This Data breach policy has been developed in accordance with the Information Privacy Act 2009 including the Mandatory Notification of Data Breach (MNDB) scheme, which requires Queensland public sector agencies to prepare and maintain a data breach policy outlining how they identify, assess and respond to data breaches, including suspected Eligible Data Breaches.
Under the Information Privacy Act 2009, a data breach involves unauthorised access to, or disclosure of, information or the loss of information where unauthorised access or disclosure is likely to occur.
The purpose of this policy is to establish the Queensland Family and Child Commission’s (the Commission) approach to managing data breaches to minimise harm to individuals, ensure compliance with legislative obligations, and support timely and appropriate notification to affected individuals and the Office of the Information Commissioner (OIC).
Roles and responsibilities, breach identification and classification and governance requirements with detailed procedures set out in the Commission’s Data breach response plan.
This policy applies to all actual, suspected or potential data breaches involving information held by, or on behalf of, the Commission, including information held by contracted service providers and third parties. Where a breach does not involve personal information, it will be managed by Governance and Risk and IT Services, in conjunction with the relevant business area, under applicable information security, risk management and breach response processes.
This policy establishes the Commission’s framework for managing data breaches, including governance, roles and responsibilities, breach identification and classification, assessment, notification, recordkeeping and continuous improvement.