1. Who the scheme applies to
  2. What makes a breach notifiable
  3. The response sequence
    1. Contain and assess within 30 days
    2. Notify the OAIC
    3. Notify the affected individuals
    4. Where the Commissioner steps in
  4. What happens if you get it wrong
  5. Where businesses commonly trip up
  6. When to bring in a privacy lawyer
  7. The assessment window is where the outcome is decided

Every year Australian businesses lose, misplace or have stolen personal information about their customers. When that happens, the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth) (the Act) decides whether the business must tell anyone about it. The scheme has been in force since 22 February 2018 and applies to data breaches that occur on or after that date.

The scheme exists because of a simple problem. If a business loses control of personal information, the affected individuals are the only people who can actually protect themselves, by changing passwords, watching for identity fraud and cancelling compromised cards. They can only do that if they are told. The NDB scheme forces the organisations and government agencies covered by the Act to notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals when a breach meets the statutory test.

This article explains how the scheme operates end to end: who is covered, what triggers a notification, the assessment and notification steps, and what happens when a business gets it wrong. For most small to medium businesses the scheme becomes relevant the moment a laptop goes missing, an email goes to the wrong recipient or a contractor's system is compromised.

Who the scheme applies to

The NDB scheme applies to APP entities, which means Australian Government agencies and private sector organisations bound by the Australian Privacy Principles. In practice, for a business, the starting point is size. An organisation with an annual turnover above $3 million is generally covered, while a small business with turnover of $3 million or less is exempt under s 6D of the Act.

The small business exemption has important carve-outs. A small business is still covered if it is a health service provider, a credit reporting body, or handles certain categories of information such as tax file numbers. The scope of the scheme under s 26WE(1) also expressly reaches credit reporting bodies, credit providers and tax file number recipients, so businesses in those sectors should not assume the turnover test saves them.

The other actor in the scheme is the OAIC. It is the regulator that receives the notifications, investigates incidents, can compel information and can apply to court for civil penalties. The affected individuals are the third actor: the scheme is built around getting information to them so they can act. Where a business, the OAIC and affected individuals all share an interest in a fast and accurate notification, the scheme tends to work well; where a business delays or downplays an incident, those interests collide.

What makes a breach notifiable

Not every incident involving personal information must be reported. The trigger is an eligible data breach as defined in s 26WE(2) of the Act. Three things must be present:

  • there is unauthorised access to, or unauthorised disclosure of, the personal information, or the information is lost in circumstances where unauthorised access or disclosure is likely to occur; and
  • a reasonable person would conclude that the access, disclosure or loss would be likely to result in serious harm to any of the individuals to whom the information relates.

The serious harm test is the heart of the scheme. It is an objective test, applied from the standpoint of a reasonable person, and the standard is likelihood, not possibility. Serious harm can include serious physical, psychological, emotional, financial or reputational harm, and the OAIC's guidance points to factors such as the sensitivity of the information, whether it is encrypted or protected, and what a person could do with it. A lost database of credit card numbers will usually meet the test; a leaked list of names and email addresses with no other identifying detail may not.

Loss counts even if nobody has accessed the information yet. If a USB drive holding customer records disappears, the question is whether unauthorised access is likely and, if so, whether serious harm is likely. If the drive was encrypted and the key was not stored with it, a reasonable person may well conclude that serious harm is not likely.

There is also an escape hatch. Under s 26WF, if the entity takes action before the access or disclosure results in serious harm, and as a result a reasonable person would conclude that serious harm is not likely, the incident is not an eligible data breach at all. Recovering the lost device, remotely wiping it, or changing the credentials exposed in a misdirected email can all neutralise an incident before it becomes notifiable. The action must genuinely head off the harm, not merely be attempted afterwards.

The response sequence

Once an incident occurs, the Act pushes the entity through a defined sequence. Each stage produces something specific, and the timeframes matter.

Contain and assess within 30 days

The clock starts earlier than many businesses expect. Under s 26WH, an entity that is aware there are reasonable grounds to suspect an eligible data breach must carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe one has occurred, and must take all reasonable steps to complete that assessment within 30 days of becoming aware.

Suspicion, not certainty, starts the clock. A support ticket that mentions unusual customer complaints, a fraud alert from a payment provider or a staff report of a missing laptop can all be enough. The assessment is the stage where the entity works out what information was involved, who is at risk, whether the information was protected, and whether remedial action can still prevent serious harm. That last question is important, because an incident successfully neutralised during the assessment is not an eligible data breach at all.

Notify the OAIC

If the assessment concludes that there are reasonable grounds to believe an eligible data breach has happened, the entity must prepare a statement and give a copy to the Commissioner as soon as practicable under s 26WK. The statement must set out the entity's identity and contact details, a description of the breach, the particular kinds of information concerned, and recommendations about the steps individuals should take in response.

There is no fixed deadline beyond "as soon as practicable", but the 30 day assessment cap means the OAIC generally expects to hear about an eligible breach well within that window. In practice, an entity that has completed a careful assessment on day 29 and then delays the notification is inviting questions about why.

