Data breach response plan
OAIC Part 2. Write the plan before the incident. Roles, containment, assessment, notify, and records — so the NDB clock is not where you invent process.
The OAIC's Data breach preparation and response guide (updated June 2024) treats a data breach response plan as preparation, not paperwork after the fact. Part 2 sits beside Part 3 (contain, assess, notify, review) and Part 4 (the Notifiable Data Breaches scheme). If you are an APP entity, the plan is how you meet the assessment and notify clocks without inventing a process under pressure.
A usable plan names who owns the response (privacy, legal, IT/security, communications, executive), how to escalate after hours, and how to reach the OAIC form and any sector regulator. It lists systems that hold personal information, including vendors. It says how you contain (isolate accounts, revoke tokens, preserve logs) without destroying evidence. It points at the serious-harm test and the NDB statement, not a generic 'we take privacy seriously' paragraph.
Part 3's four steps are the runtime: contain the breach; assess the risks (including whether it is an eligible data breach); notify the OAIC and individuals when required; review and improve. The plan should say which step starts which clock. Thirty days is for assessing a suspicion under s 26WH(2). Notification, once you have reasonable grounds that the breach is eligible, is as soon as practicable. Remedial action that removes the likelihood of serious harm can change the notification duty — document that reasoning.
Third-party and cloud breaches still need your plan. If a provider holds or processes personal information for you, your assessment clock can start when you have grounds to suspect, not when their status page turns green. Put vendor contacts, shared-responsibility splits, and evidence requests in the plan. Pair this page with the NDB clock, the serious-harm test, and the NDB statement pages.
Practical desk: keep the plan short enough to open in an incident bridge. Attach the OAIC quick reference, the current personal-information map, and the last tabletop date. Update after every real or exercised breach. A plan that only lives in a policy PDF is not a response capability.
See also:
Fact source: OAIC, Data breach preparation and response.
