Understanding privacy breachesNew Article Page

There are many stories of hackers breaching computer security and gaining access to personal information.

We may have been the victim of an online hacker ourselves.
This is called a privacy breach.

A privacy breach can also be accidental – an email sent to the wrong person, a computer or paper file left open or accessible, or a printed email list seen by someone who is not supposed to.

Some of the ideas and methodology in this article are from the Office of the Privacy Commissioneropen_in_new (OPC).

What is a privacy breach?

A privacy breach occurs whenever personal information is lost, stolen, or accessed without permission.

Sometimes, when there is a privacy breach, an organisation may be prevented from accessing the information it holds.

Here are some common examples for boards and their schools:

  • Theft of documents or electronic devices
  • Computer hacks (including by students)
  • Ransomware attacks
  • Employee browsing
  • Emails sent to the wrong person
  • Workplace gossip.

Every organisation, including schools and their boards, holds personal information.

In other words, information about identifiable people.

It is almost inevitable that most organisations (including schools) will face a privacy breach at one time or another.

When do you need to notify the Office of the Privacy Commissioner of a privacy breach?

Sections 112–122 of the Privacy Act 2020open_in_new set out the rules around privacy breach notifications.

If a breach has caused (or may cause) someone serious harm, your board needs to notify the Privacy Commissioner.

Your board may also have to notify the affected person.

There is no precise definition of "serious harm" in the Privacy Act, so each case will be assessed individually.

The factors to be considered are:

  • The nature of the information and how sensitive it is.
  • What the organisation has done to reduce the risk of harm following the breach.
  • The actual consequences of the breach (for example, who has been able to access the information).
  • The nature of the harm that has resulted from the breach and anything else that may be relevant.

Your board is the agency responsible for privacy and can be fined if it (or its school) decides not to notify a serious privacy breach.

The approach to assessing the level of harm caused by a privacy breach means that the school's policies and procedures (and whether they are followed) will be an essential consideration if a breach occurs.

Staff and board members should follow clear privacy policies and procedures, including what to do if there is a breach.

Your board's responsibility is to ensure that these are in place and followed.

How do you create a positive privacy culture?

You can create a positive privacy culture by ensuring:

  • Your board appoints a privacy officer, or the principal is delegated to appoint one, and
  • Your board and school staff know what a privacy breach involves and that, should one occur, the staff or board member will be supported through the process.

Put privacy on your board's agenda and consider some all-board privacy training either using Office of the Privacy Commissioner online resourcesopen_in_new or enquire with them about training opportunities in your area.

Make privacy one of your board's policies.

Your board's privacy policy should include:

  • Expectations of board members around privacy, including what to do if there is a privacy breach, and
  • Expectations of the principal as delegated employer to ensure staff understand their privacy responsibilities, including what processes to follow if there is a privacy breach.

Your board may already have a policy that you can look at, or you can contact us to help you develop one.

What is the four-step C-A-N-P process?

We encourage boards (and their schools) to use the OPC's four-step C-A-N-P process.

(C)ontain - find out what has happened and take steps to stop the breach from getting worse.

(A)ssess - assess how serious the breach is using the online tool NotifyUsopen_in_new (an anonymous process).

(N)otify - if you think it is a serious privacy breach, tell the OPC as soon as possible using NotifyUsopen_in_new (you may also need to tell the people affected).

(P)revent - once the privacy breach has been resolved and the crisis is over, take steps to prevent future breaches.

Questions your board could ask

  • Do we know what a privacy breach is?
  • When do we need to notify the Privacy Commissioner of a breach?
  • What steps are we taking to create a positive privacy culture?
  • Do we use the four-step (C)ontain, (A)ssess, (N)otify, (P)revent process to manage any privacy breaches?

Templates, resources, and references

Click on the link(s) below to access the templates, resources, and references related to this topic.

These may download or open in a separate browser depending on your device.

Office of the Privacy Commissioner 
Privacy Act 2020