Inkcraft Education Logo
Legal & Compliance

Data Breach Response Plan

How we manage suspected or actual data breaches involving personal information.

ST4S Aligned Version 1.0 Last Updated: 1 August 2026 Inkcraft Education Pty Ltd

1. Purpose & Scope

This Data Breach Response Plan outlines how Inkcraft Education Pty Ltd manages suspected or actual data breaches involving personal information across both Inkcraft Studio and Inkcraft Report platforms, ensuring compliance with the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act 1988 and in alignment with the ST4S framework.

2. Incident Severity Classification

Inkcraft Education classifies data security incidents into four severity levels to ensure proportionate and timely response:

P1 — Critical

Confirmed breach involving student PII or widespread unauthorised access. Immediate containment and notification required.

P2 — High

Confirmed breach involving educator account data or institutional configuration data. Rapid containment within 4 hours.

P3 — Medium

Suspected unauthorised access attempt or anomalous system behaviour without confirmed data exposure. Investigation within 24 hours.

P4 — Low

Minor security event (e.g., failed login attempts, non-critical vulnerability report). Logged and reviewed within standard operating cycles.

3. Identification & Containment

If a potential breach is detected (e.g., unauthorised access, disclosure, or loss of data), our security team will immediately take steps to contain the breach. This may involve isolating affected systems, suspending compromised accounts, or temporarily taking the Inkcraft Studio or Inkcraft Report platform offline to prevent further data exposure.

4. Assessment (Within 48 Hours)

We will conduct an expedited assessment to determine:

  • The type and volume of data involved.
  • Whether Student Personally Identifiable Information (PII) was accessed.
  • The likelihood of serious harm to affected individuals.
  • Whether the breach affects Inkcraft Studio or Inkcraft Report data hosted on our cloud infrastructure.

5. Notification & Communication

If the assessment determines that a breach is likely to result in serious harm, or as recommended under the ST4S incident response framework, we will:

Notify School Administrators

We will notify the designated administrative contacts at affected schools within 24 to 48 hours of confirming the breach, providing details of the incident, the data affected, and recommended protective actions.

Notify Authorities

We will notify the Office of the Australian Information Commissioner (OAIC) and relevant state education departments as required by law.

6. Review & Remediation

Following containment, we will conduct a post-incident review to investigate the root cause, patch vulnerabilities, and update our security protocols to prevent recurrence. A final incident report will be made available to affected partner schools upon request. Forensic evidence will be preserved for the duration of any investigation.

7. Shared Responsibility for Cloud Credentials & Access

Inkcraft Education is responsible for the security of our Australian cloud infrastructure, single-tenant databases, software updates, and any data transmitted to or processed by our servers.

Schools are responsible for securing their user credentials, enforcing strong passwords, and managing access control for their staff and students. We recommend that schools implement multi-factor authentication (MFA) where available and promptly revoke access for departing personnel.