Data Breach Response Policy
How the Global Gambling Harm Reduction Alliance prevents, detects, and responds to personal data breaches under GDPR Article 33-34 and the Australian Privacy Principles.
Last updated: 2 August 2026
1. Purpose and Scope
This policy sets out the Global Gambling Harm Reduction Alliance (GGHRA) procedure for identifying, assessing, containing, and notifying personal data breaches affecting member or visitor data. It applies to all GGHRA systems, subprocessors (Stripe, Base44/Wix, Zoom), and anyone acting on behalf of the alliance.
2. Definitions
A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This includes confidentiality breaches (unauthorised access), integrity breaches (unauthorised alteration), and availability breaches (loss of access or destruction).
3. Roles and Responsibilities
- Privacy Lead (DPO equivalent): coordinates breach assessment, regulatory notification, and member communication. Contact via the Compliance Center.
- Platform Administrators: responsible for technical containment, evidence preservation, and system recovery.
- Subprocessors: must notify GGHRA of any incident affecting GGHRA data without undue delay and in any event within 24 hours of becoming aware.
4. Detection and Assessment
Suspected breaches may be identified through automated monitoring, audit-log review, member reports, or subprocessor notifications. Upon detection, the Privacy Lead performs a risk assessment within 24 hours to determine the likely scope, the categories and approximate number of affected individuals, and the likely consequences.
5. Containment and Recovery
Immediate steps include isolating affected systems, revoking compromised credentials, rotating API keys, and preserving forensic evidence. Recovery actions restore systems to a known-good state and apply remediation to prevent recurrence. All actions are recorded in the breach register.
6. Notification to Supervisory Authorities
Where a breach is likely to result in a risk to the rights and freedoms of individuals, GGHRA notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, in accordance with GDPR Article 33. The notification describes the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed.
7. Notification to Affected Individuals
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, GGHRA communicates the breach to affected members without undue delay, in clear and plain language, in accordance with GDPR Article 34. Communication includes the nature of the breach, the Privacy Lead's contact point, the likely consequences, and the measures taken.
8. Australian Privacy Principles
Consistent with APP 11, GGHRA takes reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. Where a serious data breach occurs that is likely to result in serious harm to individuals, GGHRA complies with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), notifying the Office of the Australian Information Commissioner and affected individuals as soon as practicable after becoming aware.
9. Breach Register
GGHRA maintains an internal register of all personal data breaches, including suspected and confirmed incidents, regardless of whether notification was required. The register documents the facts, effects, and remedial action, and is reviewed at least annually.
10. Review and Training
This policy is reviewed at least annually and after any significant breach. Administrators and the Privacy Lead receive periodic training on incident response and this policy.