View Current

Data Breach Policy

This is the current version of this document. To view historic versions, click the link in the document's navigation bar.

Section 1 - Purpose of Policy

(1) Part 6A of the Privacy and Personal Information Protection Act 1998 establishes the NSW Mandatory Notification of Data Breach Scheme  (‘the MNDB Scheme’).

(2) The University of Wollongong (‘the University’) has an obligation to comply with the MNDB Scheme in the event of a data breach involving personal or health information, that is likely to result in serious harm to an individual (‘Eligible Data Breach’).

(3) Under the MNDB Scheme, the University is required to prepare and publish a Data Breach Policy which outlines the University’s overall strategy for managing data breaches. The University is also required to maintain an internal register and public register of Eligible Data Breaches. 

(4) This Policy sets out:

  1. the University’s approach to effectively respond to a data breach and strategies to prevent future data breaches;
  2. the University’s commitment to manage Eligible Data Breaches in compliance with the MNDB Scheme;
  3. the roles and responsibilities of staff and affiliates for reporting, managing and reviewing data breaches.

(5) This Policy is implemented by the Data Breach Response Plan and supported by the Privacy Policy, Information Security Policy and critical incident management processes.

Top of Page

Section 2 - Application and Scope

(6) All staff and affiliates must comply with this Policy.

(7) This Policy applies where a suspected or known data breach occurs, involving personal and/or health information to all data that is in the possession or control of the University (‘held’) and/or that is the responsibility of the University under the State Records Act 1998.

(8) This Policy does not apply to related entities. Related entities have their own policies and procedures for the management of data breaches.

Top of Page

Section 3 - Data Breach & Eligible Data Breach

(9) A data breach occurs where personal and/or health information held by the University (whether held in digital or hard copy) is subject to unauthorised access, unauthorised disclosure or is lost in circumstances where the loss is likely to result in unauthorised access or unauthorised disclosure. A data breach may occur as the result of malicious action, systems failure, or human error. Examples of data breaches include:

  1. Unauthorised access by staff or sharing of data between teams within the University without relevant authority.
  2. Human error, such as:
    1. letter or email sent to the wrong recipient;
    2. system access is incorrectly granted to someone without appropriate authorisation;
    3. loss of a physical asset such as a paper record, laptop, USB stick or mobile phone containing data that is in the possession, control or the responsibility of the University; or
    4. failure to implement appropriate security measures such as password protection or sharing password and log in information.
  3. System failure, such as:
    1. a coding error allows access to a system without authentication, or results in automatically generated notices including incorrect information or being sent to incorrect recipients; or
    2. systems not maintained through the application of known and supported patches.
  4. Malicious or criminal attack, such as:
    1. cyber incidents such as ransomware, malware, hacking, phishing or brute force access attempts resulting in access to or theft of data;
    2. social engineering or impersonation leading into inappropriate disclosure of data;
    3. insider threats from agency employees using their valid credentials to access or disclose data outside the scope of their duties or permission; or
    4. theft of physical asset such as a paper record, laptop, USB stick or mobile phone containing data that is in the possession, control or the responsibility of the University.

(10) For a data breach to constitute an Eligible Data Breach, there are two (2) tests to be satisfied:

  1. There is an unauthorised access to, or unauthorised disclosure of, personal information held by a public sector agency or there is a loss of personal information held by a public sector agency in circumstances that are likely to result in unauthorised access to, or unauthorised disclosure of, the information; and
  2. A reasonable person would conclude that the access or disclosure of the information would be likely to result in serious harm to an individual to whom the information relates (affected individuals).

(11) Serious harm occurs where the harm arising from the Eligible Data Breach has, or may, result in a real and substantial detrimental effect to the individual.

(12) Harm to an individual is context specific and will vary, and can include physical, economic, financial, social, emotional, psychological or reputational harm.

