EEmpowerNotesSupport records, made clear
Product preview

EmpowerNotes policy

Data Breach Response Guide

How suspected security and privacy incidents are handled.

Effective 24 July 2026EmpowerNotes personnel and customer administrators

Response stages

  • Identify and contain the suspected incident.
  • Preserve evidence and record decisions, times, systems and affected data.
  • Assess likely harm, affected organisations and whether personal information was exposed.
  • Notify affected customers promptly and coordinate required communications.
  • Assess notification obligations under the Notifiable Data Breaches scheme and other applicable requirements.
  • Recover services, monitor for recurrence and complete a documented lessons-learned review.

Customer reporting

Customers should report suspected compromise immediately through privacy@empowernotes.org and include the affected account, approximate time, observed behaviour and a safe callback contact. Sensitive records should not be emailed unless specifically requested through a secure channel.

Back to policy centre