Apply the statutory exceptions per Privacy Act sections 26WF + 26WJ + 26WM(3) + 26WP. Remedial action exception per section 26WF: where the entity takes action before the unauthorised access or unauthorised disclosure results in serious harm to any individuals to whom the relevant information relates + a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals as a result of that action, the breach is not an eligible data breach. Document the remedial action + decision + rationale + evidence. Joint handling exception per section 26WJ: where two or more entities jointly and simultaneously hold personal information and the eligible data breach affects all of them, only one entity needs to comply per the documented agreement among them. Enforcement exception per section 26WP: certain enforcement bodies are exempted in specified circumstances. Inconsistency with other law per section 26WM(3): notification may be modified where inconsistent with other statutory non-disclosure obligations. Apply exceptions narrowly + with documented legal advice + record-keeping per OAIC expectation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.