# NDB serious-harm and remedy exercise

All people, events, risks and timeline entries are invented. No actual eligible-breach determination, provider response or notification has occurred.

Two fictional AI-submission scenarios separate evidence of disclosure from the serious-harm and remediation decision.

| Decision point | Stipulated example facts | Illustrative outcome |
| --- | --- | --- |
| Scenario A: disclosure | Sensitive personal details reached an uncontrolled external recipient. | Proceed to harm and remedy assessment; the application label alone is not the conclusion. |
| Scenario A: likely harm | The exercise stipulates a credible threat assessed as making serious harm more probable than not. | Likely-serious-harm condition is assumed met for teaching, not inferred from a log alone. |
| Scenario A: remedy | No completed action prevents that stipulated risk. | Follow the eligible-breach notification path, subject to applicable exceptions. |
| Scenario B: blocked input | Reliable fictional evidence establishes no transmission and no other disclosure on the assessed path. | No breach is established from that blocked submission; document the evidence and remaining scope. |
| Unknown facts | Recipient access or remedy effectiveness remains unverified. | Assess promptly; take all reasonable steps within the applicable 30-calendar-day assessment period. |
| Conclusion reached | Reasonable grounds to believe an eligible breach exist in the scenario. | Notify as soon as practicable where required; do not wait for day 30. |

## Review steps

- Establish disclosure and coverage: Identify the actual information, entity, account, path and recipients before deciding applicability.
- Evidence harm and mitigation: Record why serious harm is likely or not, and what completed remedy actually prevented.
- Separate the two timing duties: Track suspicion/assessment and the later belief/notification decision without treating 30 days as a universal notice period.

## Fictional evidence timeline

Day 0: employee reports the suspected AI disclosure; incident owner records the grounds for suspicion.
Day 1: team secures the payload/account facts and requests recipient information.
Day 2: the exercise stipulates evidence of uncontrolled disclosure and likely serious harm; effective remediation is not established.
Day 2 onward: the authorised owner follows the eligible-breach notice path as soon as practicable, subject to the actual rules and exceptions.
Day 30: not a permission to wait; the separate assessment requirement concerns all reasonable steps to complete a suspected-breach assessment.

No real notice is drafted or sent by this fixture. Apply the actual entity, information and evidence before making a real decision.

## Source and scope

Guide: https://aona.ai/resources/guides/australia-ai-data-breach-assessment/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- OAIC: Quick reference guide for responding to data breaches: https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches
- OAIC: When to report a data breach: https://www.oaic.gov.au/privacy/notifiable-data-breaches/when-to-report-a-data-breach
