Share New Policy - Data Breach 1124 on FacebookShare New Policy - Data Breach 1124 on X (formerly Twitter)Share New Policy - Data Breach 1124 on LinkedinEmail New Policy - Data Breach 1124 link
At the Ordinary Meeting of 18 August 2026, Oberon Council resolved to place the proposed Data Breach Policy on public exhibition for a period of 28 days, commencing 19 August 2026.
As part of amendments to the Privacy and Personal Information Protection Act 1998 (PPIP Act), a key change was the creation of a Mandatory Notification of Data Breach (MNDB) scheme, which requires public sector agencies to comply with the PPIP Act and notify the Privacy Commissioner and affected individuals of data breaches involving personal or health information likely to result in serious harm.
Adoption of this policy will assist Council's compliance with the MNDB scheme and associated legislative compliance with the PPIP Act and Privacy Act
The report presented to Council and the proposed policy are available for download in the Documents tab of this page. Community members are invited to review the updated policy and provide their submissions during the exhibition period.
Public submissions can be made below or sent via email to council@oberon.nsw.gov.au and must be received by the closure of the public exhibition period at 4:30pm on Wednesday 16 September 2026.
At the Ordinary Meeting of 18 August 2026, Oberon Council resolved to place the proposed Data Breach Policy on public exhibition for a period of 28 days, commencing 19 August 2026.
As part of amendments to the Privacy and Personal Information Protection Act 1998 (PPIP Act), a key change was the creation of a Mandatory Notification of Data Breach (MNDB) scheme, which requires public sector agencies to comply with the PPIP Act and notify the Privacy Commissioner and affected individuals of data breaches involving personal or health information likely to result in serious harm.
Adoption of this policy will assist Council's compliance with the MNDB scheme and associated legislative compliance with the PPIP Act and Privacy Act
The report presented to Council and the proposed policy are available for download in the Documents tab of this page. Community members are invited to review the updated policy and provide their submissions during the exhibition period.
Public submissions can be made below or sent via email to council@oberon.nsw.gov.au and must be received by the closure of the public exhibition period at 4:30pm on Wednesday 16 September 2026.
You need to be signed in to comment in this Guest Book.
You need to be signed in to comment in this Guest Book. Click here to Sign In or Register to get involved
27 August 2026
General Manager Oberon Council
Submission on Draft Data Breach Policy 1124
I support Council having a clear and effective Data Breach Policy. However, this draft contains definite factual errors, important statutory omissions and several provisions that are unclear or internally contradictory.
The policy should not be adopted in its present form.
The following errors and corrections are identified:
[Agenda report: “Privacy and Personal Protection Act 1998”] is incorrect. It should read: “Privacy and Personal Information Protection Act 1998 (NSW).”
[Policy: “Privacy Act 1998 (Cth)”] is incorrect. It should read: “Privacy Act 1988 (Cth).”
[Definition: “PPIP Act means the Privacy and Personal Information Protection Act 1988 (NSW)”] is incorrect. It should read: “PPIP Act means the Privacy and Personal Information Protection Act 1998 (NSW).”
[Definition: “HRIP Act means the Health Records Information and Privacy Act 2002 (NSW)”] is incorrect. It should read: “HRIP Act means the Health Records and Information Privacy Act 2002 (NSW).”
[“Relevant Manger or Director”] contains a drafting error. It should read: “Relevant Manager or Director.”
[“This Policy…does not apply to information that has been classified as public”] is unclear because “classified as public” is not defined. It should read: “This exclusion only applies where Council has determined that the information is lawfully publicly available or otherwise excluded from the definitions of personal or health information under the PPIP Act or HRIP Act. An internal classification alone does not determine whether the legislation applies.”
[The policy lists equipment failure, malware and denial of IT services as examples of data breaches] requires clarification. It should read: “Equipment failures, malware and denial-of-service attacks are security incidents that may result in a data breach. They are not automatically eligible data breaches unless the statutory requirements concerning personal or health information and likely serious harm are satisfied.”
[“Any Council Officer who becomes aware of a Data Breach will immediately notify the relevant Manager or Director”] does not clearly reflect the statutory reporting requirement. It should read: “An officer or employee who has reasonable grounds to suspect that an eligible data breach may have occurred must immediately report the suspected breach to the General Manager or a person formally authorised to exercise the General Manager’s functions under Part 6A of the PPIP Act.”
The current wording allows a suspected breach to remain with a manager or director while that person decides whether it might be a mandatory breach. The policy should identify one central reporting pathway and require every actual or suspected breach to be escalated immediately for proper assessment.
