Back to all postsSecurity

Data Breach Response Plan for a Migration Agency

The notification test has two limbs, and the second one rewards speed: a breach stops being notifiable if remedial action removes the likelihood of serious harm before it lands.

LodgeHQ

Compliance Team

12 September 20267 min read

Most breach plans are written as a notification procedure. That is the wrong emphasis, because of how the test is built.

Under the OAIC's quick reference guide, a data breach is eligible — and therefore notifiable — if it is likely to result in serious harm to one or more individuals and the entity has not been able to prevent that likely risk through remedial action.

Two limbs, and the second one is a door. If remedial action means the breach would not be likely to result in serious harm, it is not an eligible data breach at all. The guidance is explicit that where information is lost, remedial action is adequate if it prevents unauthorised access to, or disclosure of, the personal information. It even allows for partial success: if remedial action removes the likelihood of harm for some individuals in a larger affected group, those individuals do not need to be notified.

Which means the hours immediately after discovery are not preparation for a notification decision. They are the thing that determines whether there is one.

First, know whether the scheme applies to you

The notifiable data breach scheme binds APP entities. If your practice is a small business operator — turnover of $3 million or less, with none of the disqualifying activities — it is generally outside the scheme, as our Privacy Act checklist sets out.

Do not read that as a reason to skip the plan. Three things still reach you:

  • The Code's confidentiality and secure-keeping duties apply regardless of turnover, and the Authority can require the file and an account of what happened.
  • The statutory tort for serious invasions of privacy in Schedule 2 of the Privacy Act has no small business exemption and is actionable without proof of damage.
  • Your clients' own obligations can reach you. A sponsoring employer that is an APP entity, whose employee data you hold, will have its own assessment to run — and will need your facts to run it.

A practice that cannot say what was accessed, by whom and when is in a poor position under all three.

The clock most plans get wrong

The deadline people remember is 30 days. The deadline is real, but it is not the notification deadline.

If you suspect an eligible data breach but are not sure, you must take all reasonable steps to complete the assessment within 30 calendar days after becoming aware of the grounds that caused the suspicion.

If you have reasonable grounds to believe an eligible data breach has occurred, the obligation is to notify affected individuals and provide a statement to the OAIC as soon as practicable. There is no 30-day allowance at that point.

So the 30 days is a ceiling on deciding, not a budget for acting, and it starts at suspicion rather than at confirmation. A practice that spends three weeks working out whether it has a problem has usually also lost the window in which remedial action could have removed the problem.

The first four hours

The plan that matters is short and rehearsed.

  1. Stop the bleeding. Disable the compromised account, revoke the sharing link, recall or expire access, force a password reset, isolate the device. Containment first.
  2. Preserve the evidence. Before you clean up, capture mailbox audit logs, sign-in logs, file access logs and the message that started it. Remediation frequently destroys the record needed to establish scope, and scope is what the assessment turns on.
  3. Establish scope. Whose personal information, what categories, over what period. In a migration practice this is where sensitivity gets decided — a compromised mailbox containing passport scans, police certificates and medical results is a materially different event from one containing appointment confirmations.
  4. Attempt remedial action, deliberately and quickly. Recovery of a lost device before it was accessed, expiry of a link before it was opened, confirmation that a misdirected email was deleted unread. Then record what you did and when, because that record is the evidence supporting a decision not to notify.

Assessing seriousness in a migration context

Serious harm is likely if it is more probable than not, assessed holistically against the likelihood and the consequences. The Act sets out a non-exhaustive list of relevant matters.

Migration files carry harms that a generic assessment template will not surface:

  • Immigration status is inferable from the mere fact of the relationship. Knowing that a named person is a client of a migration practice can itself be harmful.
  • Protection matters can create physical risk. Information reaching the wrong people abroad is a different order of consequence from financial loss.
  • Relationship evidence in partner matters is intimate by construction.
  • Sponsor exposure. A breach involving employer-sponsored files affects the employer's workforce as well as your clients.
  • The information does not expire. A passport number, a birth certificate and a medical history remain useful to an attacker for years.

Notification, and who does it

Where notification is required, you must notify the individuals at risk of serious harm and give a statement to the OAIC as soon as practicable.

Only one entity has to notify

One practical point matters for sponsored work: where an eligible data breach affects multiple entities, only one of them needs to notify. It is for the entities to decide who, and the guidance says the entity with the most direct relationship with the individuals at risk should generally do it. Settle that with a sponsoring employer during the incident, in writing, rather than assuming.

Notification to clients is also a communication problem. People in the middle of a visa application are already anxious, frequently reading in a second language, and are being told that a practice they trusted has lost control of their most sensitive documents. Say plainly what happened, what information was involved, what you have done, and what specifically they should do. Arrange interpreters where they are needed — the duty to arrange access to an interpreter does not lapse because the subject is uncomfortable.

What to write down before anything happens

  • Who decides. One named person with authority to disable accounts and engage help at 9pm.
  • Who to call. Your IT provider, insurer, and a lawyer, with numbers, on paper.
  • Where the logs are and how long they are retained — a 30-day log retention makes a 30-day assessment impossible.
  • A client contact list you can reach if the system holding it is the system that is compromised.
  • A holding statement for clients, and one for sponsors.
  • The assessment record template, so the reasoning is captured as it happens rather than reconstructed.

The tabletop test

Run this for an hour, once: a staff mailbox has been accessed by someone else for an unknown period.

  • Who is told first, and how quickly?
  • Can you get the mailbox audit log, and how far back does it go?
  • Can you list the client matters that mailbox touched?
  • Can you tell which attachments left the practice?
  • Could you reach every affected client if that mailbox were unavailable?
  • At what point would you have concluded you had reasonable grounds to believe?

Most practices discover the same thing: the constraint is not the plan, it is that nobody can establish scope, because the client information lived in a mailbox rather than in a system.

Where a system helps

A breach response is an evidence exercise conducted under time pressure. Everything that makes it survivable is decided long before, by where the information lives.

Documents held against matters rather than in mailboxes narrow the blast radius of a compromised account and make scope answerable. Access logs make "what did they see" a query rather than a guess. Individual logins make attribution possible. And a client list that is not trapped inside the compromised system is what lets you notify at all.

LodgeHQ keeps client documents and correspondence in one place with per-user access, which is the difference between assessing a breach and speculating about one. Our comparison of CRM options for migration agents covers the wider choice; start a free trial to see the audit trail.

Verify before you rely on it

Breach obligations depend on whether the scheme applies to your entity and on the specific facts, and both change. Read the OAIC's guidance and the Act directly, and get legal advice at the point of suspicion rather than after the assessment.

This is general information for migration practices, not legal advice. If you believe a breach has occurred, treat the 30-day assessment clock as already running and get advice today.

Tags:Data BreachPrivacy ActIncident ResponseRisk ManagementClient Data