Data Breach Notification Plan Template
Template for Data Breach Notification Plan. Customize this template for your specific needs.
Professional Review Required
This document involves significant legal, financial, or compliance considerations. You must have a qualified professional review and approve this document before use. Do not rely on this template as legal advice.
Document: Data Breach Notification Plan
Template Preview
Version 1 • Last updated 7/30/2026
Data Breach Notification Plan
1. Document Control
Business Name: [INSERT BUSINESS NAME] ABN: [INSERT ABN] Date Prepared: [INSERT DATE] Review Date: [INSERT REVIEW DATE - usually 12 months from date prepared] Prepared By: [INSERT NAME]
2. Response Team
| Role | Name | Contact Number | |
|---|---|---|---|
| Privacy Officer / Business Owner | [INSERT NAME] | [INSERT PHONE] | [INSERT EMAIL] |
| IT Support / Technical Contact | [INSERT NAME OR IT PROVIDER] | [INSERT PHONE] | [INSERT EMAIL] |
| Legal Advisor | [INSERT NAME OR LAW FIRM] | [INSERT PHONE] | [INSERT EMAIL] |
| Communications Contact | [INSERT NAME] | [INSERT PHONE] | [INSERT EMAIL] |
3. Data Inventory
List the types of personal information your business holds and where it is stored.
| Data Type | Storage Location (e.g. Cloud Server, Filing Cabinet, Laptop) | Security Measures in Place |
|---|---|---|
| Customer Names & Addresses | [INSERT LOCATION] | [INSERT MEASURES, e.g., Password protected] |
| Financial Records (Bank Details, Invoices) | [INSERT LOCATION] | [INSERT MEASURES] |
| Employee Records (TFNs, Payroll) | [INSERT LOCATION] | [INSERT MEASURES] |
| Supplier Information | [INSERT LOCATION] | [INSERT MEASURES] |
| Health Information (if applicable) | [INSERT LOCATION] | [INSERT MEASURES] |
4. Immediate Response Steps
Use this checklist immediately upon discovering a suspected breach.
Step 1: Contain the Breach
- If a device is lost or stolen, change passwords for associated accounts immediately.
- If a system is hacked, disconnect the affected device from the internet and network.
- If physical records are lost, secure the area and check CCTV (if available).
- Do not turn off a compromised computer if IT needs to investigate logs, unless advised otherwise.
Step 2: Assemble the Team
- Notify the Privacy Officer / Business Owner.
- Contact the IT Support / Technical Contact.
- Prepare a log of events to record what happened and when.
Step 3: Initial Assessment
- What happened? (Brief description: [INSERT])
- When did it happen? (Date/Time: [INSERT])
- Who discovered it? (Name: [INSERT])
- What data is involved? (e.g., Names, Credit Cards: [INSERT])
- How many people are affected? (Approximate number: [INSERT])
5. Assessment of Serious Harm
You must determine if the breach is likely to result in serious harm to any individual. Consider the following.
| Factor | Yes / No | Notes |
|---|---|---|
| Is the information sensitive? (e.g., health records, financial details) | [YES/NO] | [INSERT NOTES] |
| Is the information in the hands of someone likely to misuse it? | [YES/NO] | [INSERT NOTES] |
| Is there a risk of identity theft? | [YES/NO] | [INSERT NOTES] |
| Is there a risk of financial loss? | [YES/NO] | [INSERT NOTES] |
| Is there a risk of physical safety or reputational damage? | [YES/NO] | [INSERT NOTES] |
Decision: Is this an eligible data breach requiring notification?
[ ] YES - Proceed to Section 6 [ ] NO - Document the reason and keep records. Monitor the situation.
6. Notification Procedures
If you determined the breach is eligible, you must notify.
A. Notify the Office of the Australian Information Commissioner (OAIC)
- Method: Use the Notifiable Data Breach statement form on the OAIC website.
- Timing: As soon as practicable.
- Content to include:
- Identity and contact details of the organisation.
- Description of the data breach.
- Kinds of information concerned.
- Recommendations for individuals.
B. Notify Affected Individuals
- Method: [INSERT METHOD, e.g., Email, Phone call, Letter]
- Timing: As soon as practicable.
- Draft Statement: (Use the text below or adapt it)
NOTICE OF DATA BREACH
Dear [INSERT CUSTOMER NAME],
We are writing to inform you of a data breach involving your personal information held by [INSERT BUSINESS NAME].
What happened: [INSERT DESCRIPTION, e.g., On [DATE], we discovered that a laptop containing customer files was stolen from a vehicle.]
What information was involved: [INSERT DETAILS, e.g., The files contained your name, address, and tax invoice number.]
What we are doing: We have [INSERT ACTIONS, e.g., reported the matter to the police, changed our security protocols, and engaged IT specialists to recover the data].
What you should do: We recommend you [INSERT ADVICE, e.g., monitor your bank accounts for unusual activity and change your password for our services].
We take the security of your information very seriously and apologise for any inconvenience or concern this may cause. If you have any questions, please contact [INSERT NAME] at [INSERT PHONE] or [INSERT EMAIL].
Sincerely,
[INSERT BUSINESS NAME]
7. Post-Incident Review
- Schedule a meeting within 7 days to review the incident.
- Identify what caused the breach (e.g., human error, system failure, malicious attack).
- Update this plan and security measures to prevent recurrence.
- Keep records of the breach and assessment for at least 3 years.
About this Template
Part of the Data Breach Notification Plan document collection
Document Type
Data Breach Notification Plan
A step by step plan for Australian businesses to manage and report data breaches. It helps you meet legal obligations under the Privacy Act.