(1) Part 6A of the Privacy and Personal Information Protection Act 1998 establishes the NSW Mandatory Notification of Data Breach Scheme (‘the MNDB Scheme’). (2) The University of Wollongong (‘the University’) has an obligation to comply with the MNDB Scheme in the event of a data breach involving personal or health information, that is likely to result in serious harm to an individual (‘Eligible Data Breach’). (3) Under the MNDB Scheme, the University is required to prepare and publish a Data Breach Policy which outlines the University’s overall strategy for managing data breaches. The University is also required to maintain an internal register and public register of Eligible Data Breaches. (4) This Policy sets out: (5) This Policy is implemented by the Data Breach Response Plan and supported by the Privacy Policy, Information Security Policy and critical incident management processes. (6) All staff and affiliates must comply with this Policy. (7) This Policy applies where a suspected or known data breach occurs, involving personal and/or health information to all data that is in the possession or control of the University (‘held’) and/or that is the responsibility of the University under the State Records Act 1998. (8) This Policy does not apply to related entities. Related entities have their own policies and procedures for the management of data breaches. (9) A data breach occurs where personal and/or health information held by the University (whether held in digital or hard copy) is subject to unauthorised access, unauthorised disclosure or is lost in circumstances where the loss is likely to result in unauthorised access or unauthorised disclosure. A data breach may occur as the result of malicious action, systems failure, or human error. Examples of data breaches include: (10) For a data breach to constitute an Eligible Data Breach, there are two (2) tests to be satisfied: (11) Serious harm occurs where the harm arising from the Eligible Data Breach has, or may, result in a real and substantial detrimental effect to the individual. (12) Harm to an individual is context specific and will vary, and can include physical, economic, financial, social, emotional, psychological or reputational harm. (13) The NSW Privacy Commissioner’s Statutory Guidelines on the assessment of data breaches under Part 6A of the Privacy and Personal Information Protection Act 1998 will be considered by the University in its assessment of all data breaches impacting data held by the University. (14) An individual who becomes aware of a suspected or known data breach at the University is to immediately notify: (15) Where there are reasonable grounds to suspect that a data breach has occurred, the University must: (16) Where a data breach has been assessed as an Eligible Data Breach, the University must: (17) Each data breach should be assessed on a case-by-case basis and a response is to be determined, depending on the circumstances associated with the data breach. (18) The University recognises that data breaches require an immediate and effective response. To meet this requirement the University may work with internal and external experts to prepare for, respond to, manage and/or improve responses to data breaches. (19) The University will comply with all relevant statutory guidelines issued by the NSW Information and Privacy Commission (IPC) under Part 6A of the Privacy and Personal Information Protection Act 1998. (20) The Data Breach Response Flowchart at Appendix A provides details of the steps to be undertaken in dealing with a data breach. (21) The Information Compliance Unit is responsible for receiving reports of a data breach, triaging and leading the response as appropriate. Further responsibilities of the Information Compliance Unit are addressed in section 10 of this Policy. (22) Where required, the Data Breach Response Team will be convened and will include key subject matter experts, depending on the nature and impact of the data breach. Key subject matter experts may include: (23) The responsibilities of the Data Breach Response Team are set out at Section 10 of this Policy. (24) The Data Breach Response Team will be convened in the event of a data breach or suspected Eligible Data Breach and will coordinate the response in accordance with the Data Breach Response Plan. (25) The MNDB Scheme requires that the University notify affected individuals and the Privacy Commissioner when there has been an Eligible Data Breach. (26) The University has 30 days from the date it becomes aware of a suspected data breach to assess whether that data breach is an Eligible Data Breach. Whilst making this assessment, all reasonable attempts must be made to mitigate any harm already done. (27) Once the University decides there has been an Eligible Data Breach, it must, to the extent that it is reasonably practicable, take steps to notify each individual to whom the Information the subject of the breach relates or the affected individuals about that breach, taking into consideration the facts and circumstances of the breach. Limited exemptions may apply to this requirement, as