Notify Commissioner of non‑personal data breach
38 Notify Commissioner of non‑personal data breach
A data scheme entity must notify the Commissioner, in an approved form (if any), within the period applicable under subsection (1A) and in accordance with any requirements prescribed by a data code, if:
the entity reasonably suspects or becomes aware that a data breach of the entity has occurred; and
data involved in the breach is not personal information about one or more individuals.
Breaches involving personal information are dealt with under Part IIIC of the Privacy Act 1988 (see section 37).
Civil penalty: 300 penalty units.
The period for notifying the Commissioner is:
the period applicable under a data code; or
if there is no period applicable under a data code—as soon as practicable after the end of the financial year in which the breach occurs.
A data code may prescribe different periods for the purposes of paragraph (1A)(a), according to whether the breach is, or is not, a breach that a reasonable person would conclude would be likely to result in serious harm to an entity, a group of entities or a thing to which the data relates.
In determining whether a reasonable person would conclude that the breach would, or would not, be likely to result in serious harm to an entity, a group of entities or a thing to which the data involved in the breach relates, have regard to the following:
the kind or kinds of data;
the sensitivity of the data;
whether the data is protected by one or more security measures and, if so, the nature of those measures;
the persons, or the kinds of persons, who have obtained, or who could obtain, the data;
the nature of the harm;
any other relevant matters.
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.