Amendments Schedule 1 Note: See also subsections 26WF(2) and (5), which deal with remedial action. (3) Before giving a direction to an entity under subsection (1), the Commissioner must invite the entity to make a submission to the Commissioner in relation to the direction within the period specified in the invitation. (4) The statement referred to in paragraph (1)(a) must set out: (a) the identity and contact details of the entity; and (b) a description of the eligible data breach that the Commissioner has reasonable grounds to believe has happened; and (c) the kind or kinds of information concerned; and (d) recommendations about the steps that individuals should take in response to the eligible data breach that the Commissioner has reasonable grounds to believe has happened. (5) A direction under subsection (1) may also require the statement referred to in paragraph (1)(a) to set out specified information that relates to the eligible data breach that the Commissioner has reasonable grounds to believe has happened. (6) In deciding whether to give a direction to an entity under subsection (1), the Commissioner must have regard to the following: (a) any relevant advice given to the Commissioner by: (i) an enforcement body; or (ii) the Australian Signals Directorate of the Defence Department; (b) any relevant submission that was made by the entity: (i) in response to an invitation under subsection (3); and (ii) within the period specified in the invitation; (c) such other matters (if any) as the Commissioner considers relevant. (7) Paragraph (6)(a) does not limit the advice to which the Commissioner may have regard. (8) If the Commissioner is aware that there are reasonable grounds to believe that the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or No. 12, 2017 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 19

Select target paragraph3