Notifiable Data Breaches
Merion's obligations and process under the Notifiable Data Breaches scheme — and what happens if a breach occurs.
The NDB scheme
The Notifiable Data Breaches (NDB) scheme is established under Part IIIC of the Privacy Act 1988 (Cth). It requires APP entities — entities regulated by the Australian Privacy Principles — to notify both affected individuals and the Office of the Australian Information Commissioner (OAIC) when an eligible data breach occurs. Merion Pty Limited (ACN 684 211 390) is an APP entity and is therefore subject to the NDB scheme.
What is an eligible data breach
An eligible data breach occurs when all three of the following conditions are met:
- There is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by Merion;
- the breach is likely to result in serious harm to one or more of the individuals whose information is involved; and
- Merion cannot prevent the likely risk of serious harm through remedial action taken after becoming aware of the breach.
Not every security incident is an eligible data breach. Where Merion identifies a potential incident, it assesses whether these three conditions are satisfied before determining whether NDB notifications are required.
What Merion does when a breach occurs
1. Contain
The immediate priority is to stop the breach from continuing or expanding. This may involve isolating the affected system, revoking compromised credentials, or disabling an exposed endpoint. Merion's incident response procedures are designed to enable rapid containment.
2. Assess
Merion assesses the nature and scope of the breach: what personal information was affected, how many individuals are involved, how the breach occurred, and whether serious harm is likely. The assessment informs both the notification obligations and the remediation plan.
3. Notify
If an eligible data breach is confirmed, Merion notifies the OAIC as soon as practicable and within 30 days of becoming aware that a breach has occurred (or, where an assessment was required, within 30 days of the decision to commence the assessment). Affected individuals are notified as soon as practicable after the OAIC is notified.
4. Review
Following containment and notification, Merion conducts a post-incident review of the controls and processes that were involved, to identify improvements and reduce the likelihood of recurrence.
What affected individuals are told
Merion's notification to affected individuals will include:
- Merion's contact details.
- A description of the type of personal information involved in the breach.
- A description of the nature of the breach (what happened and how).
- Recommendations for steps individuals can take to protect themselves — for example, monitoring financial accounts, changing passwords where applicable, or contacting their financial institution.
Contact
If you believe your personal information may have been involved in a data breach affecting Merion's systems, contact Merion immediately:
- Email: [email protected]
- Phone: (08) 6325 5761
Merion will assess the situation and respond as required under the NDB scheme.
OAIC resources
The OAIC administers the NDB scheme and publishes guidance for both entities and individuals. More information is available at oaic.gov.au/privacy/notifiable-data-breaches/.
Related pages
For Merion's technical and organisational security controls, see Security and Security of Personal Information. For vulnerability reporting, see Responsible Disclosure.
Ready to talk to Merion?
Whether you have accounts to recover or a question about a notice, the first conversation is always obligation-free.