What happens if your information is ever compromised
As a health service provider covered by the Privacy Act 1988 (Cth), we are subject to the Notifiable Data Breaches scheme in Part IIIC of the Act. A data breach occurs when personal information we hold is lost, or accessed or disclosed without authorisation.
As soon as we become aware of a suspected breach, we act immediately to contain it and prevent any further compromise, and we begin a written record of the incident and every action taken.
Where we have reasonable grounds to suspect an eligible data breach, we conduct a reasonable and expeditious assessment of whether it is likely to result in serious harm. We take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of the grounds for suspicion, and we aim to complete it far sooner. Throughout, we take any remedial action available to reduce the risk of harm.
If we have reasonable grounds to believe an eligible data breach has occurred, and remedial action has not prevented the likely risk of serious harm, we notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable. Our notification will state who we are and how to contact us, describe the breach, identify the kinds of information involved, and recommend the steps you should take in response.
Where an athlete is affected, we notify the athlete directly. We will also notify the relevant organisation of the fact and nature of the incident, without disclosing individual athletes' health information.
We fully investigate the cause, and change our systems, processes and training to prevent a recurrence. Where appropriate we also notify the Australian Cyber Security Centre and law enforcement.
If you believe your information has been involved in a breach and you have not heard from us, contact [email protected]. You may also complain directly to the Office of the Australian Information Commissioner at oaic.gov.au.