1. When you find out
  2. Your first steps
    1. 1. Preserve the evidence before you confront anyone
    2. 2. Work out what leaked and whether personal information is involved
    3. 3. Start the assessment and notify who the law requires
    4. 4. Assess your claims and stop the damage
    5. 5. Fix the gap and keep an incident record
  3. When this is a job for a lawyer
  4. The notification clock starts when you suspect

When you find out

You run a fifteen-person consultancy. On Tuesday morning a client forwards you an email thread you were never meant to see: your internal pricing schedule, a project pipeline document, and a list of every client you have billed in the past three years, sent from the personal account of a senior employee who resigned on Friday. Or the discovery takes a different shape, a supplier mentions your proposal template has been doing the rounds, a screenshotted version of your client list shows up in a competitor's pitch, a laptop goes missing from a car. However it arrives, the news is the same: confidential information has left your business, and you have to decide what to do next.

You now have two problems, not one. The commercial problem is that your client list and pricing are exactly the assets a competitor would pay for, and if the leaver has joined one, the information may already be in use. The regulatory problem is that the spreadsheet contains client names, email addresses and billing details, which are personal information under the Privacy Act 1988 (Cth). Where personal information has been accessed or disclosed without authorisation, and a reasonable person would conclude the individuals face a likely risk of serious harm, the Act treats the incident as an eligible data breach and imposes notification duties on you. The clock on those duties starts earlier than most owners expect, and what you do in the first 48 hours decides both whether you can pursue the leaver and whether you end up on the right side of the regulator.

This article walks through what to do when a leak happens, in the order a real business should do it. The first two steps are the ones most owners get backwards, and they are the ones that shape everything after them.

Your first steps

Work through these five steps in order. The first two are about discipline, not drama: they are the unglamorous work that preserves your options.

1. Preserve the evidence before you confront anyone

Your instinct will be to call the leaver, or the IT person, and start cleaning up. Do the opposite. Every claim you might later bring, and every defence you might later need, runs on evidence: who sent what, to whom, when, and who else could have done it. Once a mailbox is archived, a laptop is wiped or a log retention window passes, that evidence is gone permanently.

Capture before you change anything:

  • Email and message threads: the full thread with headers, timestamps, recipients and the original attachment, not a screenshot of the screen.
  • Access records: who logged into which systems, from where, and when; the download or export history for the file in question.
  • The file itself: a copy with its metadata intact, so you can later show which version existed when.
  • Company devices: secure the leaver's laptop and phone immediately, and do not wipe or reimage them until they have been imaged or reviewed.

What to avoid is just as important. Do not delete anything, and do not ask IT to "clean up" the mailbox or the file server. Do not confront the person before the evidence is locked down, because a confrontation is an invitation to delete the trail. And do not announce the investigation in an all-staff email, which gives everyone a reason to tidy their own records.

There is one thing you should do immediately, and it is containment, not destruction: change the passwords, revoke remote access and suspend the leaver's accounts. Take the copies first, then cut the access. Suspending an account is not the same as deleting it, and the distinction matters here.

2. Work out what leaked and whether personal information is involved

Before you can decide who to tell, you need to know what category the leaked material falls into. Sort it into two buckets:

  • Commercial confidential information: client lists, pricing models, product plans, internal financials, trade secrets, strategy documents.
  • Personal information: anything about an identifiable individual, including names, email addresses, phone numbers, home addresses, billing details, health information and employee records.

One document can sit in both buckets at once. A client list with contact details is a commercial asset in your hands and personal information about each client. That overlap is the reason a "commercial" leak so often triggers privacy obligations.

The distinction drives your legal duties. The notification scheme in Part IIIC of the Privacy Act 1988 (Cth) attaches to personal information, and an eligible data breach exists where there has been unauthorised access to or unauthorised disclosure of the information, or the information has been lost in circumstances where such access or disclosure is likely, and in each case a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals concerned (s 26WE of the Privacy Act 1988 (Cth)). "Serious harm" is not confined to identity theft; a leaked list of a therapist's clients, a supplier's pricing to a customer, or a document that reveals who a business works with can meet the test.

Two misconceptions are worth clearing up now. First, you do not need to be certain a leak will cause serious harm before the Act has anything to say to you; the scheme is built around assessment of that question, not certainty. Second, the small business exemption is narrower than most owners think. A business is a small business for these purposes if its annual turnover for the previous financial year was $3 million or less (s 6D(1)), but businesses that provide a health service and hold health information, credit reporting bodies, and contracted service providers for Commonwealth contracts are caught regardless of turnover (s 6D(4) of the Privacy Act 1988 (Cth)). If your situation is close to any of those lines, treat the information as covered until you have advice to the contrary.

3. Start the assessment and notify who the law requires

This is where the clock starts, and it starts earlier than you might think. If you are aware that there are reasonable grounds to suspect an eligible data breach has occurred, the Act requires you to carry out a reasonable and expeditious assessment of whether the circumstances amount to an eligible data breach, and to take all reasonable steps to complete that assessment within 30 days of becoming aware (s 26WH of the Privacy Act 1988 (Cth)). The trigger is suspicion, not confirmation. The day the client forwards you the email thread is day one, not the day you finish interviewing staff.

If the assessment, or information that comes to you, gives you reasonable grounds to believe an eligible data breach has happened, the notification duties follow. You must prepare a statement setting out your identity and contact details, a description of the breach, the kinds of information concerned and recommended steps for affected individuals, and give it to the Office of the Australian Information Commissioner (OAIC) as soon as practicable (s 26WK). You must also take reasonable steps to notify the affected individuals, or publish the statement on your website where individual notification is not practicable (s 26WL).

