Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryData Breach Response and Cross-Border Disclosure Procedure
Contents & downloads
Nomenclature
| Term | Definition |
|---|---|
| APP | Australian Privacy Principle |
| DISO | Defence Industry Security Office |
| NDB | Notifiable Data Breach |
| OAIC | Office of the Australian Information Commissioner |
| PI | Personal Information |
Purpose
This procedure sets out how Westlink Logistics responds to a data breach affecting personal information, and how it assesses and controls the disclosure of personal information to overseas recipients. It ensures that Westlink meets its obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) and under Australian Privacy Principle 8 (cross-border disclosure). It operationalises the commitments made in GOV-POL-015 Privacy Policy.
Scope
This procedure applies to all personal information held by Westlink, and to every Westlink director, officer, worker, contractor and subcontractor who handles personal information or who becomes aware of a suspected data breach. It applies to a data breach however it arises, including:
-
a cyber security incident (for example unauthorised access to a system, ransomware, or compromised credentials);
-
loss or theft of a device or paper record containing personal information;
-
a misdirected email, message or document, or an inadvertent disclosure; and
-
an unauthorised disclosure by a worker, contractor or other person.
Interface with cyber incident response. Where a data breach originates from a cyber security incident, the technical detection, containment, eradication and recovery are conducted under TEC-PRO-001 Cyber Incident Response Procedure. This procedure governs the privacy dimension of the same event: the eligible-data-breach assessment, the statement to the OAIC and the notification of affected individuals. A breach that does not arise from a cyber incident is handled wholly under this procedure.
Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Privacy Officer (QHSE Manager) | Owns this procedure and the eligible-data-breach assessment. Receives reports of suspected breaches, conducts the s.26WH assessment within 30 days, prepares the s.26WK statement, and notifies the OAIC and affected individuals as soon as practicable. Maintains the data breach register, the Notifiable Data Breach record and the overseas-recipient register, and conducts APP 8 assessments. |
| Security Officer (QHSE Manager) | For a cyber-origin breach, leads technical containment and recovery under TEC-PRO-001 and provides the Privacy Officer with the facts needed for the eligible-data-breach assessment. (The Security Officer and Privacy Officer are currently the same individual; the roles are described separately for clarity.) |
| Chief Executive Officer | Approves notification to the OAIC and affected individuals and authorises any public communication. Approves decisions reserved to executive authority and ensures the breach response is adequately resourced. |
| Managers and worker leads | Ensure that personal information is disclosed to an overseas recipient only after the APP 8 process in Section 10 has been followed, and that suspected breaches are escalated to the Privacy Officer without delay. |
| Workers, contractors and visitors | Report any suspected or actual data breach to the Privacy Officer (or to a manager, who escalates it) as soon as they become aware of it. |
| Legal adviser (external, as engaged) | Advises on notification thresholds, on whether an APP 8.2 exception applies, and on regulator and contractual obligations where required. |
Definitions
| Term | Definition |
|---|---|
| Personal information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in s.6 of the Privacy Act 1988 (Cth). |
| Data breach | Unauthorised access to, or unauthorised disclosure of, personal information, or the loss of personal information in circumstances where unauthorised access or disclosure is likely. |
| Eligible data breach | A data breach that meets the threshold for notification under Part IIIC of the Privacy Act 1988 (Cth): a data breach that a reasonable person would conclude is likely to result in serious harm to any of the individuals to whom the information relates, and where remedial action has not prevented that likelihood (s.26WE). |
| Serious harm | Harm to an individual that may be physical, psychological, emotional, financial or reputational. Whether serious harm is likely is assessed against the matters set out in s.26WG of the Privacy Act 1988 (Cth). |
| NDB scheme | The Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), requiring notification of eligible data breaches to affected individuals and to the OAIC. |
| OAIC | The Office of the Australian Information Commissioner — the regulator administering the Privacy Act 1988 (Cth) and the NDB scheme. |
| Overseas recipient | A person or entity outside Australia, other than Westlink or the individual concerned, to whom Westlink discloses personal information. |
Reporting and Containment
Any worker who becomes aware of a suspected or actual data breach must report it to the Privacy Officer as soon as they become aware of it, regardless of how the breach arose or whether it appears minor. Where the breach arises from a cyber security incident, the worker also reports it through the channels in TEC-PRO-001.