(13) The NSW Privacy Commissioner’s Statutory Guidelines on the assessment of data breaches under Part 6A of the Privacy and Personal Information Protection Act 1998 will be considered by the University in its assessment of all data breaches impacting data held by the University.

Top of Page

Section 4 - Reporting a Data Breach

(14) An individual who becomes aware of a suspected or known data breach at the University is to immediately notify:

  1. the University’s Service Desk or at +61 2 4221 3000;
  2. Information Compliance Unit at icu-enquiry@uow.edu.au or +61 2 4221 4368 (during office hours); or
  3. for staff, their appropriate Line Manager or Supervisor.
Top of Page

Section 5 - Responding to a Data Breach

(15) Where there are reasonable grounds to suspect that a data breach has occurred, the University must:

  1. take immediate steps to contain the breach or suspected breach to minimise the possible damage;
  2. report the breach to the Information Compliance Unit who are authorised to receive and action a report of a suspected or known data breach;
  3. carry out an assessment of the breach to determine what has occurred and whether an Eligible Data Breach has occurred, within 30 days;
  4. make all reasonable attempts to mitigate any harm done by the suspected breach;
  5. consider whether notification under legislation or other policies, procedures or agreements may be required. This may include notification to:
    1. affected individuals;
    2. Privacy Commissioner;
    3. other regulatory bodies;
    4. third parties with collaborative or contractual ties with the University; and
  6. carry out post incident review and preventative efforts, based on the type and seriousness of the breach.

(16) Where a data breach has been assessed as an Eligible Data Breach, the University must:

  1. notify the Privacy Commissioner immediately, using the form approved by the Privacy Commissioner; and
  2. notify affected individuals as soon as practicable. The University may elect to notify either:
    1. all individuals regardless of their risk of harm; or
    2. only those individuals who are likely to suffer serious harm as a result of the data breach that relates to them.

(17) Each data breach should be assessed on a case-by-case basis and a response is to be determined, depending on the circumstances associated with the data breach.

(18) The University recognises that data breaches require an immediate and effective response. To meet this requirement the University may work with internal and external experts to prepare for, respond to, manage and/or improve responses to data breaches.

(19) The University will comply with all relevant statutory guidelines issued by the NSW Information and Privacy Commission (IPC) under Part 6A of the Privacy and Personal Information Protection Act 1998.

(20) The Data Breach Response Flowchart at Appendix A provides details of the steps to be undertaken in dealing with a data breach.

Top of Page

Section 6 - Data Breach Response Team

(21) The Information Compliance Unit is responsible for receiving reports of a data breach, triaging and leading the response as appropriate. Further responsibilities of the Information Compliance Unit are addressed in section 10 of this Policy.

(22) Where required, the Data Breach Response Team will be convened and will include key subject matter experts, depending on the nature and impact of the data breach. Key subject matter experts may include:

  1. Information Compliance Unit;
  2. General Counsel and Chief Legal, Assurance and Integrity Officer;
  3. Records and evidence support;
  4. Technical support from IMTS;
  5. Communication support from the Brand, Marketing and Communication Division;
  6. Data Guardian and Data Stewards as defined in the Data Governance and Management Policy; and
  7. Other staff as necessary, depending on the context of the data breach.

(23) The responsibilities of the Data Breach Response Team are set out at Section 10 of this Policy.

(24) The Data Breach Response Team will be convened in the event of a data breach or suspected Eligible Data Breach and will coordinate the response in accordance with the Data Breach Response Plan.

Top of Page

Section 7 - Notification

(25) The MNDB Scheme requires that the University notify affected individuals and the Privacy Commissioner when there has been an Eligible Data Breach.

(26) The University has 30 days from the date it becomes aware of a suspected data breach to assess whether that data breach is an Eligible Data Breach. Whilst making this assessment, all reasonable attempts must be made to mitigate any harm already done.

