# NDB serious-harm and remedy exercise

Two fictional AI-submission scenarios separate evidence of disclosure from the serious-harm and remediation decision.

All people, events, risks and timeline entries are invented. No actual eligible-breach determination, provider response or notification has occurred.

Source: https://aona.ai/resources/guides/australia-ai-data-breach-assessment/
Sources checked: 2026-09-21

## Two different timing questions

### Suspect

Record the grounds and assess promptly

### Assess

Likely serious harm and remedial action

### Believe eligible

Apply notice duties as soon as practicable

Note: The 30-day assessment rule is separate.

| Decision point | Stipulated example facts | Illustrative outcome |
| --- | --- | --- |
| Scenario A: disclosure | Sensitive personal details reached an uncontrolled external recipient. | Proceed to harm and remedy assessment; the application label alone is not the conclusion. |
| Scenario A: likely harm | The exercise stipulates a credible threat assessed as making serious harm more probable than not. | Likely-serious-harm condition is assumed met for teaching, not inferred from a log alone. |
| Scenario A: remedy | No completed action prevents that stipulated risk. | Follow the eligible-breach notification path, subject to applicable exceptions. |
| Scenario B: blocked input | Reliable fictional evidence establishes no transmission and no other disclosure on the assessed path. | No breach is established from that blocked submission; document the evidence and remaining scope. |
| Unknown facts | Recipient access or remedy effectiveness remains unverified. | Assess promptly; take all reasonable steps within the applicable 30-calendar-day assessment period. |
| Conclusion reached | Reasonable grounds to believe an eligible breach exist in the scenario. | Notify as soon as practicable where required; do not wait for day 30. |

## Review checklist

- [ ] Establish disclosure and coverage
  Identify the actual information, entity, account, path and recipients before deciding applicability.
- [ ] Evidence harm and mitigation
  Record why serious harm is likely or not, and what completed remedy actually prevented.
- [ ] Separate the two timing duties
  Track suspicion/assessment and the later belief/notification decision without treating 30 days as a universal notice period.

## Included example files

- australia-ai-ndb-assessment.md
- australia-ai-ndb-assessment.csv
- ndb-fictional-evidence-timeline.csv

## Source references

- OAIC: Quick reference guide for responding to data breaches: https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches (2026-09-21)
- OAIC: When to report a data breach: https://www.oaic.gov.au/privacy/notifiable-data-breaches/when-to-report-a-data-breach (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
