Full internal runbook: docs/NDB_RESPONSE_PLAN.md. Named owner must be filled before production child data.
1. Detect
Sources include vendor alerts (Supabase), anomalous access logs, staff reports, and customer reports. Any suspected unauthorised access, loss, or disclosure is logged immediately.
2. Contain
Revoke compromised credentials, rotate keys, isolate affected systems, and preserve evidence. Do not destroy logs needed for assessment.
3. Assess (serious harm)
Within days — not weeks — assess whether the breach is likely to result in serious harm (identity theft, financial harm, significant distress, discrimination risk, child safety risk). Document the assessment.
4. Notify
If the NDB threshold is met, notify the OAIC and affected individuals as soon as practicable and within 30 days of becoming aware. Notices describe what happened, likely consequences, and steps individuals can take.
5. Review
After containment, remediate root cause, update this plan, and brief centres if their families were affected.