Obligations of agencies in relation to data breaches
48 Obligations of agencies in relation to data breaches
This section applies in relation to a data breach of an agency if the agency knows, or reasonably suspects, that the data breach is an eligible data breach of the agency.
The agency must—
immediately, and continue to, take all reasonable steps to—
contain the data breach;
and
mitigate the harm caused by the data breach; and
if the agency does not know whether the data breach is an eligible data breach of the agency—assess whether there are reasonable grounds to believe the data breach is an eligible data breach of the agency.
An assessment under subsection (2)(b) must be completed within—
30 days after the suspicion mentioned in subsection (1) was formed; or
if the period mentioned in paragraph (a) is extended under section 49—the extended period.
If, at any time, the agency becomes aware the data breach may affect another agency, the agency must give a written notice to the other agency of the data breach that includes—
a description of the data breach;
and
a description of the kind of personal information the subject of the data breach, without including any personal information in the description.
The agency need not comply with subsections (2)(b) and (3) in relation to the data breach if—
all of the personal information the subject of the data breach is also the subject of a data breach of 1 or more other agencies;
and
at least 1 of the other agencies has undertaken to conduct the assessment in relation to the data breach.
This Act’s bill:Explanatory memorandumSecond reading speech
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.