detailed in sections 59S to 59X under Part 6A of the Privacy and Personal Information Protection Act 1998. (28) The University must comply with the applicable statutory guidelines issued by the NSW Information and Privacy Commission (IPC) as they apply to the relevant exemptions. (29) The University may also consider notifying affected individuals of a data breach as a matter of best practice, regardless of whether the breach relates to an Eligible Data Breach. (30) The communication standards as outlined in the University’s Crisis and Critical Incident Communication Plan (CCIP) will be applied to ensure that the objectives, goals and tasks are completed and expectations are managed with all affected individuals and stakeholders. Communications will be developed in accordance with the requirements of the CCIP. (31) If the University is unable to directly notify the individuals as described in clause 27, it will publish a public data breach notification on the University’s Public Notification Register (located on the University’s website) and take all reasonable steps to publicise the notification through appropriate channels available to the University. (32) In accordance with section 59O of the Privacy and Personal Information Protection Act 1998, the public data breach notification must provide details of: (33) The University’s Data Breach Response Plan provides further guidance relating to notification requirements. (34) The public notification will remain on the University’s Public Notification Register for a period of at least 12 months. (35) In accordance with section 59M of the Privacy and Personal Information Protection Act 1998, where an Eligible Data Breach has taken place (regardless of any applicable exemption), the University must immediately notify the NSW Privacy Commissioner using the Data Breach Notification to the Privacy Commissioner form. (36) Where a public notification is made on the University’s Public Notification Register, the University will advise the Privacy Commissioner on how to access the public notification on its website. (37) In some cases, the University may have reporting obligations under both the NSW MNDB Scheme as well as the Notifiable Data Breaches Scheme under the Privacy Act 1988. (38) Depending on the nature and severity of the data breach, the University will consider if external notification is necessary. This may include: (39) Further information regarding the steps that the University will take are set out in the Data Breach Response Plan. (40) The University will maintain appropriate records to provide evidence of the management of a data breach and to meet its recordkeeping obligations under the State Records Act 1998. (41) The University will also establish and maintain an internal register of all data breaches. Where an Eligible Data Breach has occurred, the following details will be captured, in compliance with obligations under the MNDB Scheme: (42) The University has established a range of systems and processes for preventing and managing data breaches. (43) Effective data breach management assists the University in avoiding or reducing possible harm to both the affected individuals/organisations and the University and may prevent future breaches. (44) The University is committed to regularly reviewing, maintaining and testing its systems and procedures in accordance with the Information Security Policy and other related information technology data security and disaster recovery policies. (45) This Policy and the Data Breach Response Plan will be reviewed and tested biennially or where improvements are identified in response to a data breach, whichever is sooner. (46) The review of this Policy will be aligned with the cyber security incident response and critical incident management review processes where practicable. (47) The University has controls in place to ensure it is prepared in the event of a data breach: (48) Where the University proposes to share data with a third-party such as a contractor, agent or consultant, for the purpose of undertaking work for or with the University, it will take reasonable steps to ensure that the third party has robust practices in place to protect the data and prevent its unauthorised use or disclosure. (49) The University must ensure that contracts and agreements with contracted service providers handling personal or health information (for example, system hosting) include appropriate provisions to meet the University’s obligations under this Policy, including at a minimum: (50) The Data Breach Response Plan provides further information regarding the University’s procedures for data breaches and contracted service providers. (51) The MNDB Scheme assigns various responsibilities to the head of an agency (the person responsible for the agency’s day to day management). In accordance with section 59ZJ of the Privacy and Personal Information Protection Act 1998, the head of an agency may delegate the exercise of those responsibilities to relevant staff. (52) The Vice-Chancellor and President, as the University’s head of an agency, has delegated the exercise of those responsibilities to relevant staff as outlined in this Policy, the Data Breach Response Plan and associated incident management processes. (53) The Vice President (Operations) is responsible for: (54) The General Counsel and Chief Legal, Assurance and Integrity Officer is responsible for: (55) The Chief Information Digital Officer is responsible for: (56) The Information Compliance Unit is responsible for: (57) The Data Breach Response Team is responsible for the exercise of the following functions: (58) Line Managers are responsible for: (59) All staff are responsible for: (60) Data Breach Response FlowchartData Breach Policy