Notify the affected individuals

The same statement is the basis for telling individuals. Under s 26WL, the entity must take such steps as are reasonable in the circumstances to notify the contents of the statement to each affected individual, or to each individual at risk from the breach. Direct notification is the rule: email, SMS, letter or phone, depending on what contact details the entity holds and what is reasonable.

If it is not practicable to notify individuals directly, the entity must publish a copy of the statement on its website. That fallback is not a free pass: the entity must first be satisfied that direct notification is genuinely impracticable, and the website publication must still give individuals the recommended steps.

Where the Commissioner steps in

The OAIC is not a passive recipient. Under s 26WR the Commissioner can direct an entity to prepare and give a statement and to notify individuals, even where the entity itself has not concluded that a breach occurred. Under s 26WQ the Commissioner can also declare that notification is not required in particular cases, for example where notification would prejudice a law enforcement investigation. And under s 26WU the Commissioner has power to require an entity to produce information and documents about an actual or suspected eligible data breach.

What happens if you get it wrong

The consequences of failing to notify are more serious than the scheme's early years suggested. A breach of Part IIIC, or a failure to secure personal information in the first place, can be an interference with privacy. For a serious or repeated interference, s 13G of the Act now exposes a body corporate to a maximum civil penalty of the greatest of $50 million, three times the value of any benefit obtained from the conduct, or 30% of the entity's adjusted turnover during the breach period. Non-corporate entities face up to $2.5 million. Other interferences with privacy carry penalties of up to 2,000 penalty units under s 13H.

These figures reflect the Privacy and Other Legislation Amendment Act 2024 (Cth), which received assent on 10 December 2024 and dramatically increased the maximum penalties that had applied since the scheme began. The same Act introduced a statutory tort for serious invasions of privacy, which came into force in late 2025 and gives individuals a direct right to sue, and a Children's Online Privacy Code with its own enforcement regime.

Penalties are not the only cost. The OAIC publishes details of notified breaches, so a notification is a public event that customers, insurers and competitors can all see. A business that notifies properly at least controls the narrative; a business that is investigated for failing to notify faces a regulator that is openly hostile to delay, and an individual affected by the breach may complain to the OAIC or, now, sue directly under the new tort.

Where businesses commonly trip up

The most common failures in the scheme are process failures rather than deliberate concealment:

  • Not recognising that suspicion starts the clock: Many businesses wait for certainty before starting an assessment, burning the 30 days and leaving themselves unable to complete a reasonable assessment in time.
  • Confusing "no harm yet" with "no likely serious harm": The test is prospective and objective. A stolen database does not become safe just because no fraudulent use has been reported.
  • Treating remedial action as an afterthought: The s 26WF exception only applies where action is taken before serious harm occurs and actually changes the reasonable assessment. Attempted recovery after the fact does not unwind the obligation.
  • Assuming encryption solves everything: An encrypted device still requires an assessment of whether access is likely, including whether the encryption key was stored with the device or compromised elsewhere.
  • Forgetting third parties: If a contractor, software provider or mailing house holds the information, it may have its own notification obligations, and the entity that supplied the data may need to notify as well. Contracts that require processors to report incidents to the entity quickly are essential, because a slow processor can eat the entity's 30 day window.
  • Flying without a plan: Entities that respond ad hoc take longer to assess, and delay in notifying is the single most criticised behaviour in OAIC enforcement. A written breach response plan, nominated roles and tested contact procedures make the difference between a 30 day assessment and a scramble.

When to bring in a privacy lawyer

The scheme is technical, and the serious harm assessment is a judgment call that a court or the OAIC may later scrutinise. A privacy lawyer is most useful at three points. Before an incident, a lawyer can confirm whether the business is actually covered, review the breach response plan and the contracts with processors, and advise on cyber insurance. During an incident, a lawyer can help run the assessment within the 30 day window, pressure-test the serious harm analysis, and draft the statement to the OAIC and to affected individuals so it is complete and does not create liability. After an incident, a lawyer can manage the OAIC's information requests, respond to an investigation, and defend any penalty application.

Bringing in legal help early is far cheaper than doing so after a notification has gone wrong. A conversation before an incident, or in the first days of one, can be the difference between an incident that is contained and notified cleanly and one that becomes a penalty, a tort claim and a very public lesson in the scheme's teeth.

The assessment window is where the outcome is decided

Everything that follows in the scheme turns on what happens in the first 30 days. A prompt, well-documented assessment that identifies the information involved, takes genuine remedial action where it can, and notifies as soon as practicable converts a bad incident into a manageable one. A slow or half-hearted assessment converts the same incident into an investigation, a public notification, and potentially a penalty measured in tens of millions of dollars. The business that treats the moment of first suspicion as the moment to act, and that takes advice before the clock runs, is the business the scheme is designed to protect. A no-obligation conversation with a privacy lawyer about whether your business is covered, and how your breach response would hold up, is a small price against the cost of getting it wrong.