Legal & compliance centre

HLD Group

Breach notification policy

Notifying regulators, customers, and individuals of data breaches.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines how HLD Group assesses and, where required, notifies data breaches to regulators, affected individuals, customers, and other parties, and the timeframes within which it must do so. Notification is a legal obligation in most jurisdictions in which we operate, with strict deadlines and significant penalties for failure.

This policy governs the notification obligations that arise from a security incident. The detection, containment, and investigation of the incident itself are governed by the Incident Response Policy, which this policy works alongside.

2. Scope

This policy applies to any actual or suspected breach of personal data or regulated data held or processed by HLD Group, whether as controller of our own data or as processor of customer data, across all systems and jurisdictions in which we operate.

3. Definitions

  • Data breach — unauthorised access to, disclosure of, or loss of personal or regulated data
  • Eligible data breach — under Australian law, a breach likely to result in serious harm to an affected individual
  • Personal data breach — under the GDPR, a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data
  • Controller and processor — the party determining the purposes of processing, and the party processing on its behalf
  • Supervisory authority — the regulator to which a breach may be notifiable

4. Breach assessment

On confirmation of a data breach, its nature, scope, and likely consequences are assessed without undue delay to determine notification obligations. The assessment considers the categories and volume of data, the number and identity of affected individuals, the likelihood and severity of harm, and whether the data was encrypted or otherwise protected.

5. Notification obligations by jurisdiction

Australia — Notifiable Data Breaches scheme

Under Part IIIC of the Privacy Act 1988 (Cth), where there are reasonable grounds to believe an eligible data breach has occurred — a breach likely to result in serious harm to any affected individual — HLD Group notifies the Office of the Australian Information Commissioner and affected individuals as soon as practicable. Where we only suspect an eligible breach, we complete an assessment within 30 days.

European Union — GDPR

Under Article 33 of the GDPR, a personal data breach is notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Under Article 34, where the breach is likely to result in a high risk, affected individuals are informed without undue delay. As a processor, we notify the affected customer controller without undue delay under Article 33(2).

United States

Breaches involving US residents are notified in accordance with the applicable state breach-notification statutes (all US states impose notification duties, with varying triggers and timeframes), and with sector-specific laws such as HIPAA and the HITECH Act for protected health information, and the FTC Safeguards Rule for financial data, where applicable.

Other jurisdictions and contracts

Notification is made under any other applicable law and under the terms of customer contracts, which frequently impose notification timeframes shorter than statutory minimums. The strictest applicable requirement governs.

6. Notification content

  • The nature of the breach and the categories and approximate number of individuals and records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address it and to mitigate harm
  • Recommended steps affected individuals can take to protect themselves
  • Contact details for further information

7. Processor obligations to customers

Where HLD Group processes customer data as a processor, we notify the affected customer without undue delay after becoming aware of a breach affecting their data, provide the information they need to meet their own notification obligations, and support their response, in accordance with the Data Processing Policy and the applicable data processing agreement. We do not notify regulators or individuals on a controller customer’s behalf unless contractually instructed to do so.

8. Records and cooperation

  • All breaches, including those assessed as not notifiable, are documented with the facts, effects, and remedial action, as required by GDPR Article 33(5) and good practice
  • Breach records are retained under the Data Retention Policy
  • HLD Group cooperates fully with supervisory authorities and provides information they require

9. Framework alignment

  • Privacy Act 1988 (Cth), Part IIIC (Notifiable Data Breaches scheme)
  • GDPR Articles 33 and 34 and Article 33(5) (documentation)
  • US state breach-notification statutes; HIPAA/HITECH Breach Notification Rule; FTC Safeguards Rule
  • ISO/IEC 27001:2022 Annex A controls 5.24 to 5.28 (information security incident management)
  • NIST SP 800-53 Rev. 5 control IR-6 (incident reporting)

10. Roles, exceptions, and review

The CISO and privacy officer jointly own breach assessment and notification, with legal counsel. No individual may decide unilaterally not to notify a breach that meets a legal threshold. This policy is reviewed at least annually and after any notifiable breach.

Related frameworks

For contractual attestations or audit packs, contact [email protected].