1. Who must comply
  2. The standing duty to secure personal information
  3. What counts as an eligible data breach
  4. Step one: contain the breach and assess it within 30 days
  5. Step two: notify the OAIC and affected individuals
  6. Step three: review and prevent recurrence
  7. Consequences of getting it wrong
  8. A practical compliance checklist
  9. Where a privacy lawyer helps
  10. Start the clock the moment you suspect a breach

Australia's mandatory data breach notification regime has been in force since 22 February 2018. If your business holds personal information and that information is lost or accessed without authorisation, the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth) (the Act) may require you to notify the Office of the Australian Information Commissioner (OAIC) and the individuals affected.

This article sets out who the scheme applies to, what triggers the notification duty, the steps you must take when a breach happens, and what is at stake if you get it wrong.

Who must comply

The NDB scheme applies to entities that already have an obligation under the Act to secure personal information. That includes Australian Government agencies, and private sector and not-for-profit organisations with an annual turnover of more than $3 million in the previous financial year.

The Act's $3 million threshold matters for small business. A business is a small business for the purposes of the Act if its annual turnover for the previous financial year was $3 million or less, and small business operators are generally not covered by the Act. Turnover includes all income from all sources, but not assets held, capital gains or proceeds of capital sales.

However, a business of any size is covered if it:

  • Provides a health service: health service providers include private hospitals, medical practitioners, pharmacists, allied health professionals, complementary therapists, child care centres and private schools.
  • Trades in personal information: for example, disclosing personal information about individuals to someone else for a benefit, service or advantage, or collecting personal information in exchange for a benefit or service.
  • Is a credit reporting body or credit provider: including banks, credit unions, building societies, and retailers or utilities that offer credit.
  • Is a contracted service provider for a Commonwealth contract: the obligations apply to personal information held for the purpose of providing those services.
  • Operates a residential tenancy database: the operator's handling of personal information held in that database is covered by the Act.
  • Is an employee association or conducts protected action ballots: the Act covers employee associations registered or recognised under the Fair Work (Registered Organisations) Act 2009 (Cth) and persons who conduct protected action ballots.
  • Is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) or is accredited under the Consumer Data Right or Digital ID systems: the reporting entity limb extends through the expansion of the AML/CTF regime to new designated services.
  • Is related to a body corporate that is covered by the Act, or has opted in to coverage: related bodies corporate of covered entities are caught, and other entities may opt in to the Act's coverage.

The Act also applies to recipients of tax file number information in relation to that information, even if they are not otherwise covered. Employee records are generally exempt from the scheme, except that tax file number information contained in an employee record is still protected.

Because the Privacy Act has been under reform for several years, including proposals to narrow or remove the small business exemption, the scope of these obligations can change. If you are unsure whether your business is covered, the OAIC's small business checklist is a useful starting point, and a privacy lawyer can confirm your position.

The standing duty to secure personal information

The NDB scheme is built on an existing obligation. Australian Privacy Principle 11 requires every APP entity to take such steps as are reasonable in the circumstances to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include technical and organisational measures, and extend to destroying or de-identifying information the entity no longer needs.

What is "reasonable" depends on the circumstances, including the sensitivity of the information, the size of the business and the cost of available safeguards. A business that holds only basic contact details can reasonably do less than one holding Medicare numbers or health records. Getting this baseline right matters: a breach that would have been prevented by reasonable safeguards can itself become evidence in a regulator's investigation.

What counts as an eligible data breach

Not every security incident triggers notification. The duty arises only for an eligible data breach under section 26WE of the Act. That exists where:

  • there is unauthorised access to, or unauthorised disclosure of, personal information; or
  • personal information is lost in circumstances where unauthorised access or disclosure is likely to occur;

and in either case a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates.

"Serious harm" is assessed objectively, and section 26WG sets out the factors to weigh. These include the kind and sensitivity of the information, whether it was protected by security measures and how easily those measures could be overcome, who has obtained or could obtain the information, and the nature of the harm. As a practical matter, financial information, government identifiers such as driver's licences and passports, and health information will usually point towards serious harm, particularly if they were not encrypted. Harm to reputation, and the likelihood that an individual will suffer serious physical, psychological, emotional, financial or economic harm, all count.

There is an important exception. Under section 26WF, if the entity takes action before the access or disclosure results in serious harm, and as a result a reasonable person would conclude that serious harm is no longer likely, the incident is not an eligible data breach. Recovering a stolen laptop before it is opened, or locking down a compromised account before the information is accessed, can remove the notification duty entirely.

Step one: contain the breach and assess it within 30 days

The moment your business becomes aware that there are reasonable grounds to suspect an eligible data breach, the statutory clock starts. Section 26WH requires the entity to carry out a reasonable and expeditious assessment of whether the circumstances amount to an eligible data breach, and to take all reasonable steps to complete that assessment within 30 days of becoming aware.

