Compliance · CEO + 2IC
Risk, safeguarding and incident · Privacy Act 1988 Pt IIIC (Notifiable Data Breaches) / B029

Privacy Incident and Data Breach Register (NDB)

Specified by policy. This register does not exist yet.

Confidential Board quarterly not in B043 v1.0

Specification

B043 Governance Registers Suite v1.0 §5
Source policy
Privacy Act 1988 Pt IIIC (Notifiable Data Breaches) / B029
Owner
2IC
Cadence
On discovery + quarterly Board summary
Classification
Confidential
Held
Not started
Board reporting
Quarterly summary (B043 §9)
Last reviewed
Next review due
NoteDAS holds NDIS plans, health information and case files for a 7-person org, so a data breach is a live risk with a statutory clock: contain, assess likely serious harm within 30 days, notify the OAIC and affected individuals if the threshold is met. B043 v1.0 §5 catalogues no such register and no file exists — this row is the gap, stated rather than omitted. It was briefly scaffolded inside the advocacy CRM (28 Aug 2026, das-path-planner#17) and removed: a whole-of-organisation privacy obligation cannot live behind an advocacy login where only PII-cleared caseworkers can see it and the audit catalogue does not know it exists.

What is missing

Privacy Act 1988 Pt IIIC (Notifiable Data Breaches) / B029 requires DAS to maintain this register at a quarterly cadence, owned by 2IC. No artefact was found in the audit pack, in DAS CURRENT FILES, or anywhere else searched. It is additionally owed to the Board as a quarterly summary under B043 §9.

Starting it means one of two things: create the register, or amend B043 to remove the requirement. Both are decisions; leaving it in this state is the only option that is not.

Currency reviews

B043 §10 — who confirmed it current, when
Reviewed By Outcome Sampled Findings
Loading…