Trust Centre
Data breach response
What we do when information we hold may have been lost, accessed, disclosed or altered without authorisation - including when the law requires us to tell you and the regulator.
Effective 21 August 2026
This policy applies to any information we hold, and it applies whether the cause is an attack, a mistake by us, a failure at one of the providers listed in section 05 of our Privacy policy, or a device or credential falling into the wrong hands.
01What counts as a data breach
A data breach is unauthorised access to, unauthorised disclosure of, or loss of information we hold. Examples that would trigger this policy:
- an account accessed by someone who is not its owner;
- records belonging to one agent becoming visible to another;
- a document, identity check or transcript disclosed to the wrong person;
- a credential or access token being exposed; and
- an incident at a provider that holds information on our behalf.
02What we do, and in what order
- 1. Contain
- Stop the exposure. Revoke the credential, close the path, disable the account, take the surface down if that is what it takes. Containment comes before investigation, and before working out how it happened.
- 2. Preserve
- Keep the logs and records needed to understand the incident before anything is cleaned up.
- 3. Assess
- Establish what information was involved, whose it was, how many people are affected, and whether serious harm is likely. Where a breach is suspected but not confirmed, the Privacy Act requires this assessment to be completed within 30 days, and we treat that as an outer limit rather than a target.
- 4. Notify
- Tell the people affected and, where required, the regulator. Section 03 sets out when.
- 5. Remediate
- Fix the cause, not the instance, and confirm the fix holds. An incident is not closed because the symptom stopped.
03When we tell you
Australia's Notifiable Data Breaches scheme, in Part IIIC of the Privacy Act 1988 (Cth), requires notification where a breach is likely to result in serious harm to an affected person and we have not been able to prevent that harm through remedial action.
Where that threshold is met we will, as soon as practicable:
- notify the Office of the Australian Information Commissioner with a statement describing the breach, the information involved and what people should do; and
- notify each affected person directly where it is practicable to reach them.
Our notification will tell you, in plain words:
- what happened and when;
- what information about you was involved;
- what we have done about it; and
- what you should do, if anything.
We will not delay telling you in order to finish an investigation. Where facts are still being established we will say so rather than wait.
04Breaches involving your clients
If you are an agent, records about your clients sit in your account. Where a breach affects those records we will notify you, and we will tell you what we have established so that you can meet your own obligations to the people involved.
Where the breach originates in your own account - a shared password, a compromised device, a mailbox connected to the platform - the obligation to notify the people affected is yours. We will support you with what we can establish from our side.
05Breaches at a provider
Some information is held by the providers named in section 05 of our Privacy policy. Where one of them suffers a breach affecting information we sent them, we apply this policy to it: we assess the effect on the people whose information was involved, and we notify on the same basis as if the breach had happened here.
06Telling us
If you believe information held by us has been exposed, tell us at support@buyersagents.com.au. Say what you saw and when. A report that turns out to be nothing costs us an hour; one that goes unmade costs somebody a great deal more.
If you would prefer to raise it with the regulator, the Office of the Australian Information Commissioner is at oaic.gov.au.
07Afterwards
Every incident is reviewed for the mechanism that allowed it, not only the instance that revealed it. Where the review changes how the platform works, the relevant policy on this site is updated and its effective date moves.