The OAIC treats 30 days as a maximum, not a target. It recommends that entities begin by containing the breach, for example by shutting down affected systems, revoking access privileges, recovering lost data and preserving evidence, and then move quickly to identify what information was involved, who has had access to it, and what harm is likely.

The OAIC's data breach preparation and response guide suggests a three-stage assessment: initiate (decide who will run the assessment), investigate (gather what is known about the incident), and evaluate (decide whether it is an eligible data breach). The entity should document the assessment and its outcome. If the assessment cannot be completed within 30 days, the OAIC expects the entity to be able to demonstrate that all reasonable steps were taken, and to explain the delay.

Step two: notify the OAIC and affected individuals

If the assessment concludes that there has been an eligible data breach, the entity must act promptly. Section 26WK requires it to prepare a statement and give a copy to the OAIC as soon as practicable after becoming aware of the breach. The statement must set out:

  • The entity's identity and contact details: so the OAIC and affected individuals know who is responsible.
  • A description of the eligible data breach: what happened and when it occurred.
  • The particular kinds of information involved: be specific. The OAIC expects a statement to say "driver's licence numbers" rather than "ID documents", because the detail determines what individuals can do to protect themselves.
  • Recommendations about the steps individuals should take: for example, contacting their bank, replacing a Medicare card or driver's licence, or placing a ban on their credit report.

The entity must also notify individuals. Section 26WL offers three options depending on what is practicable: notify every individual whose information was involved; notify only those individuals at risk of serious harm; or, if neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it. The OAIC expects a published statement to remain accessible for at least six months. Any method of notification is acceptable as long as it is reasonable, whether a phone call, SMS, letter or email.

Where the same incident affects more than one entity, only one entity needs to prepare the statement and notify, and it is usually sensible for the entity with the most direct relationship with the affected individuals to take the lead.

The Commissioner also has a backstop power under section 26WR: if the OAIC is aware of reasonable grounds to believe an eligible data breach has occurred, it may direct the entity to prepare and give it a statement and to notify affected individuals.

Step three: review and prevent recurrence

Once the immediate response is over, the work is not done. The OAIC expects an entity's approach to data breach management, including its response plan, to be reviewed after an incident. A post-breach review should ask how the breach happened, whether the safeguards required by APP 11 were in place and adequate, whether the response plan worked, and what needs to change. Common improvements include updating access controls and passwords, disposing of storage media securely, training staff on handling personal information, and appointing a person accountable for data security.

Consequences of getting it wrong

The stakes are substantial. A breach of the Act that amounts to a serious interference with privacy exposes a body corporate to a civil penalty of up to the greatest of $50 million, three times the value of any benefit obtained from the conduct, or 30% of its adjusted turnover during the relevant period, under section 13G of the Act. Individuals face penalties of up to $2.5 million, and other interferences with privacy attract penalties of up to 2,000 penalty units.

Beyond fines, the OAIC can investigate on its own initiative, conciliate complaints from affected individuals, make determinations, and seek orders from the Federal Court. Failure to comply with a direction to notify is itself a serious matter. And the commercial damage of a mishandled breach should not be underestimated: affected customers who hear about an incident through the media rather than from the business itself rarely forgive the lapse.

A practical compliance checklist

Work through these items to keep your data breach response on track:

  • Confirm whether your business is covered by the Act, including the exceptions for health service providers, businesses trading in personal information, credit providers and Commonwealth contracted service providers.
  • Meet the APP 11 baseline: reasonable technical and organisational measures to protect personal information, and a process for destroying or de-identifying information no longer needed.
  • Have a written data breach response plan naming who leads the response, before an incident occurs.
  • On suspicion of a breach, contain it, preserve evidence, and start a documented assessment immediately.
  • Complete the assessment within 30 days of becoming aware.
  • If it is an eligible data breach, prepare the statement and give it to the OAIC and affected individuals as soon as practicable.
  • After the dust settles, review what went wrong and update your safeguards and plan.

Where a privacy lawyer helps

A lawyer's main value in this area is before the 30-day clock starts. At the planning stage, a privacy lawyer can review whether your business is caught by the Act, stress-test your security arrangements against APP 11, and help you write a response plan that assigns roles and preserves privilege. When a breach occurs, they can help you work through the serious harm assessment, decide who needs to be notified and what the statement should say, deal with the OAIC on your behalf, and manage the interfaces with insurers, regulators and affected individuals. Engaging help early is usually far cheaper than defending an investigation after a notification goes wrong.

Start the clock the moment you suspect a breach

The obligation that catches most businesses by surprise is not the notification itself, but the assessment duty that precedes it. The 30-day period starts when your business has reasonable grounds to suspect an eligible data breach, not when the breach is confirmed. A helpdesk ticket that sits unanswered for a fortnight, or an unexamined report of a lost laptop, can quietly burn half the assessment window. Document your suspicions the day they arise, contain what you can, and get advice early. The businesses that manage data breaches well are not the ones that never have them, but the ones whose first response is immediate, documented and legally informed.