skills/arckit-au-ndb-playbook/SKILL.md
[COMMUNITY] Generate a Notifiable Data Breach (NDB) scheme response playbook under Privacy Act 1988 Part IIIC — eligible-data-breach test, 30-day OAIC notification timeline, individual notification, containment, and lessons-learned framework.
npx skillsauth add tractorjuice/arckit-codex arckit-au-ndb-playbookInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by a Privacy Officer and legal counsel before adoption. NDB scheme guidance is updated by OAIC — verify against current OAIC publications before any external use.
You are an enterprise architect generating a Notifiable Data Breach (NDB) scheme response playbook under the Privacy Act 1988 (Cth) Part IIIC.
$ARGUMENTS
The Notifiable Data Breach (NDB) scheme under Privacy Act 1988 (Cth) Part IIIC requires APP entities (Australian Government agencies + private organisations subject to the Privacy Act) to notify the OAIC and affected individuals when an "eligible data breach" of personal information occurs and is likely to result in serious harm.
The NDB scheme has three statutory tests:
The notification clock is 30 days to OAIC + affected individuals from the time the entity has reasonable grounds to believe an eligible data breach has occurred. Privacy Act Tranche 1 reform (Dec 2024) increased OAIC enforcement powers and introduced a private right of action, materially increasing the cost of poor NDB handling.
A working NDB playbook is operational — it must be executable under time pressure, owned by a named responder, and tested.
Authoritative anchors:
Read prerequisites:
ARC-{P}-AUPIA-v*) — APP 11 cross-referenceARC-{P}-AUE8-v*) — security baselineARC-{P}-AUISM-v*) — Domain 2 (Cyber Security Incidents)ARC-{P}-DFD-*) — personal-information flows, disclosure paths, external entities, storesARC-{P}-DATA-v*) — affected personal-information entities, sensitivity, retention, data ownersARC-{P}-SNOW-v*) if available — incident queues, escalation groups, change/problem workflows, knowledge articles.arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/au-ndb-playbook-template.md.arckit/templates-custom/au-ndb-playbook-template.md.arckit/templates/au-ndb-playbook-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> AUNDB --filename for the artefact filename.
Resolve the <!-- DOC-CONTROL-HEADER --> marker per RENDERING.md. Use the Australian classification scheme (UNOFFICIAL / OFFICIAL / OFFICIAL:Sensitive / PROTECTED / SECRET) — replace the standard UK line in the header.
Generate the following sections:
Entity Profile — APP entity status, Privacy Officer designation, accountable officer for NDB response, business hours + after-hours contact details, key incident-team roles.
NDB Eligibility Test — explicit decision tree:
If 1 + 2 = Yes and 3 = No → eligible data breach → notify within 30 days.
30-Day Timeline Plan — day-by-day milestones from Day 0 (becoming aware of suspected breach) through Day 30 (OAIC + individual notification deadline):
Roles & Responsibilities (RACI) — Privacy Officer, Security Officer, CISO, Legal, Communications, accountable executive — clear responsibility matrix.
Detection + Containment Procedures — how breaches become known to the playbook owner (SIEM alerts, customer reports, vendor disclosure, insider report); immediate containment steps; evidence preservation.
Assessment Procedure — how to determine eligibility under the three statutory tests; serious-harm assessment criteria (financial loss, identity theft, emotional distress, physical safety, reputational harm); reasonable-steps mitigation to remove eligibility.
OAIC Notification Form Content — what OAIC requires per the statutory form: nature of breach, kind of information involved, recommendations for affected individuals, contact details. Template language for use in the OAIC form.
Individual Notification Approach — direct vs publication-based notification options, content requirements, channel decisions, language and accessibility considerations.
Communications Plan — internal, external, media, regulator-coordinated. Pre-written holding statements + escalation triggers.
Post-Incident Review — root cause analysis, lessons learned, control updates feeding back into AUE8 + AUISM + AUPIA artefacts.
Coordination With Other Reporting Obligations — SOCI Act 12hr / 72hr (where applicable), DISP incident reporting, sectoral reporting (APRA, AHPRA, etc.). Single incident may trigger multiple obligations on different timelines.
Tabletop Exercise Plan — annual tabletop scenario, evidence retention, lessons-learned cycle.
ArcKit Evidence Integration — map $arckit-dfd, $arckit-data-model, $arckit-servicenow, $arckit-risk, $arckit-traceability, and $arckit-graph-report outputs to breach scope, incident workflow, decision evidence, risk treatment, and coverage gaps.
Populate the External References section per .arckit/references/citation-instructions.md. Privacy Act 1988 + OAIC NDB scheme guidance MUST appear in the Document Register.
Write the artefact via the Write tool to projects/<project-id>/<filename>.
Show only a summary to the user (one paragraph plus the 30-day timeline summary).
After completing this command, consider running:
$arckit-dfd -- DFDs identify personal-information flows, breach blast radius, notification channels, and third-party disclosure paths.$arckit-data-model -- Data model evidence identifies personal-information entities, sensitive attributes, retention, and affected data subjects.$arckit-au-pia -- NDB playbook is the operational complement to AUPIA APP 11 mitigation; APP 11 references NDB.$arckit-au-disp-attestation -- DISP attestation pack cites NDB capability evidence.$arckit-servicenow -- ServiceNow incident, problem, change, and knowledge workflows operationalise NDB response ownership and evidence capture.$arckit-risk -- NDB-relevant risks tagged into the project risk register.$arckit-traceability -- NDB triggers, roles, decisions, notifications, and lessons learned should trace to evidence and controls.$arckit-graph-report -- Graph reporting should show AUNDB coverage alongside privacy, security, risk, and traceability artefacts.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.