On becoming aware of a suspected breach, Westlink first takes immediate steps to contain it and to limit any further unauthorised access, disclosure or loss — for example by recovering or remotely wiping a device, disabling an account, recalling a misdirected message, or isolating an affected system under TEC-PRO-001. The Privacy Officer records the breach in the data breach register, including what is known, the personal information involved, and the containment action taken.
Eligible Data Breach Assessment
Where Westlink suspects that there may have been an eligible data breach but does not yet have reasonable grounds to believe one has occurred, the Privacy Officer carries out a reasonable and expeditious assessment of whether the breach is an eligible data breach, and takes all reasonable steps to complete that assessment within 30 days of becoming aware of the suspected breach (s.26WH).
The assessment determines:
-
whether there has been unauthorised access to, unauthorised disclosure of, or loss of personal information held by Westlink;
-
whether a reasonable person would conclude that the breach is likely to result in serious harm to any of the individuals to whom the information relates, having regard to the matters in s.26WG (including the kind and sensitivity of the information, whether it is protected by security measures, and the persons who have or could obtain it); and
-
whether remedial action taken by Westlink means the breach is no longer likely to result in serious harm, in which case it is not an eligible data breach (the remedial-action exception, s.26WF). The remedial action and the basis for the conclusion are recorded.
The outcome of the assessment, with its rationale, is recorded in the Notifiable Data Breach record and retained, whether or not the breach is found to be eligible.
Notification
Where Westlink has reasonable grounds to believe that an eligible data breach has occurred, the Privacy Officer, with the approval of the CEO, as soon as practicable:
-
prepares a statement that complies with s.26WK and gives a copy of the statement to the Commissioner (the OAIC); and
-
notifies the affected individuals in accordance with s.26WL — by notifying each individual at risk from the breach, or each individual to whom the information relates, or, where neither is practicable, by publishing the statement and taking reasonable steps to publicise it.
Where the breach involves Defence personnel or information handled under Westlink’s DISP membership, the Privacy Officer also ensures the Defence Industry Security Office is notified under the external notification pathways in TEC-PRO-001, in addition to the OAIC.
NDB Statement Content
The statement prepared under s.26WK and given to the OAIC must set out:
-
the identity and contact details of Westlink;
-
a description of the eligible data breach;
-
the kind or kinds of personal information concerned in the breach; and
-
the recommendations about the steps that affected individuals should take in response to the breach.
The same content forms the basis of the notification given to affected individuals. Westlink retains a copy of every statement given to the OAIC and of the notifications made to individuals.
Data Breach Response Plan
Westlink maintains a data breach response capability so that a breach is handled quickly and consistently. The response is led by the Privacy Officer and draws on a response team comprising the Security Officer and managed service provider (for cyber-origin breaches), the CEO, an external legal adviser where required, and the person responsible for communications.
The response follows four phases:
-
contain — take immediate steps to limit the breach and prevent further access, disclosure or loss;
-
assess — conduct the eligible-data-breach assessment under Section 6;
-
notify — where the breach is an eligible data breach, notify the OAIC and affected individuals under Sections 7 and 8; and
-
review — conduct a post-breach review of the cause and of the controls, and implement corrective actions.
The plan is integrated with TEC-PRO-001 Cyber Incident Response Procedure, QHSE-PRO-001 Hazard and Incident Reporting and Investigation Procedure, and Westlink’s business-continuity arrangements. The plan is tested at least annually, ordinarily through a desktop exercise, and is updated to reflect the lessons from any test or actual breach.
Cross-Border Disclosure of Personal Information
Before disclosing personal information about an individual to an overseas recipient, Westlink takes such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to the information (APP 8.1). This applies to the overseas recipients that routinely arise in Westlink’s international freight and chartering work — for example foreign shipping agents, customs brokers, port agents, charter-party counterparties and overseas service providers — where Westlink discloses personal information such as contact details, identity or passport details for seafarer logistics, or data required for customs clearance.
Reasonable steps before disclosure. The responsible manager, with the Privacy Officer, conducts and records due diligence on the overseas recipient and ensures that the contract or arrangement with the recipient requires it to handle the personal information consistently with the Australian Privacy Principles. The assessment and the basis for the disclosure are recorded before the personal information is disclosed.
Overseas-recipient register. Westlink maintains a register of the overseas recipients to which it discloses personal information, recording for each recipient the country, the kind of personal information disclosed, the basis for the disclosure, and the outcome of the per-country assessment.
