Data Breach

To set out procedures to implement the mandatory notifiable data breaches scheme that applies under the Privacy Act 1988 .

Data breach means unauthorised access to, or unauthorised disclosure of, personal information or a loss of personal information. Examples of a data breach are when a device containing personal information is lost or stolen, an entity’s database containing personal information is hacked or an entity mistakenly provides personal information to the wrong person.

Notifiable data breach means a data breach that is likely to result in serious harm, which must be notified to affected individuals and the Office of the Australian Information Commissioner (OAIC).

Personal information means information or an opinion about an individual who is identified, or who can reasonably be identified, from the information, whether or not the information or opinion is true or recorded in a material form, and includes sensitive information; and

Sensitive information means information or an opinion that is also personal information, about a person’s racial or ethnic origin, political opinions, memberships of political, professional and trade associations and unions, religious and philosophical beliefs, sexual orientation or practises, criminal history, health information, and genetic and biometric information.

Identification of a breach

Assessment of a breach

A response team will be formed for a serious breach. The team will include all senior LHS staff members and the LHS Privacy Officer, as well as a legal team that will provide legal advice and compliance.

Breaches that are not serious

Breaches that are not assessed as serious breaches may be handled by the senior LHS staff members, but must be reported to the LHS Privacy Officer.

Documentation will be stored by LHS electronically for each suspected breach.

Questions? Contact [email protected]

Updated September 2023

Recommended articles