Skip to main content
GGHRA
Legal & Governance

Data Breach Response Policy

How the Global Gambling Harm Reduction Alliance prevents, detects, and responds to personal data breaches under GDPR Article 33-34 and the Australian Privacy Principles.

Last updated: 2 August 2026

1. Purpose and Scope

This policy sets out the Global Gambling Harm Reduction Alliance (GGHRA) procedure for identifying, assessing, containing, and notifying personal data breaches affecting member or visitor data. It applies to all GGHRA systems, subprocessors (Stripe, Base44/Wix, Zoom), and anyone acting on behalf of the alliance.

2. Definitions

A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This includes confidentiality breaches (unauthorised access), integrity breaches (unauthorised alteration), and availability breaches (loss of access or destruction).

3. Roles and Responsibilities

  • Privacy Lead (DPO equivalent): coordinates breach assessment, regulatory notification, and member communication. Contact via the Compliance Center.
  • Platform Administrators: responsible for technical containment, evidence preservation, and system recovery.
  • Subprocessors: must notify GGHRA of any incident affecting GGHRA data without undue delay and in any event within 24 hours of becoming aware.

4. Detection and Assessment

Suspected breaches may be identified through automated monitoring, audit-log review, member reports, or subprocessor notifications. Upon detection, the Privacy Lead performs a risk assessment within 24 hours to determine the likely scope, the categories and approximate number of affected individuals, and the likely consequences.

5. Containment and Recovery

Immediate steps include isolating affected systems, revoking compromised credentials, rotating API keys, and preserving forensic evidence. Recovery actions restore systems to a known-good state and apply remediation to prevent recurrence. All actions are recorded in the breach register.

6. Notification to Supervisory Authorities

Where a breach is likely to result in a risk to the rights and freedoms of individuals, GGHRA notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, in accordance with GDPR Article 33. The notification describes the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed.

7. Notification to Affected Individuals

Where a breach is likely to result in a high risk to the rights and freedoms of individuals, GGHRA communicates the breach to affected members without undue delay, in clear and plain language, in accordance with GDPR Article 34. Communication includes the nature of the breach, the Privacy Lead's contact point, the likely consequences, and the measures taken.

8. Australian Privacy Principles

Consistent with APP 11, GGHRA takes reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. Where a serious data breach occurs that is likely to result in serious harm to individuals, GGHRA complies with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), notifying the Office of the Australian Information Commissioner and affected individuals as soon as practicable after becoming aware.

9. Breach Register

GGHRA maintains an internal register of all personal data breaches, including suspected and confirmed incidents, regardless of whether notification was required. The register documents the facts, effects, and remedial action, and is reviewed at least annually.

10. Review and Training

This policy is reviewed at least annually and after any significant breach. Administrators and the Privacy Lead receive periodic training on incident response and this policy.

We use cookies to measure how the platform is used and improve it.

Essential cookies are always on. Analytics cookies are only enabled with your consent. See our Privacy Policy.