TemplateDownload as markdown

Data Breach Response Plan — Template

A one-page plan for a small Australian software product. Replace every [bracket]. Written for the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988; use it even if the small business exemption probably covers you — the plan is cheap and improvising mid-incident is not.

Owner: [name — for a solo operator, that’s you: assessor and decision-maker]

Scope: all products operated by [company]. Review annually or after any incident.


What counts as a breach

Unauthorised access to, unauthorised disclosure of, or loss of personal information held by [company] or its processors. Examples worth listing for your own product:

Step 1 — Contain (immediately, same day)

Step 2 — Assess (start immediately; complete within 30 days at the outside)

Step 3 — Notify (as soon as practicable, if serious harm is likely and not remediated)

Step 4 — Record and review

Detection — your known weak point (keep a standing list)

Most small products would not notice a breach. Write down, honestly, the gaps that would stop you noticing one, and treat each as a breach-readiness item, not just ops:

The point of this section is that it is a register, not a boast. A gap you have written down is one you can close; a gap you have not is one you will discover mid-incident.

Key locations

This template ships alongside the au-compliance-pack skills: github.com/UgoHarry/au-compliance-pack.


Not legal advice; details verified against OAIC guidance at the time of writing.