LEGAL

Data Breach Policy

Our commitment to detecting, responding to and notifying data breaches

Last updated: 24 July 2026

If you suspect a breach involving RILLA Shield data, email us immediately at security@rillashield.app.

1. Scope & Purpose

This policy sets out how Rilla Shield Defence Pty Ltd ("we", "us", "our") detects, assesses, contains, and reports data breaches involving personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) scheme.

A "data breach" occurs when personal information we hold is accessed, disclosed, or lost in circumstances where unauthorised access, disclosure, or loss is likely to result in serious harm to any individual to whom the information relates.

2. Detection

We detect potential breaches through:

  • Automated security monitoring, alerts and anomaly detection
  • Immutable audit logs and access reviews
  • Third-party vulnerability and penetration testing
  • Reports from staff, customers, partners, and security researchers
  • Notifications from service providers, regulators, and law-enforcement

Anyone who suspects a breach involving RILLA Shield should report it immediately to security@rillashield.app. For privacy-related breaches, you may also contact legal@rillashield.com.au.

3. Response Process

When a potential breach is identified, we act promptly to:

  • Contain: take immediate steps to limit the breach, revoke access, isolate affected systems, and preserve evidence.
  • Assess: determine the nature and extent of the breach, the categories of personal information involved, and the individuals likely to be at risk of serious harm.
  • Notify: if required under the NDB scheme, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
  • Remediate: fix the root cause, apply security improvements, and restore normal operations.
  • Review: conduct a post-incident review to identify lessons learned and update controls to prevent recurrence.

4. Notification Timeframes

We will notify affected individuals and the OAIC as soon as practicable when an eligible data breach is likely to result in serious harm. We aim to notify affected customers within 72 hours of becoming aware of a confirmed breach, and the OAIC within the same timeframe where required by the NDB scheme.

Notifications will include:

  • a description of the breach and the information involved
  • steps we have taken to contain the breach
  • recommendations for steps individuals can take to protect themselves
  • contact details for further information

5. Lawful Delay & Exceptional Circumstances

In exceptional circumstances, we may delay notification to affected individuals where law-enforcement or national security agencies advise that notification would interfere with an investigation or otherwise harm the public interest. We will still notify the OAIC as required and notify affected individuals as soon as the restriction no longer applies.

6. Customer Responsibilities

Users of the Service play a critical role in preventing breaches. You must:

  • keep your account credentials secure and confidential
  • enable multi-factor authentication where available
  • promptly report any suspected unauthorised access or suspicious activity
  • ensure that you only upload personal information that is necessary and that you have authority to share

7. Contact

For breach-related matters, contact our security team at security@rillashield.app. For privacy-related questions, contact legal@rillashield.com.au.