Privacy incidents 104-04070000
This document outlines information to assist staff to identify and manage a privacy incident.
Reporting a potential privacy incident
Step |
Action |
1 |
Potential privacy incident + Read more ... Notify your Team Leader about the potential incident. Work with your Team Leader to identify if the potential privacy incident is serious. This includes where disclosure or unauthorised access of personal information has occurred, that could impact an individual or individuals:
This includes children and those at risk of harm due to family and domestic violence. See Risk identification and management of threats to the safety or welfare of a child The Resources page has a link to the Privacy and Secrecy intranet page, which contains further information about managing privacy incidents. Is the potential privacy incident serious?
Note: if the customer or another party may be at imminent risk of harm due to the incident, Service Officers should consult with their Team Leader/Leadership to identify the delegate that should refer the matter to the Social Work Services Branch. For referrals to that Branch, see Social Work Services
|
2 |
Take all corrective action necessary + Read more ... Complete any corrective action immediately, do not wait for contact from Privacy. Corrective action may include:
If Service Officers are unsure or concerned about what corrective action to take, steps should be taken to consult with line managers. What steps have been taken to correct the privacy incident? Taking corrective action can help minimise the impact of the privacy incident. For example:
Corrective action should not be delayed pending the privacy review. Note: document any corrective action in the Privacy Incident Notification Form. See Resources page for a link to the form. Once corrective action is taken, go to Step 3. |
3 |
Complete and submit the Privacy Incident Notification Form + Read more ... |
4 |
Privacy will assess the incident + Read more ... Privacy will triage and assess the incident by assigning a level of priority. The incident will be:
Once the incident has been finalised, Privacy will send the responsible business a report of their assessment and recommendations where appropriate. |