
Moderation
Handling community conflict and incidents
Respond to community incidents by triaging risk, containing harm, assigning an owner and communicating without exposing private details.
When conflict becomes a serious incident, limit immediate harm, establish what is known and assign a named owner. Leave rule-compliant disagreement open where possible. Treat threats and exposed private information as urgent.
Triage before deciding on a sanction
Read the relevant exchange and report. Ask what is happening now, who may be affected and whether the conduct or sharing continues.
| What you find | First response to consider |
|---|---|
| Strong criticism or disagreement within the rules | Leave it available and clarify the question if useful. |
| A personal attack or escalating exchange | Interrupt the conduct, review context and explain how discussion may continue. |
| A threat or exposed private information | Limit further exposure or contact promptly and alert the appropriate internal owner. |
These are triage choices, not automatic penalties. A report requires review; an unpopular opinion is not itself a breach. If someone may face an immediate safety threat, use the organisation’s urgent safety procedure.
When to Use Immediate Action vs. Further Review
- Strong criticism within rules
- Leave available; clarify question if helpful.
- Personal attack or escalation
- Interrupt conduct; review context; guide discussion back on track.
- Threat or exposed private info
- Limit exposure immediately; alert internal safety owner.
Contain harm and keep a restricted record
Use community controls to restrict harmful material, pause replies or limit contact where necessary. Removing a post may stop further viewing there, but cannot retrieve copies, notifications or screenshots already received.
Record the relevant post, timing, reports, actions and handoffs in an approved restricted location. Capture only what the people handling the case need. If a privacy or security investigation may follow, coordinate evidence handling with its owner while taking steps to reduce immediate exposure.
If personal information may be exposed, containment can include stopping the unauthorised practice, recovering records or shutting down the affected system. If shutdown is impractical or could destroy evidence, consider changing or revoking access privileges, or addressing the security weakness.
Assess suspected exposure by gathering facts and evaluating possible harm to affected people. A case that first appears minor may have more serious implications once its full circumstances are understood, so tailor the response to the risks and take remedial action where possible.
Key Actions When Handling a Community Incident
- Restrict harmful material using community controlsPause replies, limit contact, or restrict visibility
- Record actions in a restricted locationCapture post, timing, reports, actions taken, handoffs
- Assess potential harm from exposureGather facts; evaluate risk to affected individuals
- Coordinate with privacy/security teams if neededEnsure evidence handling aligns with investigation needs
Give the response one owner
A moderator may take an authorised immediate action. A serious case may also require a privacy, security, support or senior business owner. Record who coordinates the response, who decides restrictions, who contacts affected people and when each handoff will be reviewed.
If personal information may have been exposed, the privacy owner should assess the organisation’s role and obligations. Australia’s Notifiable Data Breaches scheme applies to covered entities and eligible breaches; likely serious harm and effective remedial action matter to that assessment. A suspected eligible breach calls for prompt assessment, not a delay in containment.
For a suspected data breach, organise the work around four steps: contain, assess, notify and review. Steps can be combined or handled at the same time; containment, assessment and notification should happen simultaneously or in quick succession where appropriate. Circumstances determine which steps are needed and whether extra actions are required.
Check whether the organisation is covered by the Notifiable Data Breaches scheme rather than assuming every community operator has the same obligations.
Covered entities include Australian Government agencies, businesses and not-for-profit organisations with annual turnover above AU$3 million, as well as some entities such as private health service providers, credit providers and tax file number recipients. Some businesses of any size are covered, including those that trade in personal information.
Four Key Steps for Responding to a Notifiable Data Breach (NDM Scheme)
- ContainStop the breach from spreading; restrict access, remove harmful content or shut down affected systems.
- AssessEvaluate whether the breach is eligible under the NDB scheme—consider likely serious harm and remedial action.
- NotifyIf eligible, notify affected individuals and the Australian Information Commissioner (OAIC) promptly.
- ReviewAnalyse how the incident occurred and implement changes to prevent recurrence.
Covered Entities Under Australia’s NDB Scheme
- Australian Government agencies
- Yes – automatically covered
- Businesses with turnover > AU$3 million
- Yes – covered if they handle personal information
- Private health service providers
- Yes – regardless of size
- Credit providers
- Yes – regardless of size
- Tax file number recipients
- Yes – regardless of size
Speak to each audience separately
Tell the author privately what action was taken, the rule or safety concern involved and how to request review if available. Tell a reporter what can appropriately be shared about the response. If readers need to understand a visible change, give a short note about the thread and what discussion may continue.
Do not identify a reporter, repeat removed material, disclose another member’s account details or speculate about motives. Avoid promising that nobody saw the post or that an investigation is complete before those facts are known.
If an incident is an eligible data breach under the scheme, notification to affected individuals and the Australian Information Commissioner may be mandatory. In some circumstances, it may be appropriate to notify individuals immediately, before containment or assessment is complete; coordinate that decision with the responsible privacy owner.
Restore the underlying issue and close the case
An incident may begin with a legitimate complaint. Removing an attack does not resolve a product, policy or support question. Decide where that question continues and who answers it. Do not require a targeted member to negotiate publicly for help.
Record the moderation decision, notices, any review request and work still open with other teams. Check whether the response reduced risk and whether a rule, tool or handoff needs improvement. Limit access to the case record under the organisation’s retention arrangements.
For a suspected data breach, include a review of how the incident occurred and what could prevent a future breach. Keep this distinct from resolving the member-facing issue: the incident review is about reducing the chance of recurrence, while the underlying complaint may still need an owner and an answer.
In this guide
- Responding when a member posts confidential informationContain a confidential community post, assess the information and remaining risk, and route privacy or security follow-up.
- Managing disputes involving paying customersHandle a paying customer’s conduct and complaint separately, with fair moderation and a clear route for the purchase or service issue.
- Explaining a moderation decision without exposing private detailsExplain a moderation action to authors, reporters and readers while protecting private case details and giving an available review route.
- Reviewing a serious incident with the moderation teamReview a serious moderation incident with a factual timeline, decision checks and improvement actions with owners.


