your [list specific data, e.g. name, address, phone number, bank account details].

What we have done Since discovering the issue, we have:

  • Secured the system to stop further data loss.
  • Launched an investigation to find out exactly what happened.
  • [List other actions, e.g. reset passwords / notified police].

What you should do Because your information was involved, we recommend you take the following steps: [Provide specific advice here based on the data lost, for example:

  • Monitor your bank accounts for unusual transactions.
  • Change your password for your account with us.
  • Contact your financial institution if you provided bank details.]

We apologise for any stress or inconvenience this causes. If you have any questions about this incident, please contact [Name] on [Phone Number] or at [Email Address].

Yours sincerely,

[Name] [Position] [Business Name]

Notifying the Office of the Australian Information Commissioner (OAIC)

If the breach is likely to result in serious harm to any individual, you must notify the OAIC as soon as practicable. You must do this under the Privacy Act 1988 (Cth).

You can notify the OAIC using the Notifiable Data Breaches (NDB) form on their website. Do not wait until you finish your investigation to notify them. You must provide the following information in your notification.

First, describe the breach. Explain how the breach happened and what personal information was involved. Be specific about the type of data lost, such as tax file numbers, medical records, or credit card details.

Second, outline the steps you have already taken to fix the breach. This shows the OAIC you are managing the situation. List the actions you took to reduce the impact on affected individuals. This includes things like remote wiping devices, changing passwords, or contacting banks.

Third, describe the steps you are taking to prevent the breach from happening again. The OAIC wants to know you have reviewed your security measures. You might mention new staff training, updated software, or physical security improvements.

Finally, provide details about the individuals you have notified. Confirm that you have contacted the people affected by the breach. If you have not notified them yet, explain why and when you plan to do so. Keep a record of your submission to the OAIC for your own business files.

Required

Optional Sections

Post-Incident Review

Steps to review the incident and improve future security.

Post-Incident Meeting Requirements

After a data breach is contained, you must hold a post-incident meeting. This meeting is essential for understanding what went wrong and preventing it from happening again. You must schedule this meeting within a reasonable timeframe, usually within one week of resolving the incident. All relevant staff must attend. This includes business owners, office managers, and anyone who handled the breach response. If you used external IT support or a legal advisor, they should join too.

Documenting the Cause

The primary goal of this meeting is to identify the root cause of the breach. You must document the exact sequence of events. Start from when the breach began and trace it through to discovery. Ask specific questions. Was the breach caused by a phishing email, a lost mobile phone, or outdated software? Did a staff member make a mistake, or did a system fail?

You must record these findings in writing. Create a Post-Incident Report. This report must detail the cause, the data exposed, and who was affected. This documentation is a legal requirement under the Privacy Act 1988 (Cth). The Office of the Australian Information Commissioner (OAIC) may request this report during an investigation. If you cannot prove you investigated the cause, you risk penalties for failing to take reasonable steps to secure information.

Updating Security Policies

Once the cause is known, you must review your security policies. If the breach happened because an employee clicked a bad link, your training policy is lacking. If a thief stole a laptop from a work van, your device storage policy is too weak. You must update your Data Breach Response Plan to address the specific failure.

Review your compliance with the Notifiable Data Breaches (NDB) scheme. Ensure your updated policies align with the Australian Privacy Principles. For example, APP 11 requires you to take reasonable steps to protect personal information. If your current steps failed, you must implement stronger controls. This might include two-factor authentication, mandatory regular password changes, or encrypting all customer data.

Action Items and Follow-Up

The meeting must conclude with a list of action items. Assign a specific person to every task. Set deadlines for implementing new security measures. Do not rely on verbal agreements. Write down who is doing what and when.

Finally, schedule a follow-up meeting. This allows you to check if the new policies are working. Continuous improvement shows the OAIC you take privacy seriously. It also builds trust with your clients. A small business owner who learns from a breach demonstrates professionalism and responsibility.

Optional

Frequently Asked Questions

What is a Data Breach Notification Plan?
A Data Breach Notification Plan is a set of instructions that helps a business respond to a data security incident. It ensures the business acts quickly to stop the breach and complies with Australian notification laws.
When do I need a Data Breach Notification Plan?
You need this plan before a breach happens. If you handle personal information, such as customer names or bank details, you should have a plan ready to minimise damage and meet legal timeframes.
Is a Data Breach Notification Plan legally required in Australia?
The Privacy Act 1988 requires entities covered by the NDB scheme to take reasonable steps to protect data and notify breaches. Having a written plan is considered a reasonable step to ensure compliance.
What is an eligible data breach?
An eligible data breach occurs when personal information is lost or accessed, and this access is likely to result in serious harm to an individual. Serious harm can be financial, physical, psychological, or reputational.
Who do I notify if a breach occurs?
If you have an eligible data breach, you must notify the Office of the Australian Information Commissioner (OAIC) and the individuals whose information was affected. You must do this as soon as practicable.
Do small businesses need a Data Breach Notification Plan?
Yes, small businesses with a turnover over $3 million or those that trade in personal information must comply with the NDB scheme. Even small sole traders benefit from having a plan to protect their clients and reputation.
What should I include in a notification to a client?
You must describe the breach, the type of information involved, and recommend steps the individual should take to protect themselves. You should also provide your contact details so they can ask questions.

Explore More Documents

Ready to create your document?

Use our free template or generate a custom version tailored to your needs.

Use Free Template
Create your custom version — free to start

20 free credits on signup — no card needed

This document involves significant legal or financial considerations. Professional review is strongly recommended.