Part IIIC of the Privacy Act 1988 (the notifiable data breach scheme) applies to an accredited data recipient or designated gateway holding CDR data to which privacy safeguard 12 applies as if CDR data replaced personal information, the recipient or gateway replaced the entity and CDR consumers replaced individuals. The recipient must therefore assess suspected eligible data breaches of CDR data promptly (within 30 days under section 26WH) and, where a breach is likely to result in serious harm to a CDR consumer (whether an individual or a business), prepare a statement for the Information Commissioner and notify affected consumers. Failures are privacy safeguard breaches the Information Commissioner can investigate under section 56ET.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.