Notification to individuals

(27) Once the University decides there has been an Eligible Data Breach, it must, to the extent that it is reasonably practicable, take steps to notify each individual to whom the Information the subject of the breach relates or the affected individuals about that breach, taking into consideration the facts and circumstances of the breach.  Limited exemptions may apply to this requirement, as detailed in sections 59S to 59X under Part 6A of the Privacy and Personal Information Protection Act 1998.

(28) The University must comply with the applicable statutory guidelines issued by the NSW Information and Privacy Commission (IPC) as they apply to the relevant exemptions.

(29) The University may also consider notifying affected individuals of a data breach as a matter of best practice, regardless of whether the breach relates to an Eligible Data Breach.

(30) The communication standards as outlined in the University’s Crisis and Critical Incident Communication Plan (CCIP) will be applied to ensure that the objectives, goals and tasks are completed and expectations are managed with all affected individuals and stakeholders. Communications will be developed in accordance with the requirements of the CCIP.

Public notification

(31) If the University is unable to directly notify the individuals as described in clause 27, it will publish a public data breach notification on the University’s Public Notification Register (located on the University’s website) and take all reasonable steps to publicise the notification through appropriate channels available to the University.

(32) In accordance with section 59O of the Privacy and Personal Information Protection Act 1998, the public data breach notification must provide details of:

  1. the circumstances of the data breach, including a description of the breach and the type of information impacted;
  2. the actions the University has taken or plans to take to control or mitigate the harm to individuals;
  3. steps that an affected individual should consider taking in response to the data breach; and
  4. how the individual may contact the University for any additional information.

(33) The University’s Data Breach Response Plan provides further guidance relating to notification requirements.

(34) The public notification will remain on the University’s Public Notification Register for a period of at least 12 months.

Notification to the Privacy Commissioner

(35) In accordance with section 59M of the Privacy and Personal Information Protection Act 1998, where an Eligible Data Breach has taken place (regardless of any applicable exemption), the University must immediately notify the NSW Privacy Commissioner using the Data Breach Notification to the Privacy Commissioner form.

(36) Where a public notification is made on the University’s Public Notification Register, the University will advise the Privacy Commissioner on how to access the public notification on its website.

Other notification considerations

(37) In some cases, the University may have reporting obligations under both the NSW MNDB Scheme as well as the Notifiable Data Breaches Scheme under the Privacy Act 1988.

(38) Depending on the nature and severity of the data breach, the University will consider if external notification is necessary. This may include:

  1. NSW Police Force and/or Australian Federal Police, where the University suspects a data breach is a result of criminal activity;
  2. Cyber Security NSW, the Office of the Government Chief Information Security Officer and The Australian Cyber Security Centre, where a data breach is a result of a cyber security incident;
  3. The Office of the Australian Information Commissioner, where a data breach may involve agencies under the Federal jurisdiction;
  4. Any third-party organisations, contractors or agencies whose data may be affected;
  5. The State Records Authority NSW where records are unlawfully accessed, destroyed, deleted or altered and the integrity of the records has been impacted;
  6. Financial services providers, where a data breach includes an individual’s financial information;
  7. Professional associations, regulatory bodies or insurers, where a data breach may have an impact on these organisations, their functions and their clients; or
  8. The Australian Cyber Security Centre where a data breach involves malicious activity from a person or organisation based outside Australia.

(39) Further information regarding the steps that the University will take are set out in the Data Breach Response Plan.

Top of Page

Section 8 - Recordkeeping Requirements

(40) The University will maintain appropriate records to provide evidence of the management of a data breach and to meet its recordkeeping obligations under the State Records Act 1998.

(41) The University will also establish and maintain an internal register of all data breaches. Where an Eligible Data Breach has occurred, the following details will be captured, in compliance with obligations under the MNDB Scheme:

  1. who was notified of the breach;
  2. when notification of the breach was made;
  3. the type of breach;
  4. the steps taken by the University to mitigate harm done by the breach;
  5. the actions taken to prevent future breaches; and
  6. the estimated cost of the breach.
Top of Page

Section 9 - Systems and Processes for Managing Data Breaches

(42) The University has established a range of systems and processes for preventing and managing data breaches.

