Practical AI and SaaS for Business

AI Vendor Breach Response Plan Template for Australian Businesses

A free AI vendor breach response plan template for Australian businesses. Covers the immediate steps, NDB scheme assessment, OAIC notification procedure, and individual notification drafts needed when an AI incident occurs.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You manage a mid-sized family law firm, and your team now drafts correspondence and summarises case files with AI tools. If one of them is breached, you have to work out what happened, whether it is notifiable, and who to tell, fast. This template gives you a ready-made plan: who does what, how to check NDB eligibility, and how to notify the OAIC and your clients. No legal background needed. Copy it in and you are covered.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

An AI vendor breach response plan tells your business exactly what to do, in what order, and who is responsible when an AI tool is involved in a data incident. Without a plan, businesses spend the first hours of a breach trying to determine who is in charge. That delay costs time you need for your 30-day NDB assessment. This free template gives you a structured starting point. Adapt it to your business, name your response team, and keep it somewhere everyone can find it.

In short: Copy the template below into a document, fill in your business details and key contacts, and store it alongside your general data breach response plan. Review it annually or whenever you adopt a new AI tool. Last verified: June 2026. Next review: September 2026.

What this template covers

This template covers the five phases of an AI-related data incident response: initial containment, incident assessment, NDB eligibility determination, OAIC notification, and affected individual notification. It is designed for Australian businesses subject to the Privacy Act 1988 and the Notifiable Data Breaches scheme.

This template is a starting point, not legal advice. Incidents involving large volumes of sensitive personal information, health data, financial data, or information about children should be reviewed by a privacy-qualified lawyer before final decisions about notification are made. The OAIC also has a self-assessment tool on their website that complements this template.

In practice: the practice manager at a family law firm has fifteen staff using an AI tool to draft client correspondence. Before this template, if that tool were breached she would spend the first day working out who was responsible for what, whether the incident met the NDB threshold, and how to word a notification to affected clients, all while still running the firm's daily caseload. After filling in this template with her response team's names, the same morning looks different: containment is already assigned to a named person, the NDB eligibility questions are laid out in order, and a draft notification is sitting ready to be personalised. The decision that used to eat a full day now takes about an hour.

AI Vendor Breach Response Plan Template

AI VENDOR BREACH RESPONSE PLAN

Business name: [Your business name]
ABN: [Your ABN]
Plan owner: [Name and role of the person responsible for this plan]
Last reviewed: [Date]
Next review due: [Date, suggest annually]


Response team

RoleNameContact
Incident lead (decision-maker)
IT or systems contact
Privacy contact / legal adviser
Customer communications lead

Phase 1: Contain (do this first, within the first hour)

  • Identify which AI tool or vendor is involved
  • Suspend access to the affected AI tool or workspace
  • Revoke any compromised credentials or API keys
  • Confirm no further data is being shared or exposed
  • Record the time and date you became aware of the incident

Phase 2: Assess (within 24 hours)

  • Identify what personal information was involved (names, emails, health records, financial data, passwords)
  • Estimate how many individuals are affected
  • Determine how the breach occurred (vendor hack, staff error, misconfigured access, lost device)
  • Contact the AI vendor if their systems were involved and request a written incident report
  • Record your findings in the incident log below

Incident log entry:
Date and time of incident: _______________
Date and time discovered: _______________
AI tool or vendor involved: _______________
Description of what happened: _______________
Types of personal information involved: _______________
Estimated number of individuals affected: _______________
Cause (if known): _______________
Containment steps taken: _______________


Phase 3: NDB eligibility determination (within 30 days of first awareness)

Answer both questions below. If both answers are YES, proceed to Phase 4.

Question 1: Was there unauthorised access to, unauthorised disclosure of, or loss of personal information?
[ ] Yes   [ ] No   [ ] Uncertain (document reasoning)

Question 2: Would a reasonable person conclude this breach is likely to result in serious harm to one or more affected individuals?
[ ] Yes   [ ] No   [ ] Uncertain (document reasoning)

Serious harm indicators (tick if applicable):
[ ] Health or medical information involved
[ ] Financial account details, credit card numbers, or banking credentials involved
[ ] Passwords, PINs, or security credentials involved
[ ] Identity documents (passport, drivers licence, Medicare) involved
[ ] Information about children involved
[ ] Information that could enable identity fraud involved
[ ] Information that could cause physical harm, stalking, or harassment

Assessment outcome: [ ] Eligible data breach   [ ] Not eligible   [ ] Refer to legal adviser
Assessed by: _______________ Date: _______________


Phase 4: OAIC notification (as soon as practicable after eligible breach confirmed)

Submit the Notifiable Data Breach form at oaic.gov.au. The form will ask for:

  • Organisation name, ABN, and contact details
  • Description of the breach (what happened, when, how)
  • Types of personal information involved
  • Number of individuals affected (or estimate)
  • Likely serious harm to affected individuals
  • Containment and remediation steps taken
  • Steps affected individuals should take

OAIC notification date and reference number: _______________


Phase 5: Notify affected individuals (as soon as practicable)

Use the template below. Notify directly by email or letter where possible.

