Part 6
Notifiable privacy breaches and compliance notices
Notifiable privacy breaches
113Assessment of likelihood of serious harm being caused by privacy breach
When an agency is assessing whether a privacy breach is likely to cause serious harm in order to decide whether the breach is a notifiable privacy breach, the agency must consider the following:
- any action taken by the agency to reduce the risk of harm following the breach:
- whether the personal information is sensitive in nature:
- the nature of the harm that may be caused to affected individuals:
- the person or body that has obtained or may obtain personal information as a result of the breach (if known):
- whether the personal information is protected by a security measure:
- any other relevant matters.