(43) Effective data breach management assists the University in avoiding or reducing possible harm to both the affected individuals/organisations and the University and may prevent future breaches.

Review and update

(44) The University is committed to regularly reviewing, maintaining and testing its systems and procedures in accordance with the Information Security Policy and other related information technology data security and disaster recovery policies.

(45) This Policy and the Data Breach Response Plan will be reviewed and tested biennially or where improvements are identified in response to a data breach, whichever is sooner. 

(46) The review of this Policy will be aligned with the cyber security incident response and critical incident management review processes where practicable.

Training and awareness

(47) The University has controls in place to ensure it is prepared in the event of a data breach:

  1. Mandatory privacy training in staff induction on obligations under privacy legislation;
  2. Proactively identifying security vulnerabilities which may impact the University’s information through active monitoring and auditing of public domains;
  3. Initiatives to increase cyber security maturity, including mandatory cyber training as outlined in the Acceptable Use of IT Resources Policy and relevant procedures for the appropriate sharing of personal and sensitive information;
  4. Desktop data breach exercises;
  5. Privacy and records training for University staff on privacy and records legislation;
  6. Maintenance and implementation of a Privacy Management Plan outlining the University’s initiatives and procedures for ensuring compliance with the Privacy and Personal Information Protection Act 1998 and Health Records and Information Privacy Act 2002;
  7. Maintenance of a public facing webpage with resources for the public and clear directions on how to report a suspected data breach;
  8. Internal resources to help staff identify, report and respond to a suspected data breach, including:
    1. Training and awareness activities on eligible data breaches under the MNDB scheme;
    2. Details of the kinds of data breaches that may amount to an eligible data breach, the actions to be taken in response to a data breach and measures to be taken to prevent future data breaches;
    3. This Policy and the Data Breach Response Plan; and
    4. Links to the IPC resources relating to data breaches and the MNDB Scheme.

Data breach provisions in supplier contracts / other collaboration agreements

(48) Where the University proposes to share data with a third-party such as a contractor, agent or consultant, for the purpose of undertaking work for or with the University, it will take reasonable steps to ensure that the third party has robust practices in place to protect the data and prevent its unauthorised use or disclosure.

(49) The University must ensure that contracts and agreements with contracted service providers handling personal or health information (for example, system hosting) include appropriate provisions to meet the University’s obligations under this Policy, including at a minimum:

  1. Timeframes for reporting suspected data breaches to the University;
  2. Requirements for cooperation in assessing and mitigating a data breach; and
  3. Where relevant, notification responsibilities.

(50) The Data Breach Response Plan provides further information regarding the University’s procedures for data breaches and contracted service providers.

Top of Page

Section 10 - Roles and Responsibilities

(51) The MNDB Scheme assigns various responsibilities to the head of an agency (the person responsible for the agency’s day to day management). In accordance with section 59ZJ of the Privacy and Personal Information Protection Act 1998, the head of an agency may delegate the exercise of those responsibilities to relevant staff.

(52) The Vice-Chancellor and President, as the University’s head of an agency, has delegated the exercise of those responsibilities to relevant staff as outlined in this Policy, the Data Breach Response Plan and associated incident management processes.

(53) The Vice President (Operations) is responsible for:

  1. deciding whether a data breach is an Eligible Data Breach, or there are reasonable grounds to believe the data breach is an Eligible Data Breach;
  2. escalating data breach response actions to the Critical Incident Management Team, as appropriate;
  3. making determinations regarding the application of any exemptions and approval of any extension periods, as outlined in the MNDB Scheme;
  4. where the University is unable to notify, or it is not practicable to notify, any or all of the affected individuals, making a determination to publish a public notification via the University’s Public Notification Register; and
  5. deciding whether external notification or engagement is required e.g. law enforcement or other third parties (see Section 7) based on guidance from the General Counsel and Chief Legal, Assurance and Integrity Officer.

