Notifiable Data Breaches Scheme (Australia)
Notification to Individuals

Notifiable Data Breaches Scheme (Australia) AUNDB-A5: Notification to Affected Individuals: Methods and Content

Notify affected individuals per Privacy Act sections 26WL + 26WM. The entity must take steps as are reasonable in the circumstances to notify the contents of the statement to (a) each of the individuals to whom the relevant information relates (option 1 per section 26WL(2)(a)), OR (b) each of the individuals who are at risk from the eligible data breach (option 2 per section 26WL(2)(b)), OR (c) publish the statement on the entitys website + take reasonable steps to publicise the contents of the statement (option 3 per section 26WL(2)(c)) where it is not practicable for the entity to comply with option 1 or option 2. The notification to individuals must contain the same content as the statement to the Commissioner per section 26WK(3) + may include additional steps tailored to individuals (passwords to change + accounts to monitor + credit monitoring offers + support services). Notification method must be appropriate to the individuals + the breach (email + post + SMS + telephone + secure portal message) with consideration for accessibility + language + vulnerable persons. Document the notification method + content + reach + responses + complaints + remedial measures.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.