PropoDoc provides self-help document templates and tools. It is not a law firm and does not provide legal advice. Learn more.
Skip to main content
Example
guide

Data Breach Notification Plan Example

Example document for Data Breach Notification Plan. Use this as a reference when creating your own.

Professional Review Required

This document involves significant legal, financial, or compliance considerations. You must have a qualified professional review and approve this document before use. Do not rely on this template as legal advice.

Document: Data Breach Notification Plan

Example Document

Last updated 7/30/2026

Data Breach Notification Plan

1. Document Control

Business Name: Smith's Plumbing Services Pty Ltd ABN: 12 345 678 901 Date Prepared: 01/07/2023 Review Date: 01/07/2024 Prepared By: John Smith

2. Response Team

RoleNameContact NumberEmail
Privacy Officer / Business OwnerJohn Smith0412 345 678john@smithplumbing.com.au
IT Support / Technical ContactCity IT Solutions03 9000 0000support@cityit.com.au
Legal AdvisorMelbourne Legal Partners03 9000 1111advice@mlp.com.au
Communications ContactSarah Smith0412 345 679sarah@smithplumbing.com.au

3. Data Inventory

Data TypeStorage LocationSecurity Measures in Place
Customer Names & AddressesXero Cloud Accounting2FA enabled, Strong Passwords
Financial Records (Bank Details)Xero Cloud Accounting2FA enabled, Limited user access
Employee RecordsMyob & Locked Filing CabinetPassword protected, Physical lock

4. Immediate Response Steps

Step 1: Contain the Breach

  • Called City IT Solutions to revoke access for stolen laptop.
  • Changed admin passwords for Xero.

Step 2: Assemble the Team

  • John Smith (Owner) notified.
  • Sarah Smith (Office Manager) notified.

Step 3: Initial Assessment

  • What happened: Company laptop stolen from ute overnight.
  • When did it happen: Overnight on 15/10/2023.
  • Who discovered it: John Smith, 06:30 AM 16/10/2023.
  • What data is involved: Client quotes and invoices containing names, addresses, and partial bank account details (BSB/Account). No passwords or credit card numbers.
  • How many people are affected: Approximately 45 clients from the last 3 months.

5. Assessment of Serious Harm

FactorYes / NoNotes
Is the information sensitive?YesBank details are present.
Is the information in the hands of someone likely to misuse it?UnknownLaptop was password protected but drive may not be fully encrypted.
Is there a risk of identity theft?LowLimited info, but bank details are a risk.
Is there a risk of financial loss?YesBank details could be used for fraud.
Is there a risk of physical safety?No

Decision: YES - Eligible data breach requiring notification due to presence of bank details.

6. Notification Procedures

A. Notify the OAIC

  • Submitted online form on 16/10/2023.

B. Notify Affected Individuals

  • Method: Email and SMS for immediate receipt. Follow up letter for those without email.

Draft Statement: Dear [Client Name],

We are writing to inform you of a data breach involving your personal information held by Smith's Plumbing Services.

What happened: On 16 October 2023, we discovered that a company laptop was stolen from a vehicle. The laptop contained files with your personal information.

What information was involved: The files included your name, address, and bank account details (BSB and Account Number). The laptop did not contain your tax file number or credit card details.

What we are doing: We have remotely disabled the laptop's access to our systems. We have reported the theft to the police. We are currently reviewing our security to ensure this does not happen again.

What you should do: We recommend you monitor your bank accounts for any unusual transactions over the coming weeks. If you notice anything suspicious, please contact your bank immediately.

We sincerely apologise for this incident. If you have questions, please call John on 0412 345 678.

Sincerely, Smith's Plumbing Services

Notes

Note on Decision: The business owner determined the breach was eligible because bank account details were involved. Even though the laptop had a login password, the files themselves might not have been encrypted, creating a risk of financial loss. This triggered the notification requirement.

About this Example

Part of the Data Breach Notification Plan document collection

Document Type

Data Breach Notification Plan

A step by step plan for Australian businesses to manage and report data breaches. It helps you meet legal obligations under the Privacy Act.

Complexity

moderate

Risk Level

high