Privacy Act 1988 (Australia)
Breach Response

Privacy Act 1988 (Australia) AUPRV-7: Notifiable Data Breaches (NDB) Scheme, Incident Response

Per Privacy Act Part IIIC Notifiable Data Breaches scheme: breach notification. Requirements include (a) implement Notifiable Data Breaches (NDB) Scheme - if an eligible data breach occurs (unauthorised access or disclosure of personal information + likely to result in serious harm) notify OAIC + affected individuals as soon as practicable + (b) conduct breach assessment within 30 days of becoming aware of suspected breach + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + assessment process + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting OAIC reporting.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 205 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

Malaysia PDPA 2010 · 4 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43
  • MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment
  • MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access

Peru DPL · 4 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements
  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance

South Korea PIPA · 4 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25

FedRAMP Rev 5 · 3 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT
  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)
  • GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement

ISO/IEC 27400:2022 · 3 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.5 Security monitoring and incident response
  • 27400-7.3 Data minimization and purpose limitation

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

Indonesia PDP Law · 3 controls

  • IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity
  • IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements
  • IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes

Liechtenstein DPA · 3 controls

Mauritius DPA · 3 controls

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection
  • MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration
  • MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability
  • MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
  • MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal
  • MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold
  • MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In

NIST SP 800-122 · 3 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 3 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data
  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

POPIA · 3 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

FISMA · 2 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

GLBA · 2 controls

  • GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
  • GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

India DPDP Act · 2 controls

  • INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary
  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

MTCS (Singapore) · 2 controls

  • MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA
  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM

Mexico LFPDPPP · 2 controls

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

PDPA Thailand · 2 controls

  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 4.4.7 Emergency and Incident Response
  • AL-DPA-12 International Data Transfers
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

HITECH Act · 1 control

  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors
  • HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF

IEEE 1686 · 1 control

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

IEEE 7000 · 1 control

  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)

ISMAP (Japan) · 1 control

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

Japan AI Guidelines · 1 control

  • JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle
  • JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • LAOS-CC-LaoCERT-Incident-Response-National-Cybersecurity-Coordination-Article-22 Laos Cybercrime LaoCERT + Incident Response + National Cybersecurity Coordination + Article 22

MARS-E · 1 control

  • MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning
  • PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 205 it maps to, and the evidence behind each claim, over MCP and REST.