[The policy applies to councillors, volunteers, contractors and third-party providers but does not provide them with a clear reporting pathway] should be corrected by including: “Councillors, volunteers, contractors, consultants and third-party providers must immediately report an actual or suspected data breach to Council’s nominated privacy or data-breach contact.” The policy should provide the relevant email address, telephone number and after-hours process.
[The NSW assessment section does not state when the 30-day assessment period begins] is a significant omission. It should include: “The assessment must be undertaken expeditiously and completed within 30 calendar days after an officer or employee first becomes aware that there are reasonable grounds to suspect an eligible data breach may have occurred.”
The 30-day period does not commence when the matter eventually reaches the General Manager.
[The policy does not explain the statutory extension process] should be corrected by including: “An extension may only be approved where the assessment cannot reasonably be completed within 30 days. The Privacy Commissioner must be notified in writing within the original 30-day period. The notice must confirm that the assessment has commenced, state that an extension has been approved and specify the extension period. Further written notice must be given if another extension is required.”
[The policy allows the General Manager or Response Team to assess a breach but contains no assessor conflict-of-interest provision] omits a statutory requirement. It should include: “A person whom the General Manager reasonably suspects was involved in an action or omission that led to the breach must not be appointed as an assessor.” This is required by section 59G(3) of the PPIP Act.
[“All Council Officers will take all immediate steps to contain any Data Breach”] is too broad and may result in unauthorised action. It should read: “Council officers must immediately report the breach, preserve relevant evidence and take only safe and authorised containment action. The General Manager or authorised delegate must ensure that all reasonable efforts are made to contain the breach and mitigate harm.”
[The policy does not define “serious harm”] is an important omission. It should include: “Serious harm means a real and substantial detrimental effect on an individual and may include physical, economic, financial, emotional, psychological or reputational harm.”
[The notification section does not state what information must be provided to affected individuals] should be corrected by including the requirements of section 59O of the PPIP Act. The policy should state: “Where reasonably practicable, a notification must include the date of the breach, a description of what occurred, how it occurred, the type of breach, the personal or health information involved, the period of exposure, actions taken or planned, recommended protective steps, information about privacy complaints and internal reviews, Council’s name and Council contact details.”
[The policy refers to website notices, newspaper notices and media releases as forms of indirect notification] requires clarification. It should read: “Where Council cannot directly notify affected individuals, or direct notification is not reasonably practicable, Council must publish the prescribed notification on its public notification register and take reasonable steps to publicise that notification. Newspaper notices, media releases and other publicity are supplementary and do not replace the statutory register.”
[The policy does not address the statutory exemptions from notifying affected individuals] is a substantial omission. It should include: “The policy must address the exemptions concerning multiple-agency breaches, investigations or legal proceedings, successful mitigation, statutory secrecy, serious risks to health or safety and compromised cybersecurity. Any decision to rely on an exemption must be properly authorised and documented. An exemption from notifying individuals does not remove Council’s obligation to notify the Privacy Commissioner.”
[“Commonwealth Notifiable Data Breaches are specific to unauthorised access or disclosure of TFNs”] is incomplete and therefore incorrect. It should read: “Council’s Commonwealth notification obligations may arise where tax file number information is lost, accessed without authority or disclosed without authority, the breach is likely to result in serious harm and remedial action has not prevented that likely harm.”
[“Council has 30 days to complete this assessment from the date of the initial report of the Data Breach”] is incorrect for the Commonwealth assessment period. It should read: “Council must take all reasonable steps to complete the assessment within 30 days after becoming aware that there are reasonable grounds to suspect that an eligible data breach may have occurred.”
[The policy contains an internal eligible data breach register but does not state the annual-reporting obligation] is an omission. It should include: “Council must include the required summary of information from its eligible data breach incident register in its annual report, in accordance with section 59ZE of the PPIP Act.”
[“Steps 4 and 5 only need to be followed if the preceding steps result in any notification or review requirements”] contradicts the later statement that Council will conduct a detailed review of all data breaches. It should read: “Every data breach will receive a proportionate review. A formal post-incident review must be undertaken for every eligible, serious or high-risk data breach.”
[“Privacy Management Plan – Draft”] should be replaced with: “Council’s current, approved, implemented and publicly accessible Privacy Management Plan.” Council should confirm whether it presently has a Privacy Management Plan that complies with section 33 of the PPIP Act and addresses the Mandatory Notification of Data Breach Scheme.
[The section numbering jumps from section 4 to section 11] should be corrected so the document has complete and sequential section numbering.
[“Financial Implications: Nil”] is not supported by any explanation. Council should either substantiate this statement or replace it with: “Implementation and data breach response costs will be met from existing budgets where possible, with additional expenditure reported to Council as required.”
