Last updated: 09 August 2026
This Data Breach Response Plan sets out how Service Integrity Mystery Shopping identifies, assesses, contains, escalates, and responds to actual or suspected data breaches involving personal information, client confidential information, shopper information, or project data.
This plan applies the requirements of the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme, together with Service Integrity’s contractual confidentiality obligations and client-specific onboarding requirements.
This plan applies to:
Service Integrity will:
Incident Lead: Steven Di Pietro, CEO Responsible for coordinating the response, client notification, external advice, and final sign-off.
Operations Support: relevant Service Integrity operations staff Responsible for identifying affected projects, users, records, shoppers, clients, and business processes.
Platform / Supplier Contact: LiveShopper (SASSIE) support or other relevant system provider Responsible for platform-specific investigation, access review, restoration, and security evidence where the incident involves hosted systems.
External Advisers: broker, insurer, legal adviser, IT and security support as required Responsible for specialist advice where the incident may trigger insurance, legal, regulatory, or technical response obligations.
A data breach or suspected data breach may be identified through:
Any staff member who becomes aware of a suspected breach must escalate it to Steven Di Pietro as soon as practicable.
The first priority is containment. Depending on the incident, containment may include:
Service Integrity will assess:
Notification timing. Where client information is or may be affected, Service Integrity will notify the client as soon as practicable and in any event within two business days of becoming aware of the incident. An initial assessment will follow within five business days, and the client will receive a status update at least every five business days while the incident remains open.
Notification will include, to the extent known:
Where the Notifiable Data Breaches scheme applies, Service Integrity will complete its assessment within 30 days of becoming aware of the incident and will notify affected individuals and the Office of the Australian Information Commissioner as required.
Remediation may include:
After the incident is resolved, Service Integrity will record:
The review will be used to improve procedures, staff guidance, and client-specific handling requirements.
Service Integrity treats information about a client, its staff, its customers, its investors or members, its associated entities, project scenarios, and engagement outputs as confidential.
If client information is involved in an actual or suspected breach, Service Integrity will notify the client within the timeframes set out above and will cooperate with reasonable information requests about the incident, containment, and remediation.