Most breach-response plans are written for the technology. The part that actually fails under pressure is almost always the decision, not the pipeline.
Section 8(5) sets the baseline: reasonable security safeguards to prevent a personal data breach in the first place. Section 8(6) is what happens when that fails anyway — notification, and it names two separate audiences, not one. The Data Protection Board has to be told. The affected Data Principals have to be told. Satisfying one of those doesn't satisfy the other, and a plan that only covers the regulatory filing while treating customer notification as optional PR has only done half the job the Act actually asks for.
A common instinct, especially under pressure, is that if the issue got patched quickly enough and nothing was "confirmed" to have leaked, there's nothing to report. That instinct is exactly backwards: it's a judgement call about whether a breach happened at all, made by the same person who's under the most pressure for the answer to be no. A security incident report that never becomes a breach decision isn't evidence nothing happened — it's evidence nobody with the authority to decide ever looked at it properly.
The decision that something is — or genuinely isn't — a reportable personal data breach shouldn't rest on one person, especially not the same person who found it or who's responsible for the system that failed. Not because any one person is untrustworthy, but because a decision with legal consequences deserves a second, differently-motivated read before it's final — the same reason a company doesn't let one person both initiate and approve its own expense report.
The organisations that handle this well treat containment, root cause, and the "is this reportable" call as separate steps, each recorded, with the final call made by someone other than whoever raised the initial flag. That's not bureaucracy for its own sake — it's what makes the eventual answer to a regulator (or to an affected customer) something you can actually stand behind. It's the same separation-of-duty principle we built into how Consent Tree handles an incident internally: the person who proposes a stage doesn't get to also approve it.
What the Act actually says — S.8(6) requires notifying BOTH the Data Protection Board and affected Data Principals — satisfying one is not satisfying the other.