Trust Centre

Data Breach Response

How we detect, contain, assess and notify in the event of a data breach.

Back to Trust Centre

Data Breach Response Policy

Effective date: 28 July 2026 — Governed by the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme

Suspected breach? Contact us immediately.

Email support@sportsorganised.com at any time. All reports are treated as urgent and acknowledged within 24 hours.

Australian legal framework: SportsOrganised is bound by the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme (Part IIIC). Under the NDB scheme, we are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs — that is, when a breach is likely to result in serious harm to one or more individuals. Because we hold student PII on behalf of schools, we take these obligations extremely seriously.

1. What Is an Eligible Data Breach

Under the NDB scheme, an eligible data breach occurs when all three of the following conditions are met:

There is unauthorised access to, or disclosure of, personal information — or personal information is lost in circumstances where such access or disclosure is likely.

This is likely to result in serious harm to one or more individuals whose information is involved.

SportsOrganised has not been able to prevent the likely risk of serious harm through remedial action taken after the breach.

Breaches that do not meet this threshold must still be internally documented and assessed. Examples of potential breaches include: unauthorised database access, accidental exposure of student records, loss of a device containing exported data, or a staff account being compromised.

2. How We Detect Breaches

SportsOrganised maintains audit logs of all significant data actions, automated alerting for anomalous access patterns, and role-based access controls that limit exposure. We also rely on responsible disclosure from staff, school administrators, or external security researchers. If you observe unexpected behaviour in your account — such as unrecognised logins or altered data — report it immediately.

3. Our Response Actions

Upon becoming aware of a suspected breach we follow this four-stage process. The 30-day OAIC notification clock begins from the moment we become aware of reasonable grounds to suspect an eligible data breach.

1

Contain

Immediate (within hours)

Isolate affected systems and accounts, revoke any compromised credentials, suspend unauthorised access, and preserve forensic evidence. A named incident owner is assigned within the first hour.

  • Take affected services or accounts offline if necessary
  • Revoke session tokens and reset passwords for compromised accounts
  • Preserve server logs and audit trails in read-only storage
  • Notify internal leadership and legal counsel
2

Assess

Within 30 days of awareness

Determine the nature, scope, and likely impact of the breach. This assessment drives notification obligations under the NDB scheme.

  • Identify which personal information was accessed or disclosed
  • Determine the number and identity of affected schools and individuals
  • Assess whether the breach is likely to result in serious harm
  • Assess whether any remedial action can prevent the risk of serious harm
  • Document findings in a formal incident record
3

Notify

As soon as practicable — no later than 30 days from awareness

Where the breach meets the NDB eligibility threshold, we notify the OAIC and affected individuals. School administrators are notified regardless of whether the breach is eligible under NDB.

  • Lodge a data breach notification with the OAIC via the online portal
  • Notify affected school administrators by email with a clear incident summary
  • Where serious harm is likely, notify affected individuals directly with recommended protective steps
  • Notification statements include: a description of the breach, data types involved, steps taken, and contact details for further enquiries
4

Remediate

Ongoing following containment

Close the vulnerability, strengthen controls, and ensure the breach cannot recur. Maintain a complete incident record for regulatory purposes.

  • Patch or reconfigure the underlying vulnerability
  • Review and tighten access controls and authentication requirements
  • Conduct a post-incident review with lessons learned
  • Update internal security procedures as required
  • Retain incident documentation for a minimum of 5 years

4. What We Will Tell Affected Schools

School administrators will receive a written notification that includes at minimum:

The date the breach was discovered and when it occurred (if known)

A description of the type of breach (unauthorised access, disclosure, loss)

The categories and approximate volume of personal information involved

Steps SportsOrganised has already taken to contain the breach

Steps we recommend the school takes to protect affected individuals

A direct contact for further questions and ongoing updates

5. OAIC Notification and Regulatory Cooperation

Where an eligible data breach is identified, SportsOrganised will submit a statement to the Office of the Australian Information Commissioner (OAIC) using the prescribed NDB notification form. This statement is submitted as soon as practicable and no later than 30 days after we become aware of the breach. We cooperate fully with any subsequent OAIC investigation or audit. We also maintain an internal breach register for all incidents — eligible or not — for a minimum retention period of five years.

6. Prevention Measures

We take proactive steps to minimise breach risk across the platform:

Encryption: Data is encrypted in transit (TLS 1.2+), and sensitive credentials such as passwords and two-factor secrets are encrypted at rest.

Tenant isolation: Each school's data is logically isolated with strict tenant-scoped query enforcement — no cross-tenant data access is possible.

Role-based access: Staff access is limited to the minimum data required for their role. Student PII cannot be accessed by users without explicit permission.

Audit logging: All significant data actions are timestamped and logged for traceability.

Regular reviews: We conduct periodic security reviews of our infrastructure, access controls, and code.

Vulnerability disclosure: We maintain a responsible disclosure process for external researchers who identify security issues.

7. Reporting a Breach or Security Vulnerability

To report a suspected data breach or security vulnerability, contact our security team at support@sportsorganised.com. We acknowledge all reports within 24 hours and provide a substantive response within 72 hours. For general privacy enquiries, contact support@sportsorganised.com.

Further information about the NDB scheme and the OAIC's role is available at oaic.gov.au.