Section 1 - Purpose of Policy
Section 2 - Application and Scope
Section 3 - Data Breach & Eligible Data Breach
Section 4 - Reporting a Data Breach
Top of PageSection 5 - Responding to a Data Breach
Section 6 - Data Breach Response Team
Section 7 - Notification
Notification to individuals
Public notification
Notification to the Privacy Commissioner
Other notification considerations
Section 8 - Recordkeeping Requirements
Top of PageSection 9 - Systems and Processes for Managing Data Breaches
Review and update
Training and awareness
Data breach provisions in supplier contracts / other collaboration agreements
Section 10 - Roles and Responsibilities
Top of PageSection 11 - Definitions
Top of Page
Section 12 - Appendix A: Data Breach Response Flowchart
View Current
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.
Word/Term
Definition
Affiliate
Includes people holding University of Wollongong Honorary Awards as conferred by the University Council, including the awards of Emeritus Professor, Honorary Doctor and University Fellow; people appointed in accordance with the University’s Academic Honorary Titles Policy; and people engaged by the University as agency staff, contractors, volunteers and work experience students.
Data Breach Response Team
A team of subject matter experts responsible for leading the University’s initial response to a potential or suspected Eligible data breach in accordance with the University’s Data Breach Response Plan. (This includes ensuring that immediate containment measures have been undertaken and an assessment has been conducted to determine escalation of the breach, where relevant.)
The Data Breach Response Team will be led by a suitably qualified subject matter expert who has sufficient authority and expertise to carry out the required response actions (see Section 6).Health information
Health information, for the purpose of this Policy, refers to health information defined in Health Records and Information Privacy Act 2002 (or as amended in the Health Records and Information Privacy Act 2002 from time to time) as:
“(a) personal information that is information or an opinion about:
(i) the physical or mental health or a disability (at any time) of an individual; or
(ii) an individual’s express wishes about the future provision of health services to him or her; or
(iii) a health service provided, or to be provided, to an individual; or
(b) other personal information collected to provide, or in providing, a health service; or
(c) other personal information about an individual collected in connection with the donation, or intended donation, of an individual’s body parts, organs or body substances; or
(d) other personal information that is genetic information about an individual arising from a health service provided to the individual in a form that is or could be predictive of the health (at any time) of the individual or of any sibling, relative or descendant of the individual; or
(e) healthcare identifiers.”
Information
Health information and/or personal information as the context permits
Line Manager
Staff member who directly or indirectly supervises another Staff member or holds a leadership responsibility.
Personal information
Personal information, for the purpose of this Policy, refers to personal information defined in the Privacy and Personal Information Protection Act 1998 (or as amended in the Privacy and Personal Information Protection Act 1998 from time to time) as:
“Information or an opinion (including information or an opinion forming part of a database and whether or not recorded in a material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion.” Under the Privacy and Personal Information Protection Act 1998, personal information does not include:
Public Notification Register
A register, made available on the University’s website, that contains details of an Eligible data breach so that individuals are adequately informed about the breach, are able to determine whether they may be affected and take action to protect their Information.
Related Entities
UOW Global Enterprises and UOW Pulse
Sensitive information
A subclass of Personal Information relating to an individual's ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities.
Staff
All people employed by the University including conjoint appointments, whether on continuing, permanent, fixed term, casual or cadet or traineeship basis. For the purpose of this Policy any reference to Staff is to be understood to mean both Staff and/or Affiliates.