Exceptions (APP 8.2). The obligation in APP 8.1 does not apply where Westlink reasonably believes that the overseas recipient is subject to a law, or a binding scheme, that has the effect of protecting the information in a way that, overall, is at least substantially similar to the Australian Privacy Principles and that the individual can access to enforce (for example the General Data Protection Regulation for recipients in the European Union, or the Personal Data Protection Act for recipients in Singapore); or where the individual consents to the disclosure after being expressly informed that APP 8.1 will not apply; or where another exception in APP 8.2 applies. Where Westlink relies on an exception, the basis for it is assessed and recorded before the disclosure.
Accountability (s.16C). Where Westlink discloses personal information to an overseas recipient and APP 8.1 applies (and no exception applies), an act done, or a practice engaged in, by the overseas recipient that would breach the Australian Privacy Principles is taken, under s.16C of the Privacy Act 1988 (Cth), to have been done or engaged in by Westlink and to be a breach of the Australian Privacy Principles by Westlink.
Records and Documented Information
Documented information made under this procedure is retained as evidence that Westlink has met its obligations under the Privacy Act 1988 (Cth) and is managed in accordance with GOV-SCH-001 (Document Retention Schedule). The records expected under this procedure are listed in the Records section.
Applicable Standards and Legislation
This procedure gives effect to the following legislative requirements:
-
Privacy Act 1988 (Cth), Schedule 1 — Australian Privacy Principle 8 (cross-border disclosure of personal information) and s.16C (acts and practices of overseas recipients of personal information)
-
Privacy Act 1988 (Cth), Part IIIC — Notification of eligible data breaches: s.26WE (eligible data breach), s.26WF (remedial-action exception), s.26WG (serious harm — relevant matters), s.26WH (assessment of suspected eligible data breach), s.26WK (statement about eligible data breach), s.26WL (entity must notify eligible data breach)
Compliance coverage — cited by 5 requirements across 1 framework
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(5)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP8-01 | APP 8.1 | Full | §Cross-Border Disclosure of Personal InformationGOV-PRO-006 §Cross-Border Disclosure establishes the APP 8.1 reasonable-steps process (per-recipient due diligence and APP-equivalent contractual clauses), the overseas-recipient register, and s.16C accountability. | |
| PRV-APP8-02 | APP 8.2 | Full | §Cross-Border Disclosure of Personal InformationGOV-PRO-006 §Cross-Border Disclosure (Exceptions) requires assessing and recording whether an APP 8.2 exception applies (substantially similar law/binding scheme, informed consent, or another exception) before relying on it, via the overseas-recipient register's per-country assessment. | |
| PRV-NDB-01 | s.26WE — eligible data breach | Full | §Eligible Data Breach AssessmentGOV-PRO-006 §Eligible Data Breach Assessment establishes the dedicated all-cause assessment distinct from QHSE-PRO-001, with a PI/serious-harm/remediation triage and the 30-day s.26WH assessment timeline. | |
| PRV-NDB-02 | s.26WH, s.26WK, s.26WL — assessment, statement and notification | Full | §Notification / NDB Statement ContentGOV-PRO-006 §Notification and §NDB Statement Content set out the s.26WK statement and its required content, the s.26WL notification of affected individuals, the copy given to the OAIC, and the 30-day assessment workflow. | |
| PRV-NDB-03 | s.26WK(3), OAIC guidance — data breach response plan | Full | §Data Breach Response PlanGOV-PRO-006 §Data Breach Response Plan sets out the response team (Privacy Officer, Security Officer/MSP, CEO, Legal, Communications), the contain/assess/notify/review phases, integration with TEC-PRO-001 and QHSE-PRO-001, and at-least-annual testing. |
Declared compliance references (5)
PRV-NDB-01PRV-NDB-02PRV-NDB-03PRV-APP8-01PRV-APP8-02
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 05/06/2026 | GOV-PRO-006 | Data Breach Response and Cross-Border Disclosure Procedure | QHSE (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | New document — Data Breach Response and Cross-Border Disclosure Procedure operationalising GOV-POL-015 Privacy Policy. Establishes the all-cause data breach response (reporting and containment, the s.26WH eligible-data-breach assessment, the s.26WK statement and s.26WL notification of the OAIC and affected individuals, the NDB statement content, and the data breach response plan) and the APP 8 cross-border disclosure controls (reasonable steps, the overseas-recipient register, the APP 8.2 exceptions and s.16C accountability) under the Privacy Act 1988 (Cth). |