[The policy states that Council already has robust encryption, data-loss prevention systems, a current asset inventory, strong vulnerability management and regular independent penetration testing] should only remain if Council can verify that each of these controls is currently implemented, maintained and regularly tested.
For these reasons, I request that Draft Data Breach Policy 1124 not be adopted as presently written. It should be revised against Part 6A of the Privacy and Personal Information Protection Act 1998 and current Information and Privacy Commission guidance.
The amended policy, together with this and any other submissions, should then be reported back to Council for consideration and adoption. Any delegation to the General Manager should be limited to typographical and formatting corrections and should not extend to substantive changes to Council’s legal obligations or breach-response procedures.
The NSW Mandatory Notification of Data Breach Scheme commenced on 28 November 2023. I also request that Council advise what compliant and publicly accessible Data Breach Policy has been operating since that date.
This policy deals with the protection of the personal and health information of residents, staff, councillors and other members of the community. It must be legally accurate, clearly written and operationally capable of being followed from the moment a breach is first suspected.
27 August 2026
General Manager
Oberon Council
Submission on Draft Data Breach Policy 1124
I support Council having a clear and effective Data Breach Policy. However, this draft contains definite factual errors, important statutory omissions and several provisions that are unclear or internally contradictory.
The policy should not be adopted in its present form.
The following errors and corrections are identified:
[Agenda report: “Privacy and Personal Protection Act 1998”] is incorrect. It should read: “Privacy and Personal Information Protection Act 1998 (NSW).”
[Policy: “Privacy Act 1998 (Cth)”] is incorrect. It should read: “Privacy Act 1988 (Cth).”
[Definition: “PPIP Act means the Privacy and Personal Information Protection Act 1988 (NSW)”] is incorrect. It should read: “PPIP Act means the Privacy and Personal Information Protection Act 1998 (NSW).”
[Definition: “HRIP Act means the Health Records Information and Privacy Act 2002 (NSW)”] is incorrect. It should read: “HRIP Act means the Health Records and Information Privacy Act 2002 (NSW).”
[“Relevant Manger or Director”] contains a drafting error. It should read: “Relevant Manager or Director.”
[“This Policy…does not apply to information that has been classified as public”] is unclear because “classified as public” is not defined. It should read: “This exclusion only applies where Council has determined that the information is lawfully publicly available or otherwise excluded from the definitions of personal or health information under the PPIP Act or HRIP Act. An internal classification alone does not determine whether the legislation applies.”
[The policy lists equipment failure, malware and denial of IT services as examples of data breaches] requires clarification. It should read: “Equipment failures, malware and denial-of-service attacks are security incidents that may result in a data breach. They are not automatically eligible data breaches unless the statutory requirements concerning personal or health information and likely serious harm are satisfied.”
[“Any Council Officer who becomes aware of a Data Breach will immediately notify the relevant Manager or Director”] does not clearly reflect the statutory reporting requirement. It should read: “An officer or employee who has reasonable grounds to suspect that an eligible data breach may have occurred must immediately report the suspected breach to the General Manager or a person formally authorised to exercise the General Manager’s functions under Part 6A of the PPIP Act.”
The current wording allows a suspected breach to remain with a manager or director while that person decides whether it might be a mandatory breach. The policy should identify one central reporting pathway and require every actual or suspected breach to be escalated immediately for proper assessment.
[The policy applies to councillors, volunteers, contractors and third-party providers but does not provide them with a clear reporting pathway] should be corrected by including: “Councillors, volunteers, contractors, consultants and third-party providers must immediately report an actual or suspected data breach to Council’s nominated privacy or data-breach contact.” The policy should provide the relevant email address, telephone number and after-hours process.
[The NSW assessment section does not state when the 30-day assessment period begins] is a significant omission. It should include: “The assessment must be undertaken expeditiously and completed within 30 calendar days after an officer or employee first becomes aware that there are reasonable grounds to suspect an eligible data breach may have occurred.”
The 30-day period does not commence when the matter eventually reaches the General Manager.
[The policy does not explain the statutory extension process] should be corrected by including: “An extension may only be approved where the assessment cannot reasonably be completed within 30 days. The Privacy Commissioner must be notified in writing within the original 30-day period. The notice must confirm that the assessment has commenced, state that an extension has been approved and specify the extension period. Further written notice must be given if another extension is required.”
[The policy allows the General Manager or Response Team to assess a breach but contains no assessor conflict-of-interest provision] omits a statutory requirement. It should include: “A person whom the General Manager reasonably suspects was involved in an action or omission that led to the breach must not be appointed as an assessor.” This is required by section 59G(3) of the PPIP Act.
