Welcome to the
Mandatory Notification of Data Breach (MNDB) scheme assessment tool, designed to assist Queensland government agencies determine whether a data breach is an eligible data breach as defined in section 47 of the
Information Privacy Act 2009 (IP Act).
When a data breach occurs and an agency reasonably suspects the breach to be eligible under the MNDB scheme, it must conduct an assessment to determine whether there are reasonable grounds to believe this to be the case. The assessment must be conducted promptly and completed within 30 days unless an extension of time is reasonably required.
This tool provides agencies with a structure to conduct the assessment with associated advice for consideration at each step of the process.
However, the tool can also be used to support the initial consideration of a data breach to help inform an agency's next steps.
The result or recommendation provided by the tool is only a guide, and nothing in this tool comprises legal advice.
Each breach requires consideration of its specific circumstances, and while this tool assists agencies, a comprehensive and objective assessment is required before decisions are made.
The Office of the Information Commissioner (OIC) recommends that this tool, and other OIC MNDB Guidelines or Resources are used in combination with an agency's own policies and procedures. Assessment decisions should consider an agency's own systems, including its decision-making delegations, the type of personal information held, its IT systems and data breach security posture, its functions, and the environment in which it operates.
If a crime is happening now, your own or another life or property is in immediate danger, or an event is time critical, call Triple Zero (000). If you need to contact the police and it is non-urgent, call Queensland Police Service - Policelink on 131 444 or (07) 3055 6206.