You are running a business and a staff member has just told you a laptop containing customer details was stolen. Or your payment provider has emailed to say its systems were hacked and transaction records were accessed. Or a former employee still has login access to your customer database. The circumstances differ, but the question is the same: what do you do now?
A data breach is an unauthorised access to, unauthorised disclosure of, or loss of, personal information. How you respond decides both the harm suffered by the people whose information is involved and your exposure under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth) (the Act). By the end of a properly run response you should have the incident contained, a documented assessment of whether anyone faces a real risk of serious harm, notifications sent to the Office of the Australian Information Commissioner (OAIC) and to affected individuals where the law requires it, and a reviewed set of processes that reduces the chance of a repeat.
One assumption is worth correcting up front: not every data breach has to be reported to the regulator. Only an "eligible data breach", meaning one that is likely to result in serious harm to any of the individuals concerned, triggers mandatory notification. The OAIC's response guidance is built around four steps: contain, assess, notify and review, and this article walks through each of them in the order they run.
Before you respond: what to have ready
A data breach response runs faster and more cleanly when the following are already in place. Some are legal prerequisites, others are practical:
- Confirm whether the NDB scheme applies to you: The scheme covers APP entities: Australian Government agencies and private sector and not-for-profit organisations with an annual turnover of more than $3 million. It also covers health service providers of any size, credit providers, credit reporting bodies, businesses that trade in personal information, and tax file number recipients. A small business below the turnover threshold is generally outside the scheme unless one of those exceptions applies, though it may still have notification duties under contracts, industry codes or other laws.
- Know what personal information you hold and where: You cannot assess a breach you cannot scope. Keep a working map of the customer, client and employee data you hold, where it lives (in-house systems, cloud providers, third parties) and how sensitive it is.
- Name an incident lead and a response team: One person should own the response, with defined roles for IT, communications and legal, so decisions are not deferred while everyone assumes someone else is handling it.
- Preserve evidence: Logs, back-ups, access records and the compromised system itself are the raw material of your assessment and of any later OAIC investigation. Containment should never mean wiping a server or re-imaging a laptop before the facts are gathered.
- Keep the reporting contacts handy: Bookmark the OAIC's Notifiable Data Breaches reporting portal and the Australian Cyber Security Centre (ACSC) at cyber.gov.au, which is where cyber incidents should be reported.
- Check your notification duties outside the NDB scheme: Cyber insurance policies, customer contracts and sector regulators can all impose their own reporting requirements, and if you hold the data of people in the European Union the General Data Protection Regulation (GDPR) can require notification to a European regulator within 72 hours of becoming aware of a breach.
Two of these trip businesses up more than the rest. The first is coverage: a business that provides a health service or trades in personal information is in the scheme regardless of size, and many owners do not realise it until a breach happens. The second is evidence: the urge to "fix" the system fast is exactly what destroys the records the assessment and any regulator will need.
The four steps of a data breach response
The four steps below are the framework the OAIC recommends. They are not always sequential: steps one to three often run at the same time or in quick succession, and in some cases it is appropriate to notify individuals immediately, before containment or assessment is complete.
Contain the breach immediately
Once you discover or suspect a breach, act immediately to limit it. Stop the unauthorised practice, recover the records if you can, or shut down the system that was breached. If shutting the system down is impractical, or would destroy evidence, revoke or change access privileges and fix the weakness in physical or electronic security that allowed the breach.
As you contain, work through a short set of questions:
- Who currently has access to the information?
- Is the information still being shared, disclosed or lost without authorisation?
- What can be done to secure it, or to stop the access or disclosure, and reduce the risk of harm to affected individuals?
Be careful not to destroy evidence while you do this. Logs, back-ups and the compromised system itself may be needed to identify the cause of the breach, to work out who is at risk, and to defend the response later.
Assess whether the breach is notifiable
The assessment is the step that decides what the law requires of you. Under s 26WE of the Act, an eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of, personal information, and a reasonable person would conclude the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates.
The Act sets out the matters to weigh in that assessment in s 26WG: the kind and sensitivity of the information involved, whether it was protected by security measures and how easily those measures could be overcome, and who has obtained, or could obtain, the information. Serious harm is not limited to financial loss. It can include physical, psychological, emotional or reputational harm, and it is assessed objectively, from the perspective of a reasonable person, not from what you believed at the time.
The timing is where most businesses misstep. Under s 26WH, if you are aware of reasonable grounds to suspect that an eligible data breach may have occurred, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware. The clock starts on suspicion, not on confirmation. Document the assessment as you go, including why you reached the conclusion you did, because if the OAIC later investigates, that record is your evidence of a reasonable response.
Remedial action matters here. If you can remove the risk of serious harm, for example by recovering a lost device before the information on it is accessed, or because the data was encrypted, the notification obligations may not arise at all. The OAIC's guidance is explicit that if remedial action successfully prevents a likely risk of serious harm, the NDB notification obligations may not apply.