[“All Council Officers will take all immediate steps to contain any Data Breach”] is too broad and may result in unauthorised action. It should read: “Council officers must immediately report the breach, preserve relevant evidence and take only safe and authorised containment action. The General Manager or authorised delegate must ensure that all reasonable efforts are made to contain the breach and mitigate harm.”
[The policy does not define “serious harm”] is an important omission. It should include: “Serious harm means a real and substantial detrimental effect on an individual and may include physical, economic, financial, emotional, psychological or reputational harm.”
[The notification section does not state what information must be provided to affected individuals] should be corrected by including the requirements of section 59O of the PPIP Act. The policy should state: “Where reasonably practicable, a notification must include the date of the breach, a description of what occurred, how it occurred, the type of breach, the personal or health information involved, the period of exposure, actions taken or planned, recommended protective steps, information about privacy complaints and internal reviews, Council’s name and Council contact details.”
[The policy refers to website notices, newspaper notices and media releases as forms of indirect notification] requires clarification. It should read: “Where Council cannot directly notify affected individuals, or direct notification is not reasonably practicable, Council must publish the prescribed notification on its public notification register and take reasonable steps to publicise that notification. Newspaper notices, media releases and other publicity are supplementary and do not replace the statutory register.”
[The policy does not address the statutory exemptions from notifying affected individuals] is a substantial omission. It should include: “The policy must address the exemptions concerning multiple-agency breaches, investigations or legal proceedings, successful mitigation, statutory secrecy, serious risks to health or safety and compromised cybersecurity. Any decision to rely on an exemption must be properly authorised and documented. An exemption from notifying individuals does not remove Council’s obligation to notify the Privacy Commissioner.”
[“Commonwealth Notifiable Data Breaches are specific to unauthorised access or disclosure of TFNs”] is incomplete and therefore incorrect. It should read: “Council’s Commonwealth notification obligations may arise where tax file number information is lost, accessed without authority or disclosed without authority, the breach is likely to result in serious harm and remedial action has not prevented that likely harm.”
[“Council has 30 days to complete this assessment from the date of the initial report of the Data Breach”] is incorrect for the Commonwealth assessment period. It should read: “Council must take all reasonable steps to complete the assessment within 30 days after becoming aware that there are reasonable grounds to suspect that an eligible data breach may have occurred.”
[The policy contains an internal eligible data breach register but does not state the annual-reporting obligation] is an omission. It should include: “Council must include the required summary of information from its eligible data breach incident register in its annual report, in accordance with section 59ZE of the PPIP Act.”
[“Steps 4 and 5 only need to be followed if the preceding steps result in any notification or review requirements”] contradicts the later statement that Council will conduct a detailed review of all data breaches. It should read: “Every data breach will receive a proportionate review. A formal post-incident review must be undertaken for every eligible, serious or high-risk data breach.”
[“Privacy Management Plan – Draft”] should be replaced with: “Council’s current, approved, implemented and publicly accessible Privacy Management Plan.” Council should confirm whether it presently has a Privacy Management Plan that complies with section 33 of the PPIP Act and addresses the Mandatory Notification of Data Breach Scheme.
[The section numbering jumps from section 4 to section 11] should be corrected so the document has complete and sequential section numbering.
[“Financial Implications: Nil”] is not supported by any explanation. Council should either substantiate this statement or replace it with: “Implementation and data breach response costs will be met from existing budgets where possible, with additional expenditure reported to Council as required.”
[The policy states that Council already has robust encryption, data-loss prevention systems, a current asset inventory, strong vulnerability management and regular independent penetration testing] should only remain if Council can verify that each of these controls is currently implemented, maintained and regularly tested.
For these reasons, I request that Draft Data Breach Policy 1124 not be adopted as presently written. It should be revised against Part 6A of the Privacy and Personal Information Protection Act 1998 and current Information and Privacy Commission guidance.
The amended policy, together with this and any other submissions, should then be reported back to Council for consideration and adoption. Any delegation to the General Manager should be limited to typographical and formatting corrections and should not extend to substantive changes to Council’s legal obligations or breach-response procedures.
The NSW Mandatory Notification of Data Breach Scheme commenced on 28 November 2023. I also request that Council advise what compliant and publicly accessible Data Breach Policy has been operating since that date.
This policy deals with the protection of the personal and health information of residents, staff, councillors and other members of the community. It must be legally accurate, clearly written and operationally capable of being followed from the moment a breach is first suspected.
Yours sincerely
Councillor Helen Hayden
Oberon Council