(54) The General Counsel and Chief Legal, Assurance and Integrity Officer is responsible for:

  1. conducting an assessment of whether the data breach is, or there are reasonable grounds to believe the data breach is an Eligible Data Breach, within 30 days after being made aware that a data breach has occurred;
  2. where an assessment confirms an Eligible Data Breach, escalating the assessment to the Vice President (Operations);
  3. notifying the Privacy Commissioner immediately in the approved form, if the data breach is an Eligible Data Breach;
  4. notifying each individual to whom the information the subject of the breach relates, or each affected individual;
  5. providing written notice to the Privacy Commissioner regarding the application of any exemptions, any extension periods, or how to access any public notifications made by the University, as outlined in the MNDB Scheme;
  6. identifying and making a recommendation to the Vice President (Operations) as to whether other external notification or engagement is required e.g. law enforcement or other third parties;
  7. identifying legal obligations and providing advice, as required.

(55) The Chief Information Digital Officer is responsible for:

  1. ensuring all steps are taken in accordance with the Cybersecurity Incident Response Plan; and
  2. engaging and liaising with external cyber incident response service providers or other resources with requisite expertise, where necessary.

(56) The Information Compliance Unit is responsible for:

  1. receiving data breach notifications and confirming preliminary assessment reports; 
  2. assessing the containment and/or remediation measures already undertaken (if any) and taking further actions as required to mitigate any further compromise of the data;
  3. where a preliminary assessment confirms a suspected or known Eligible Data Breach, escalating the preliminary assessment to General Counsel and Chief Legal, Assurance and Integrity Officer;
  4. making a determination to convene the Data Breach Response Team, in consultation with the General Counsel and Chief Legal, Assurance and Integrity Officer. Where a determination has been made to convene the Data Breach Response Team, the following actions will be conducted by the Senior Manager, Information Compliance (or delegate) in their capacity as lead coordinator of the team:
    1. ensuring data breach response actions are conducted in accordance with this Policy and the Data Breach Response Plan;
    2. ensuring that all response actions are recorded in the Data Breach Report Form and retained in accordance with the Records Management Policy;
    3. ensuring any relevant evidence of the data breach is preserved and securely stored, as appropriate;
    4. conducting and leading the post-response assessment of the University’s response to the data breach;
  5. establishing, maintaining and recording data breaches on the University’s internal data breach register;
  6. managing any complaints received as a result of the data breach;
  7. reviewing, testing and updating this Policy at least biennially.

(57) The Data Breach Response Team is responsible for the exercise of the following functions:

  1. Lead coordinator: Senior Manager, Information Compliance or delegate, to lead the response and provide privacy expertise. Where a suspected eligible data breach has occurred, the Senior Manager, Information Compliance or delegate will carry out required actions as outlined at Section 10 of this Policy;
  2. General Counsel and Chief Legal, Assurance and Integrity Officer: responsible for reporting to the Senior Executive, providing legal support and supporting team members. Where a suspected eligible data breach has occurred, the General Counsel and Chief Legal, Assurance and Integrity Officer will carry out required actions as outlined at Section 10 of this Policy;
  3. Records and evidence support: maintain records of all actions taken by the Data Breach Response Team and providing administrative support;
  4. Technical support: a member of IMTS to facilitate response and containment actions, assist with root cause analysis and provide forensic support;
  5. Communication support: a member of the Brand, Marketing and Communication Division to assist with communication to stakeholders and affected individuals, where relevant;
  6. Data Guardian: senior leadership with high-level knowledge, expertise and tactical decision making in respect of data within their responsibility, where relevant;
  7. Data Steward: business and technical subject matter experts who typically provide ongoing technical support as a part of their day-to-day role, where relevant;
  8. Other staff, depending on the context of the breach.

