Data Breach Policy
Our commitment to detecting, responding to and notifying data breaches
Last updated: 24 July 2026
If you suspect a breach involving RILLA Shield data, email us immediately at security@rillashield.app.
1. Scope & Purpose
This policy sets out how Rilla Shield Defence Pty Ltd ("we", "us", "our") detects, assesses, contains, and reports data breaches involving personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) scheme.
A "data breach" occurs when personal information we hold is accessed, disclosed, or lost in circumstances where unauthorised access, disclosure, or loss is likely to result in serious harm to any individual to whom the information relates.
2. Detection
We detect potential breaches through:
- Automated security monitoring, alerts and anomaly detection
- Immutable audit logs and access reviews
- Third-party vulnerability and penetration testing
- Reports from staff, customers, partners, and security researchers
- Notifications from service providers, regulators, and law-enforcement
Anyone who suspects a breach involving RILLA Shield should report it immediately to security@rillashield.app. For privacy-related breaches, you may also contact legal@rillashield.com.au.
3. Response Process
When a potential breach is identified, we act promptly to:
- Contain: take immediate steps to limit the breach, revoke access, isolate affected systems, and preserve evidence.
- Assess: determine the nature and extent of the breach, the categories of personal information involved, and the individuals likely to be at risk of serious harm.
- Notify: if required under the NDB scheme, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
- Remediate: fix the root cause, apply security improvements, and restore normal operations.
- Review: conduct a post-incident review to identify lessons learned and update controls to prevent recurrence.
4. Notification Timeframes
We will notify affected individuals and the OAIC as soon as practicable when an eligible data breach is likely to result in serious harm. We aim to notify affected customers within 72 hours of becoming aware of a confirmed breach, and the OAIC within the same timeframe where required by the NDB scheme.
Notifications will include:
- a description of the breach and the information involved
- steps we have taken to contain the breach
- recommendations for steps individuals can take to protect themselves
- contact details for further information
5. Lawful Delay & Exceptional Circumstances
In exceptional circumstances, we may delay notification to affected individuals where law-enforcement or national security agencies advise that notification would interfere with an investigation or otherwise harm the public interest. We will still notify the OAIC as required and notify affected individuals as soon as the restriction no longer applies.
6. Customer Responsibilities
Users of the Service play a critical role in preventing breaches. You must:
- keep your account credentials secure and confidential
- enable multi-factor authentication where available
- promptly report any suspected unauthorised access or suspicious activity
- ensure that you only upload personal information that is necessary and that you have authority to share
7. Contact
For breach-related matters, contact our security team at security@rillashield.app. For privacy-related questions, contact legal@rillashield.com.au.
