Data Breach Response Plan

Service Integrity Data Breach Response Plan

Last updated: 09 August 2026

Purpose

This Data Breach Response Plan sets out how Service Integrity Mystery Shopping identifies, assesses, contains, escalates, and responds to actual or suspected data breaches involving personal information, client confidential information, shopper information, or project data.

This plan applies the requirements of the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme, together with Service Integrity’s contractual confidentiality obligations and client-specific onboarding requirements.

Scope

This plan applies to:

  • Service Integrity staff, contractors, and authorised representatives;
  • mystery shopping projects managed by Service Integrity;
  • client information, shopper information, staff information, and project records;
  • systems used to collect, store, process, analyse, or report mystery shopping data; and
  • third-party systems used by Service Integrity, including the SASSIE platform provided by LiveShopper.

Key Principles

Service Integrity will:

  • act quickly to contain suspected breaches;
  • preserve evidence and avoid unnecessary deletion or alteration of affected records;
  • assess whether personal information or confidential client information is involved;
  • notify affected clients promptly where their information may be affected;
  • comply with legal notification obligations where required;
  • document decisions, actions, and timelines; and
  • review incidents after resolution to reduce recurrence risk.

Roles And Responsibilities

Incident Lead: Steven Di Pietro, CEO Responsible for coordinating the response, client notification, external advice, and final sign-off.

Operations Support: relevant Service Integrity operations staff Responsible for identifying affected projects, users, records, shoppers, clients, and business processes.

Platform / Supplier Contact: LiveShopper (SASSIE) support or other relevant system provider Responsible for platform-specific investigation, access review, restoration, and security evidence where the incident involves hosted systems.

External Advisers: broker, insurer, legal adviser, IT and security support as required Responsible for specialist advice where the incident may trigger insurance, legal, regulatory, or technical response obligations.

Response Process

1. Identify

A data breach or suspected data breach may be identified through:

  • staff report;
  • client notification;
  • shopper notification;
  • unusual account activity;
  • misdirected email or file sharing;
  • lost or stolen device;
  • unauthorised access to systems;
  • malware, phishing, credential compromise, or supplier alert; or
  • platform notification from LiveShopper (SASSIE) or another service provider.

Any staff member who becomes aware of a suspected breach must escalate it to Steven Di Pietro as soon as practicable.

2. Contain

The first priority is containment. Depending on the incident, containment may include:

  • disabling or resetting affected accounts;
  • revoking file links or shared access;
  • asking unintended recipients to delete misdirected information;
  • pausing affected workflows;
  • isolating affected devices;
  • preserving logs and relevant emails;
  • contacting platform support; and
  • notifying the insurer or broker where the incident may trigger policy requirements.

3. Assess

Service Integrity will assess:

  • what happened;
  • when it happened;
  • what information was involved;
  • whether personal information was accessed, disclosed, lost, or at risk;
  • whether client information or client customer information was involved;
  • how many people or records may be affected;
  • whether harm is likely;
  • whether the incident is an eligible data breach under the Notifiable Data Breaches scheme;
  • whether the client must be notified under contract or onboarding requirements; and
  • whether external legal, technical, insurer, or regulator advice is required.

4. Notify

Notification timing. Where client information is or may be affected, Service Integrity will notify the client as soon as practicable and in any event within two business days of becoming aware of the incident. An initial assessment will follow within five business days, and the client will receive a status update at least every five business days while the incident remains open.

Notification will include, to the extent known:

  • a plain-English description of the incident;
  • the date and time identified;
  • the type of information involved;
  • containment steps already taken;
  • further investigation steps underway;
  • any known or likely impact;
  • proposed remediation; and
  • next update timing.

Where the Notifiable Data Breaches scheme applies, Service Integrity will complete its assessment within 30 days of becoming aware of the incident and will notify affected individuals and the Office of the Australian Information Commissioner as required.

5. Remediate

Remediation may include:

  • account security changes;
  • password resets;
  • access permission review;
  • revised staff instruction;
  • supplier escalation;
  • technical patching;
  • process changes;
  • revised file-sharing controls;
  • additional staff training; and
  • documented client-specific safeguards.

6. Review

After the incident is resolved, Service Integrity will record:

  • cause;
  • affected information;
  • response timeline;
  • decisions made;
  • notifications sent;
  • remediation completed; and
  • prevention actions.

The review will be used to improve procedures, staff guidance, and client-specific handling requirements.

Client-Specific Handling

Service Integrity treats information about a client, its staff, its customers, its investors or members, its associated entities, project scenarios, and engagement outputs as confidential.

If client information is involved in an actual or suspected breach, Service Integrity will notify the client within the timeframes set out above and will cooperate with reasonable information requests about the incident, containment, and remediation.

Related Documents