Notification to the regulator and notification to affected individuals can run in parallel with your own investigation, and often should. If you already have reasonable grounds to believe, do not hold the statement back while you keep digging for a fuller picture; the duty is to notify as soon as practicable, and the statement can be supplemented.

The OAIC is not the only person with a right to hear from you:

  • Affected clients: beyond the statutory duty, client agreements often contain notification clauses, and a client who learns of the leak from a third party will be harder to keep.
  • Contract counterparties: if the leaked material came from a joint project, check what your NDA or collaboration agreement says about notification of unauthorised disclosure.
  • Your insurers: cyber and management liability policies routinely require prompt notice of incidents, and late notification can void cover.

4. Assess your claims and stop the damage

Running in parallel with the notification steps, you should be working out what the leaker has actually done and what you can do about it. Where a former employee, contractor or third party has taken or used the information, you may have claims on more than one basis.

Breach of confidence is the equitable claim that protects confidential information as such. The classic Australian formulation asks whether the information had the necessary quality of confidence, was communicated in circumstances importing an obligation of confidence, and has been used or disclosed without authorisation, to the detriment of the person who entrusted it, as applied by the NSW Court of Appeal in Del Casale v Artedomus (Aust) Pty Ltd [2007] NSWCA 172. Where the leaver signed a confidentiality clause in an employment contract, or an NDA covered the disclosure, you also have a straightforward breach of contract claim for damages.

The remedies worth knowing about are the urgent ones. An interlocutory injunction can stop the recipient from using or disclosing the information while the matter is resolved, and the court can order delivery up and deletion of copies. These orders are time sensitive: courts are far more willing to restrain ongoing use of information than to compensate you after the damage has been done. If the information is already in a competitor's hands, speed is the whole game.

A written demand letter is the practical first move, and it does double duty. It identifies the information, asserts its confidentiality, requires return and deletion, and puts the recipient on notice that further use will be pursued. That notice also matters legally: for information that was never clearly marked as confidential, a demand cements the "circumstances importing an obligation of confidence" element for any use that happens after it.

Two further points belong in this step. If the leaker is a director or officer of your company, their use of information acquired through their position may also breach s 183 of the Corporations Act 2001 (Cth), which prohibits officers from improperly using information to gain an advantage or cause detriment. And check your own exposure before you start sending demands: if your privacy policy or marketing promised strong data security and the leak happened because the basics were missing, affected customers may argue your public statements were misleading or deceptive conduct under s 18 of the Australian Consumer Law, which is Schedule 2 of the Competition and Consumer Act 2010 (Cth). Make sure what you told the world matches what you actually did.

5. Fix the gap and keep an incident record

Once the immediate response is under way, the work shifts to documentation and prevention, and both should happen while the details are fresh.

Keep a written record of what leaked, how it happened, when you first became aware, what steps you took, who you notified and what they said. If the OAIC investigates, or the leaver later claims wrongful dismissal, this record is your account of events. A note made in the moment is far more credible than a reconstruction three months later.

One decision affects everything you write: whether the investigation is protected by legal professional privilege. An investigation conducted for the dominant purpose of obtaining legal advice, or for use in anticipated litigation, is privileged, which means the record of it does not have to be disclosed to the OAIC or in court. The same investigation run internally, without advice, produces documents that can be compelled. If you want the protection, get the lawyer involved at the start rather than after the internal report is written.

Finally, close the door the leak came through. Review who has access to which systems and which documents, reissue confidentiality obligations to the people who remain, update your information security policy and retrain staff on handling sensitive files. The next leak will usually come through the same gap, and the cheapest outcome is to have closed it while the incident is still fresh in everyone's mind.

When this is a job for a lawyer

Some leaks resolve with a demand letter and a change of passwords. Others need professional help from day one, and the markers are reasonably clear. Call a lawyer early if personal information is involved and you are within the Privacy Act, if the leaver is a departing employee who has joined a competitor, if the information is still in circulation, if you have been threatened with a claim, or if your insurer has conditions attached to notification.

If you bring the situation to a practitioner, the work typically runs like this. First, they confirm whether the Privacy Act applies to you, whether you have an eligible data breach on the current facts, and where you sit against the 30-day assessment clock, so the notification decision is made on the law rather than guesswork. Second, they take over the investigation so it is conducted under privilege. Third, they draft and lodge the OAIC statement and handle the correspondence with affected individuals, so the compliance story is consistent and complete. Fourth, they assess your claims against the leaker, send the demand letter, and negotiate return and deletion of the material. If the information is actively being used, they can move for an interlocutory injunction within days. And throughout, they keep the regulator, the insurer and your contractual obligations in step, because those three audiences rarely tolerate being managed separately.

The notification clock starts when you suspect

The single thing to remember tomorrow is this: the assessment clock and the notification duty are triggered by reasonable grounds to suspect, not by certainty. The business that preserves evidence and starts the assessment on day one keeps control of both its compliance story and its claims. The business that spends the week confronting the leaver and tidying up loses both: the regulator sees a slow response, and the evidence trail goes cold while the argument was happening.

To recap what matters: freeze the evidence before you confront anyone; classify what leaked and treat personal information as personal; start the eligible data breach assessment immediately and notify the OAIC and affected individuals as soon as you have reasonable grounds to believe; pursue your claims for breach of confidence and breach of contract while the information can still be restrained; and record and remediate so the same door does not open twice. A leak is rarely the end of a business, but the first 48 hours decide whether it is a managed incident or an expensive one.