Free template
Notifiable data breach response template
A step-by-step template for the moment you actually need it — a lost laptop, a misdirected email, unauthorised access to client files — built around the Privacy Act's Notifiable Data Breaches (NDB) scheme.
Does this apply to a small practice?
Yes — health service providers aren't exempt
The Privacy Act's small-business exemption doesn't cover health service providers, which includes counselling. That means the NDB scheme applies to your practice the same way it applies to a large health provider, regardless of your turnover or client numbers. See our Privacy Act compliance checklist for the broader picture.
What counts
What actually makes something an "eligible data breach"
Not every mistake is a notifiable breach. An eligible data breach under the Act generally has three elements: unauthorised access to, unauthorised disclosure of, or loss of personal information; that a reasonable person would conclude is likely to result in serious harm to the individuals it's about; and that you haven't been able to prevent that risk with fast remedial action. If you act quickly enough to prevent likely serious harm — for example, remotely wiping a lost device before anything could be accessed — it may not need to be notified at all.
The response
Four steps, in order
Contain
Stop the breach continuing before anything else — revoke access, change credentials, remotely wipe a device, recall a misdirected email. Do this first; assessment and notification come after containment, not instead of it.
Assess
Once you suspect a breach may be eligible, you generally have 30 days to carry out a reasonable and expeditious assessment of whether it actually meets the "likely to result in serious harm" threshold. Document what you find either way — even a "this wasn't notifiable, and here's why" conclusion should be on record.
Notify
If it is an eligible data breach, notify the OAIC and affected individuals as soon as practicable. The statement needs to identify you and your contact details, describe the breach, list the kinds of information involved, and recommend what affected individuals should do in response.
Review
Once it's contained and notified, look at why it happened and what would actually prevent a repeat — a process gap, a missing access control, a training gap — and fix that, not just the immediate symptom.
Fill this in when it happens
Incident log template
______________________________________________________
______________________________________________________
______________________________________________________
______________________________________________________
______________________________________________________
______________________________________________________
Template only, not legal advice — statutory timeframes and notification requirements are set by the Privacy Act and OAIC guidance, which can change. Confirm your specific obligations with the OAIC or a lawyer, particularly for anything time-sensitive.
Built into the platform
Fewer places for a breach to happen in the first place
Australian hosting, encryption in transit and at rest, access controls, and a full audit log on every client file — so if something ever does go wrong, you have exactly the record this template asks for, not a scramble to reconstruct it. See our security page.
Get a link to this template by email
So it's ready to find, not buried in your browser history, if you ever actually need it.
Also relevant: Privacy Act compliance checklist and how Zenvia handles security.