Case Study: Data Breach Response: Application for notification exemption
The background
We assisted an Australian organisation with its response to a data breach involving the inadvertent disclosure of sensitive personal information.
How we assisted
Standing up our response team on a Saturday morning, we provided comprehensive and urgent advice to our client’s data breach response team, as well as its Executive and Board, regarding its response to the data breach, its assessment of its notification obligations and engagement with the regulator.
This included preparing a novel application to the regulator seeking an exemption from certain notification requirements, given the unique circumstances of the breach. Our approach provided our client a clear, structured, and defensible framework for managing the breach. This ensured the organisation could effectively mitigate harm to impacted individuals while safeguarding its reputation and maintaining its capacity to provide essential services.