---

Subject: Important notice regarding your personal information

Dear [Individual's name],

We are writing to inform you of a data security incident that may have affected your personal information held by [Business name].

What happened: [Plain-English description of the breach. For example: On [date], we became aware that [AI vendor name] experienced a security incident that may have exposed data stored in our account. The information involved included [list types of data].]

What information was involved: [List the types of personal information affected, e.g., your name, email address, and account notes.]

What you should do: [Specific advice, e.g., Be alert to any unusual emails or messages claiming to be from us. Do not click links in unsolicited emails. If you believe your information has been misused, you may wish to place a fraud alert with your bank or credit provider.]

What we are doing: [Actions taken, e.g., We have suspended access to the affected tool, notified the Office of the Australian Information Commissioner, and are reviewing our AI tool security procedures.]

If you have questions, please contact us at [email address or phone number].

Sincerely,
[Business name] Team

---

Notification method: [ ] Email   [ ] Letter   [ ] Website notice (if direct contact not possible)
Date notifications sent: _______________
Number of individuals notified: _______________


Phase 6: Post-incident review (within 30 days of incident close)

  • Identify the root cause of the breach
  • Update your AI tool access policies if required
  • Review staff training on AI tool data handling
  • Update this response plan if any steps were unclear or missing
  • Review your AI vendor agreements for breach notification obligations

How to use this template

Copy this template into a Word document or your internal documentation system. Fill in your response team contacts now, before an incident occurs. Store it somewhere all relevant staff can access it, including when your normal systems are unavailable (consider a printed copy in a physical folder).

Review the template at least annually and whenever you adopt a significant new AI tool. As your AI tool stack changes, the types of personal information at risk change too. A breach response plan that covers only your CRM is no longer adequate once you have added an AI hiring tool, an AI document system, and an AI customer service platform.

Common gaps in small business breach response plans

The three most common gaps in small business breach response plans are: no named decision-maker for breach response, no pre-established relationship with a privacy lawyer or external adviser, and no process for assessing NDB eligibility. All three result in the same outcome: the first hours of a real breach are spent deciding who is in charge and what the rules are instead of responding to the incident.

A fourth gap specific to AI tools: many businesses have not added AI tools to their list of systems that are covered by a breach response plan. Your plan may cover your CRM, your accounting software, and your cloud storage, but say nothing about the AI tools your staff use every day for email drafting, document summarisation, and customer communication. If personal information flows through those tools, they belong in your plan.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: our can staff upload customer data to AI tools, our AI and the Privacy Act guide, and our free AI staff policy template.

See also: our guide to AI data breaches and the NDB scheme.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.

Try our free AI Policy Generator to generate a customised AI policy for your business.

Related reading: our free AI acceptable use policy template and our AI governance by region.

Related reading: Claude AI Review for Australian Business and Notion AI Review for Australian Small Business.

Does my business need a formal breach response plan?

There is no legal requirement in Australia for a business to have a written breach response plan. However, having one is a reasonable step for meeting your obligations under APP 11 (security of personal information), which requires you to take reasonable steps to protect personal information from misuse, interference, and loss. The OAIC recommends having a plan as part of good privacy practice. Businesses without a plan are more likely to exceed the 30-day NDB assessment window through disorganised responses.

Do I need to notify every person who might have been affected?

The NDB scheme requires notification to individuals whose personal information was involved in an eligible data breach. If you cannot identify specific affected individuals, the OAIC can direct you to publish a notice on your website as an alternative to direct notification. However, the OAIC's guidance indicates businesses are expected to make reasonable efforts to identify and contact individuals directly before resorting to a website notice. Vague, system-wide notices in place of targeted direct notification will attract scrutiny from the OAIC.

What if my business is not covered by the NDB scheme?

If your business is not covered by the Privacy Act (typically because your annual turnover is below $3 million and you are not in a special category like health services or credit), the NDB mandatory notification scheme does not apply to you. However, voluntary notification to the OAIC is always an option and is often appropriate when large volumes of personal information or sensitive data are involved. You also have ongoing contractual and ethical obligations to individuals whose data you hold, even outside the NDB scheme. A voluntary notification shows good faith and may reduce reputational damage.

Can I get help from the OAIC?

Yes. The OAIC has published guidance on preparing for and responding to data breaches, a data breach self-assessment tool, and a FAQ on the NDB scheme. These resources are free and accessible at oaic.gov.au. The OAIC also accepts voluntary reports of data breaches from businesses not covered by the mandatory scheme. For serious incidents involving large volumes of sensitive personal information, engaging a privacy-qualified lawyer before notifying is advisable.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.

Understand when an AI breach becomes a notifiable data breach under the NDB scheme, with three practical scenarios.

Read: what happens when AI gets breached