Amendments Schedule 1 (c) the access or disclosure covered by paragraph (a), or the loss covered by paragraph (b), is an eligible data breach of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; and (d) an individual covered by subparagraph (a)(ii) or (b)(ii) is at risk from the eligible data breach. (3) Subsection (2) has effect subject to section 26WF. 26WF Exception—remedial action Access to, or disclosure of, information (1) If: (a) an access to, or disclosure of, information is covered by paragraph 26WE(2)(a); and (b) the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the access or disclosure; and (c) the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so before the access or disclosure results in serious harm to any of the individuals to whom the information relates; and (d) as a result of the action, a reasonable person would conclude that the access or disclosure would not be likely to result in serious harm to any of those individuals; the access or disclosure is not, and is taken never to have been: (e) an eligible data breach of the APP entity, credit reporting body, credit provider or file number recipient, as the case may be; or (f) an eligible data breach of any other entity. (2) If: (a) an access to, or disclosure of, information is covered by paragraph 26WE(2)(a); and (b) the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, takes action in relation to the access or disclosure; and (c) the APP entity, credit reporting body, credit provider or file number recipient, as the case may be, does so before the No. 12, 2017 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 7

Select target paragraph3