
Moderation
Part of Handling community conflict and incidents
Responding when a member posts confidential information
Contain a confidential community post, assess the information and remaining risk, and route privacy or security follow-up.
If a member posts confidential information, promptly limit access and sharing. Identify the information, whose it is and what risk remains. Keep a restricted record for staff handling the case. Removing a post cannot establish that nobody saw, copied or received it.
Contain the post without spreading it
Use the community’s available controls to hide or remove the content and, if needed, pause replies. Check for copies in quoted replies, attachments, previews and other threads.
Ask staff handling the case not to forward the original post through a general team channel. A brief instruction not to repost may help if readers have begun copying it, without describing the material again.
Preserve the evidence needed to understand where and when the material appeared, what it contained, who acted and what access or sharing is known. Store it in an approved restricted location.
Coordinate with a privacy or security owner if an investigation may need the original record or access logs. Do not promise complete deletion before checking what the organisation can remove.
Identify the information and route the risk
A customer’s account details, someone’s contact information, a usable access credential and an unpublished business document need different follow-up. Ask whether the material identifies a person, enables access to an account or system, or reached someone who should not have it. Identify who can decide what happens next and who may need to be contacted.
If a credential may still work, involve the security owner to assess revocation or rotation. If the post concerns someone else’s personal information, consider potential harm to that person. Business-confidential material without personal information may need a commercial or contractual owner; it is not automatically a notifiable privacy breach.
Privacy & Security Considerations by Data Type
- Personal Information (e.g., contact details)
- Requires privacy assessment under APP 11; may trigger NDB reporting
- Access Credentials (e.g., passwords, tokens)
- Must be revoked immediately; involves security owner
- Unpublished Business Documents
- No automatic privacy breach; may require commercial or contractual review
Assess notification through the right process
For an organisation covered by the Australian Privacy Principles, APP 11 requires reasonable steps to protect personal information it holds. The Notifiable Data Breaches scheme has a separate, narrower test for covered entities and eligible breaches, including likely serious harm and whether remedial action prevents that risk. A privacy owner should assess the facts; the appearance of a post alone does not establish a reporting duty.
Move promptly while classification remains uncertain. Record what is known about access, potential harm and possible remedial steps. The OAIC advises entities to move immediately to contain, assess and remediate a data breach or suspected data breach.
When Is a Breach Notifiable Under the NDB Scheme?
- Eligible Breach?
- Only if there is a likely risk of serious harm to individuals
- Remedial Action Prevents Harm?
- If yes, no notifiable breach even if data was exposed
- Business-Confidential Only?
- Not automatically a notifiable breach unless personal information is involved
Contact people without repeating the material
Tell the poster privately what was removed or restricted, why it should not be shared and how to continue the original question safely. Someone may have posted a screenshot while seeking help; address the exposure without assuming intent. Contact affected people through the organisation’s privacy or incident process where appropriate rather than relying on a public thread notice.
If readers need to understand a visible change or stop sharing copies, a public note could say: “We removed information that should not be shared here. Please do not repost it. Use the private support route for the original question.” Use only the parts that describe actions and routes actually available. Do not identify the material, the affected person or a suspected viewer.
Complete the handoff
Check whether copies remain within the community and whether the member’s underlying problem still needs an answer. Record the containment action and give any privacy, security or commercial follow-up a named owner. Closing the moderation task does not mean the wider incident is resolved.