(58) Line Managers are responsible for:

  1. receiving notifications of a suspected or known data breach and taking local immediate containment steps to prevent any further compromise of the data;
  2. conducting an initial assessment of the data breach, notifying the relevant Data Guardian as appointed under the Data Governance and Management Policy and consulting with the Information Compliance Unit to determine appropriate response actions;
  3. where a data breach can be/is being managed appropriately locally, ensuring that a completed Data Breach Report Form is submitted to the Information Compliance Unit and retained in accordance with the Records Management Policy;
  4. participating in response actions, in accordance with this Policy and associated incident management processes.

(59) All staff are responsible for:

  1. reporting any suspected or known data breaches immediately, as per section 4 of this Policy; 
  2. assisting in response actions in accordance with this Policy and the Data Breach Response Plan.
Top of Page

Section 11 - Definitions

Word/Term
Definition
Affiliate
Includes people holding University of Wollongong Honorary Awards as conferred by the University Council, including the awards of Emeritus Professor, Honorary Doctor and University Fellow; people appointed in accordance with the University’s Academic Honorary Titles Policy;  and people engaged by the University as agency staff, contractors, volunteers and work experience students.
Data Breach Response Team
A team of subject matter experts responsible for leading the University’s initial response to a potential or suspected Eligible data breach in accordance with the University’s Data Breach Response Plan. (This includes ensuring that immediate containment measures have been undertaken and an assessment has been conducted to determine escalation of the breach, where relevant.)
The Data Breach Response Team will be led by a suitably qualified subject matter expert who has sufficient authority and expertise to carry out the required response actions (see Section 6).
Health information
Health information, for the purpose of this Policy, refers to health information defined in Health Records and Information Privacy Act 2002 (or as amended in the Health Records and Information Privacy Act 2002 from time to time) as:
“(a) personal information that is information or an opinion about:
(i) the physical or mental health or a disability (at any time) of an individual; or
(ii) an individual’s express wishes about the future provision of health services to him or her; or
(iii) a health service provided, or to be provided, to an individual; or
(b) other personal information collected to provide, or in providing, a health service; or
(c) other personal information about an individual collected in connection with the donation, or intended donation, of an individual’s body parts, organs or body substances; or
(d) other personal information that is genetic information about an individual arising from a health service provided to the individual in a form that is or could be predictive of the health (at any time) of the individual or of any sibling, relative or descendant of the individual; or
(e) healthcare identifiers.”
Information
Health information and/or personal information as the context permits
Line Manager
Staff member who directly or indirectly supervises another Staff member or holds a leadership responsibility.
Personal information
Personal information, for the purpose of this Policy, refers to personal information defined in the Privacy and Personal Information Protection Act 1998 (or as amended in the Privacy and Personal Information Protection Act 1998 from time to time) as:
“Information or an opinion (including information or an opinion forming part of a database and whether or not recorded in a material form) about an individual whose identity is apparent or can reasonably be ascertained from the information or opinion.” Under the Privacy and Personal Information Protection Act 1998, personal information does not include:
  1. information regarding an individual who has been deceased for more than 30 years;
  2. information about an individual that is readily available in a publicly available publication; and
  3. information or an opinion about an individual’s suitability for appointment or employment as a public sector official.
Public Notification Register
A register, made available on the University’s website, that contains details of an Eligible data breach so that individuals are adequately informed about the breach, are able to determine whether they may be affected and take action to protect their Information.
Related Entities
UOW Global Enterprises and UOW Pulse
Sensitive information
A subclass of Personal Information relating to an individual's ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership or sexual activities.
Staff
All people employed by the University including conjoint appointments, whether on continuing, permanent, fixed term, casual or cadet or traineeship basis. For the purpose of this Policy any reference to Staff is to be understood to mean both Staff and/or Affiliates.
Top of Page

Section 12 -  Appendix A: Data Breach Response Flowchart

(60) Data Breach Response Flowchart