Notifiable Data Breaches Scheme (Australia)
Notification to OAIC

Notifiable Data Breaches Scheme (Australia) AUNDB-A4: Notification to the Commissioner: Statement Content and Timing

Prepare and lodge the statement to the Commissioner per Privacy Act sections 26WK + 26WL. Notification must be (a) prepared as soon as practicable after the entity is aware of reasonable grounds to believe that there has been an eligible data breach, (b) lodged with the OAIC via the OAIC Notifiable Data Breach form covering the required content per section 26WK(3): the identity and contact details of the entity + a description of the eligible data breach that the entity has reasonable grounds to believe has happened + the kind or kinds of information concerned + recommendations about the steps that individuals should take in response to the eligible data breach. Where the breach is a joint eligible data breach per section 26WJ involving more than one entity, only one entity is required to comply with section 26WK provided it does so on behalf of all entities. Notification to the OAIC commences the OAIC engagement which may include further requests for information + investigation + remedial action expectations + public commentary. Maintain working liaison with OAIC throughout the response period.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.