- Australian Government agencies
- Businesses and not-for-profit organisations with an annual turnover of more than $3 million.
- Private sector health services providers (even alternative medicine practices, gyms and weight loss clinics fall under this category)
- Child care centres, private schools and private tertiary educational institutions.
- Businesses that sell or purchase personal information along with credit reporting bodies.
- Lost or stolen laptops, removable storage devices, or paper records containing personal information
- Hard disk drives and other digital storage media (integrated in other devices, for example, multifunction printers, or otherwise) being disposed of or returned to equipment lessors without the contents first being erased
- Databases containing personal information being ‘hacked’ into or otherwise illegally accessed by individuals outside of the agency or organisation
- Employees accessing or disclosing personal information outside the requirements or authorisation of their employment
- Paper records stolen from insecure recycling or garbage bins
- An agency or organisation mistakenly providing personal information to the wrong person, for example by sending details out to the wrong address, and;
- An individual deceiving an agency or organisation into improperly releasing the personal information of another person.
- There is unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information, that your organisation holds.
- This is likely to result in serious harm to one or more individuals.
- Your organisation has not been able to prevent the likely risk of serious harm with remedial action.
Your Next Steps
We’re here to help prevent you from finding yourself in a position where you must notify the OAIC of a data breach (and then deal with the possibility of a fine and other repercussions).
1. The first step is to understand your legal obligations. Within your organisation you need to have a full understanding of where you are with your technology and security policies. These need to be aligned with OAIC's strict guidelines.
2. The second step to compliance is to identify where the gaps lay within your organisations policies.
3. The solution needs to be determined to mitigate the gaps.
4. Actions need to be prioritised to ensure that you are able to effectively stand within OAIC's guidelines.
We are here to assist you with the creation of new and appropriate data management policies. The new laws are set to come into force in a matter of weeks. Click here to book an obligation free conversation with one of our experts. When it comes to changes as drastic as this, make sure your organisation is compliant – and never has to go to the OAIC with a notifiable breach.