Part 6
Notifiable privacy breaches and compliance notices
Notifiable privacy breaches
117Requirements for notification
A notification to the Commissioner under section 114 must—
- describe the notifiable privacy breach, including—
- the number of affected individuals (if known); and
- the identity of any person or body that the agency suspects may be in possession of personal information as a result of the privacy breach (if known); and
- the number of affected individuals (if known); and
- explain the steps that the agency has taken or intends to take in response to the privacy breach, including whether any affected individual has been or will be contacted; and
- if the agency is relying on section 115(2) to give public notice of the breach, set out the reasons for relying on that section; and
- if the agency is relying on an exception, or is delaying notifying an affected individual or giving public notice, under section 116, state the exception relied on and set out the reasons for relying on it or state the reasons why a delay is needed and the expected period of delay; and
- state the names or give a general description of any other agencies that the agency has contacted about the privacy breach and the reasons for having done so; and
- give details of a contact person within the agency for inquiries.
A notification to an affected individual under section 115 or a representative under section 116(3) must—
- describe the notifiable privacy breach and state whether the agency has or has not identified any person or body that the agency suspects may be in possession of the affected individual’s personal information (but, except as provided in subsection (3), must not include any particulars that could identify that person or body); and
- explain the steps taken or intended to be taken by the agency in response to the privacy breach; and
- where practicable, set out the steps the affected individual may wish to take to mitigate or avoid potential loss or harm (if any); and
- confirm that the Commissioner has been notified under section 114; and
- state that the individual has the right to make a complaint to the Commissioner; and
- give details of a contact person within the agency for inquiries.
A notification to an affected individual or their representative may identify a person or body that has obtained or may obtain that affected individual’s personal information (where the identity is known) if the agency believes on reasonable grounds that identification is necessary to prevent or lessen a serious threat to the life or health of the affected individual or another individual.
A notification to an affected individual must not include any particulars about any other affected individuals.
In order to comply with the requirement under sections 114 and 115 that notification must be made as soon as practicable, an agency may provide the information required by this section incrementally. However, any information that is available at any point in time must be provided as soon as practicable after that point in time.