Part 6
Notifiable privacy breaches and compliance notices
Notifiable privacy breaches
115Agency to notify affected individual or give public notice of notifiable privacy breach
An agency must notify an affected individual as soon as practicable after becoming aware that a notifiable privacy breach has occurred, unless subsection (2) or an exception in section 116 applies or a delay is permitted under section 116(4).
If it is not reasonably practicable to notify an affected individual or each member of a group of affected individuals, the agency must instead give public notice of the privacy breach, unless an exception in section 116 applies or a delay is permitted under section 116(4).
Public notice must be given—
- in a form in which no affected individual is identified; and
- in accordance with any regulations made under section 215(1)(a).
If subsection (2) or an exception in section 116 is relied on, the agency must notify the affected individual or individuals at a later time if—
- circumstances change so that subsection (2) or the exception no longer applies; and
- at that later time, there is or remains a risk that the privacy breach will cause serious harm to the affected individual or individuals.
A failure to notify an affected individual or give public notice under this section may be an interference with privacy under this Act (see section 69(2)(a)(iv)).