Security

Security and Data Breach Policy

SDA Listings security posture and eligible data breach response.

Version
0.1-draft
Status
Draft — pending solicitor review
Effective
Not yet effective — pending solicitor approval
Last reviewed
2026-07-16
Next review
2026-10-16
Solicitor approval
Not yet obtained
# Security and Data Breach Policy > **Status: DRAFT for solicitor review.** This document has not been approved by a legal practitioner. It is provided for internal review only and is not legal advice. **Applies to:** SDA Listings, ABN 44 156 567 671, based in Victoria, Australia. A postal address will be published once confirmed by the operator. Contact: support@sdalistings.com.au. Governing law: These terms are governed by the laws of Victoria, Australia, and applicable Commonwealth laws of Australia. ## Security and data breach **Public summary.** SDA Listings uses role-based access control, database row-level security, encrypted transport, audit logging, secret management, and regular platform maintenance. Not all implementation details are disclosed publicly. **Incident response.** In the event of a suspected incident we follow: detection → containment → investigation → remediation → notification assessment → post-incident review. If we assess that an eligible data breach has occurred, we notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. No online service is completely secure. We do not guarantee that a breach cannot occur. ## Change history Version 0.1 — initial draft prepared for solicitor review.

Feedback on this document may be sent to support@sdalistings.com.au. Historical versions and change history are maintained by the SDA Listings platform team.