Data Breach Policy
Objective
Mid-Western Regional Council (Council) has created this data breach policy (Policy) to inform the public of Council’s procedure for identifying, responding to, and reporting data breaches of council held information.
The objective of this Policy is to set out Council’s approach to identifying and managing a Data Breach, including:
- providing examples of situations considered to constitute a data breach;
- the five key steps involved in responding to a data breach;
- the considerations around notifying persons whose privacy may be affected by a data breach on a mandatory basis where required, or on a voluntary basis where warranted, to ensure that Council responds appropriately to a data breach; and
- assists the Council in avoiding or reducing possible harm to both the affected individuals and the Council.