NSWIn ForceAct
Privacy and Personal Information Protection Act 1998
59OInformation to be notified to certain individuals
Start here
Get a plain-English read of 59O
Turn the raw legal text into a practical explanation grounded in Privacy and Personal Information Protection Act 1998.
#### 59O Information to be notified to certain individuals
59O Information to be notified to certain individuals
> A notification given under section 59N(1) must, if it is reasonably practicable for the information to be provided, include the following information in relation to each eligible data breach—
>
> > (a) the date the breach occurred,
>
> > (b) a description of the breach,
>
> > (c) how the breach occurred,
>
> > (d) the type of breach that occurred,
> >
> > Examples of a type of eligible data breach—
> >
> > > 1 unauthorised disclosure
> >
> > > 2 unauthorised access
> >
> > > 3 loss of information
>
> > (e) the personal information that was the subject of the breach,
>
> > (f) the amount of time the personal information was disclosed for,
>
> > (g) actions that have been taken or are planned to ensure the personal information is secure, or to control or mitigate the harm done to the individual,
>
> > (h) recommendations about the steps the individual should take in response to the eligible data breach,
>
> > (i) information about—
> >
> > > (i) the making of privacy related complaints under Part 4, Division 3, and
> >
> > > (ii) internal reviews of certain conduct of public sector agencies under Part 5,
>
> > (j) the name of the public sector agency the subject of the breach,
>
> > (k) if more than 1 public sector agency was the subject of the breach—the name of each other agency,
>
> > (l) contact details for—
> >
> > > (i) the agency the subject of the breach, or
> >
> > > (ii) a person nominated by the agency for the individual to contact about the breach.
>
> **s 59O:** Ins 2022 No 74, Sch 1\[11\].