Privacy Act · GDPR

Data Breach Response Playbook: NDB Scheme + GDPR, 7 Documents.

From the first hour of detection to post-incident board reporting. NDB scheme and GDPR Article 33 coverage in a single playbook. Triage checklist, investigation workbook, OAIC notification templates, response log, and post-breach review.

Privacy Act 1988 (NDB scheme)GDPR Articles 33-34OAIC NDB GuideAPRA CPS 234 (incident notification)
Buy Now: $699 AUD →

7 documents: ready to implement.

AIR-DBR-GDE-001

Data Breach Response Guide

NDB scheme threshold, serious harm assessment, GDPR Article 33-34, response phases, decision points

AIR-DBR-TRG-001

Detection and Triage Checklist

First 24 hours: containment, severity classification, initial notification decision

AIR-DBR-INV-001

Investigation Workbook

Root cause, scope, personal information audit, serious harm assessment framework

AIR-DBR-NOT-001

Notification Templates

OAIC NDB, individual letter, public notice, vendor notification, GDPR Article 33: 5 templates

AIR-DBR-LOG-001

Breach Response Log

Timestamped action record, 17-milestone tracker, decisions log: the regulatory evidence trail

AIR-DBR-RVW-001

Post-Breach Review Template

Root cause analysis, response effectiveness, remediation plan, board reporting summary

AIR-DBR-REG-001

Breach Register

Organisation-wide incident log, GDPR Article 33(5) documentation, trend analysis

What makes this different.

Dual NDB + GDPR framework

NDB gives you 30 days to assess. GDPR gives you 72 hours to notify. This playbook manages both simultaneously.

Serious harm assessment framework

The investigation workbook provides a structured legal determination framework: the most consequential decision in any breach response.

Five notification templates

OAIC NDB notification, individual letter, public notice, vendor notification, and GDPR Article 33 supervisory authority notification: ready to adapt.

The response log is the evidence trail

Regulators assessing your response will examine the timestamped log. The response log is designed for real-time entry from the first hour.

Legal privilege guidance

The investigation workbook includes guidance on legal professional privilege: protecting your investigation documents from regulatory disclosure.

Who this is for Privacy Officers, CISOs, legal and compliance teams, incident responders, and any organisation holding personal information under the Privacy Act 1988.

FAQ

Yes. The playbook explicitly manages both NDB and GDPR notification timelines. The GDPR 72-hour clock is flagged throughout the triage and investigation documents.
The NDB scheme requires notification when a breach is likely to result in serious harm to affected individuals. The investigation workbook provides a structured assessment framework for making this determination: but note it is a legal judgement that should involve legal counsel.
Yes. The triage checklist is designed to be used by whoever detects the breach: not just a dedicated security team.

Ready to implement?

Download Data Breach Response Playbook today: $699 AUD, instant delivery.

Buy Now: $699 AUD → Browse all products