If your assessment concludes that serious harm is likely, move to step three. If it does not, there is no mandatory notification, but you should still document why and consider whether voluntary notification is appropriate.
Notify the OAIC and affected individuals
If you become aware of reasonable grounds to believe an eligible data breach has happened, the Act requires two things. Under s 26WK you must prepare a statement and give a copy to the Commissioner as soon as practicable. The statement must set out your identity and contact details, a description of the breach, the kinds of information concerned, and recommendations about the steps individuals should take in response. Under s 26WL you must also notify the affected individuals, taking reasonable steps to tell each person whose information is involved, or who is at risk. Where it is not practicable to notify individuals individually, you must publish the statement on your website and take reasonable steps to publicise it.
Notification is not something to delay while you perfect the statement. The OAIC's guidance notes that in some cases it may be appropriate to notify individuals immediately, before containment or assessment is complete, and that notification gives people the practical chance to change passwords, watch for scams and protect their accounts. Notification can also protect your goodwill, by showing that you take privacy seriously.
A few qualifications. The Commissioner can direct an entity to notify even where the entity does not believe the breach is eligible. There are limited circumstances in which notification is not required, including where remedial action has removed the risk of serious harm, and where notifying would prejudice a law enforcement investigation, in which case it is appropriate to consult the investigating agency before making details public. And if the NDB scheme does not apply to you at all, notification is still often the right call as a matter of good practice, because it lets affected people protect themselves and limits reputational damage.
Review and remediate
Once the immediate response is over, review the incident and use it to strengthen your handling of personal information. The OAIC recommends a security review including a root cause analysis, a prevention plan for similar incidents, audits to confirm the plan is implemented, a review of your policies and procedures, changes to employee selection and training, and a review of any service providers involved in the breach.
Look for signs of previous incidents. If similar breaches have happened before, that points to a systemic problem in your processes rather than a one-off mistake, and it is the kind of pattern a regulator will treat seriously. If you did not have a data breach response plan before, this is the time to draft one, and to train staff in it. You should also consider whether to report the incident to other bodies: the ACSC for cyber incidents, the police where a crime is suspected, and sector regulators such as ASIC or APRA where the breach involves financial services.
Where businesses get held up
Most stalled responses come down to one of four mistakes:
- Waiting for certainty before starting the assessment: The 30-day clock in s 26WH starts as soon as you are aware of reasonable grounds to suspect an eligible data breach, not when you confirm one. By the time the facts are certain, part of the assessment period may already be gone.
- Destroying evidence while containing: Wiping and rebuilding a compromised system before logs and back-ups are preserved makes the assessment harder and can look like concealment if the OAIC investigates later.
- Misjudging serious harm: Assuming only financial loss counts, or that a small amount of data means no risk, leads to under-notification and penalty exposure. Notifying every trivial incident, by contrast, causes unnecessary anxiety and desensitises people to real warnings.
- Stopping after notification: Skipping the review means the same weakness can cause a second breach, and the pattern of repeat incidents is something regulators weigh heavily.
When you need a lawyer
Legal help is usually worth engaging at two points: during the assessment, and if the OAIC becomes involved. A privacy lawyer can help you work through the serious harm test against the s 26WG factors, decide whether notification is mandatory or voluntary, and draft the statement required by s 26WK so it meets the statutory content requirements without overstating what happened. If the OAIC investigates, a lawyer can respond to the Commissioner's requests for information, deal with a direction to notify, and negotiate enforceable undertakings or determinations.
The stakes justify the help. A serious or repeated interference with privacy is a civil penalty provision, and under s 13G a body corporate can face a penalty of up to $50 million, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover, whichever is greatest. Individuals can face penalties of up to $2.5 million, and other interferences carry penalties of up to 2,000 penalty units. A lawyer can also coordinate your cyber insurer, manage cross-border obligations such as the GDPR's 72-hour rule, and protect legal professional privilege over any forensic investigation reports you commission.
The 30-day clock starts on suspicion
The single factor that most determines whether a data breach response succeeds is how quickly and seriously you treat a suspected breach, not a confirmed one. The assessment obligation in s 26WH, and its 30-day timeframe, are triggered by reasonable grounds to suspect an eligible data breach, and everything else follows from the quality of that assessment: whether it is documented, whether it weighs the s 26WG factors properly, and whether it is completed while the evidence is still intact. Get that right and the notification step, if it is required, is straightforward. Get it wrong, and you face the penalties and reputational damage the scheme exists to prevent.
If a breach happens, work through the four steps: contain it without destroying evidence, assess the risk of serious harm within the 30-day window, notify the OAIC and affected individuals if an eligible data breach is likely, and review your processes so it does not happen again. Not every breach is notifiable, but every breach should be treated seriously, documented, and learned from, and getting legal advice on the assessment early, before conclusions are committed to paper, makes the response far easier to defend.