Is this a notifiable breach? Making the serious harm call
The Privacy Act asks one judgement of you after an incident: whether the breach is likely to cause serious harm. It is far easier to make well if you worked out how you would make it before anything happened.
Most of what happens after a security incident is technical. One part is not. Under the Privacy Act 2020, if a privacy breach has caused or is likely to cause serious harm to someone, you must tell the Privacy Commissioner and the people affected, as soon as practicable.
That sentence contains a judgement, and the judgement is yours. Nobody hands you the answer.
What counts as a privacy breach
Wider than most people expect. It is not only an attacker taking data. It includes unauthorised access to personal information, disclosing it to the wrong person, losing it, and being unable to get at it when you need to.
The misaddressed email counts. So does the spreadsheet of staff details shared to a link anyone could open, the laptop left in a taxi, and the ransomware that encrypted client records even if nothing was copied out.
Most of those will turn out not to be notifiable. All of them are breaches, and all of them deserve the question being asked properly rather than waved through.
The factors that decide it
The Act sets out what to weigh when assessing whether serious harm is likely. In practice they come down to a handful of questions.
How sensitive is the information? Health details, financial information, identity documents and anything that could be used to impersonate someone sit at the top. A list of work email addresses sits much lower.
Who has it now? A trusted recipient who replied to say they deleted it is a very different position from an unknown party on the internet.
Was it protected? Properly encrypted data, with the key still safe, changes the picture considerably.
What have you already done to reduce the harm? Recalling the message, revoking the link, resetting credentials, getting written confirmation of deletion. These count, which is one reason to act before you finish deliberating.
What could realistically happen to the people involved? Financial loss, identity theft, humiliation, loss of a job or a relationship, physical risk. The test is about harm to them, not embarrassment to you.
Where businesses get it wrong
Deciding too late. “As soon as practicable” is read as days, not the weeks it takes to finish a forensic investigation. You are allowed to notify on what you know and update later, and that is usually the right approach.
Letting the wrong person decide. The technician who found the problem is the person best placed to describe it and often the person worst placed to judge harm to a client’s customers. It is a business decision with legal weight.
Deciding on reputation. Not notifying because it would be awkward is the one reasoning that reliably makes a situation worse, and failing to notify a notifiable breach is itself an offence.
Not writing it down. Whatever you conclude, record what you knew, what you weighed and why you decided as you did. If the call is ever questioned, that record is the difference between a defensible judgement and a guess.
What to settle before you need it
Three things, and an hour is enough for all of them.
Who makes the call. Named, with a deputy for when they are on leave.
What they need in front of them. What information was involved, whose it was, who has it, whether it was encrypted, and what has been done so far. Put that list in the incident plan so the technical people know what to gather.
Where the record lives. A simple register of breaches, including the ones you decided were not notifiable, is good practice and makes a pattern visible before it becomes a problem.
Where we sit
When we run an incident for a client, we gather the facts the harm assessment needs and we will say plainly what we think they point to. The decision to notify stays with the client, because it is theirs in law, and we would rather help them make it well than make it for them.