Amendments Schedule 1
Note:
See also subsections 26WF(2) and (5), which deal with remedial
action.
(3) Before giving a direction to an entity under subsection (1), the
Commissioner must invite the entity to make a submission to the
Commissioner in relation to the direction within the period
specified in the invitation.
(4) The statement referred to in paragraph (1)(a) must set out:
(a) the identity and contact details of the entity; and
(b) a description of the eligible data breach that the
Commissioner has reasonable grounds to believe has
happened; and
(c) the kind or kinds of information concerned; and
(d) recommendations about the steps that individuals should take
in response to the eligible data breach that the Commissioner
has reasonable grounds to believe has happened.
(5) A direction under subsection (1) may also require the statement
referred to in paragraph (1)(a) to set out specified information that
relates to the eligible data breach that the Commissioner has
reasonable grounds to believe has happened.
(6) In deciding whether to give a direction to an entity under
subsection (1), the Commissioner must have regard to the
following:
(a) any relevant advice given to the Commissioner by:
(i) an enforcement body; or
(ii) the Australian Signals Directorate of the Defence
Department;
(b) any relevant submission that was made by the entity:
(i) in response to an invitation under subsection (3); and
(ii) within the period specified in the invitation;
(c) such other matters (if any) as the Commissioner considers
relevant.
(7) Paragraph (6)(a) does not limit the advice to which the
Commissioner may have regard.
(8) If the Commissioner is aware that there are reasonable grounds to
believe that the access, disclosure or loss that constituted the
eligible data breach of the entity is an eligible data breach of one or
No. 12, 2017
Privacy Amendment (Notifiable Data Breaches) Act 2017
Authorised Version C2017A00012
19