Notifiable Data Breaches Scheme (Australia)
Applicability and Response Plan

Notifiable Data Breaches Scheme (Australia) AUNDB-A1: Applicability, Scope, and Data Breach Response Plan

Determine applicability and maintain a documented data breach response plan per the Notifiable Data Breaches scheme established by the Privacy Amendment (Notifiable Data Breaches) Act 2017 + Part IIIC of the Privacy Act 1988 (Cth) administered by the Office of the Australian Information Commissioner (OAIC). The scheme applies to APP entities under section 6(1) of the Privacy Act including Australian Government agencies + private sector organisations with annual turnover above the small business threshold (3 million AUD) or otherwise covered (private health providers + credit reporting bodies + tax file number recipients + employee record holders covered for non-employee records). Document scope of personal information held + applicable specific obligations (credit reporting per Part IIIA + tax file number information). Maintain a Data Breach Response Plan covering roles + response team + decision authority for breach assessment and notification + workflow + templates + contact lists + integration with broader incident response per NIST SP 800-61 or ISO/IEC 27035 + post-incident review + plan testing.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.