Amendments Schedule 1 Division 3—Notification of eligible data breaches Subdivision A—Suspected eligible data breaches 26WH Assessment of suspected eligible data breach Scope (1) This section applies if: (a) an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach of the entity; and (b) the entity is not aware that there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity. Assessment (2) The entity must: (a) carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity; and (b) take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware as mentioned in paragraph (1)(a). Note: Section 26WK applies if an entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity. 26WJ Exception—eligible data breaches of other entities If: (a) an entity complies with section 26WH in relation to an eligible data breach of the entity; and (b) the access, disclosure or loss that constituted the eligible data breach of the entity is an eligible data breach of one or more other entities; that section does not apply in relation to those eligible data breaches of those other entities. No. 12, 2017 Privacy Amendment (Notifiable Data Breaches) Act 2017 Authorised Version C2017A00012 11

Select target paragraph3