Schedule 1 Amendments (b) • the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates. An entity must give a notification if: (a) it has reasonable grounds to believe that an eligible data breach has happened; or (b) it is directed to do so by the Commissioner. 26WB Entity For the purposes of this Part, entity includes a person who is a file number recipient. 26WC Deemed holding of information Overseas recipients (1) If: (a) an APP entity has disclosed personal information about one or more individuals to an overseas recipient; and (b) Australian Privacy Principle 8.1 applied to the disclosure of the personal information; and (c) the overseas recipient holds the personal information; this Part has effect as if: (d) the personal information were held by the APP entity; and (e) the APP entity were required under section 15 not to do an act, or engage in a practice, that breaches Australian Privacy Principle 11.1 in relation to the personal information. Bodies or persons with no Australian link (2) If: (a) either: (i) a credit provider has disclosed, under paragraph 21G(3)(b) or (c), credit eligibility information about one or more individuals to a related body corporate, or person, that does not have an Australian link; or 4 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 No. 12, 2017

Select target paragraph3