What Is a Notifiable Data Breach? What Australian Businesses Must Do
A notifiable data breach is a data breach likely to cause serious harm to someone whose personal information is involved. Covered organisations must assess suspected breaches within 30 days and notify the OAIC and affected people as soon as practicable.
Written and reviewed by The Technology Office · Independent technology advisory
Key takeaways
- An eligible data breach involves personal information, is likely to cause serious harm, and has not been neutralised by prompt remedial action.
- Suspected breaches must be assessed within 30 days; eligible breaches must be notified to the OAIC and affected individuals as soon as practicable.
- The NDB scheme has no general 72-hour deadline, although other regimes such as APRA's CPS 234 can impose one.
- Most businesses under $3 million turnover are still exempt at the time of writing, but several categories are covered regardless of size.
The short answer
Under Australia's Notifiable Data Breaches (NDB) scheme, an eligible data breach occurs when personal information is lost, or accessed or disclosed without authorisation; the breach is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that harm through remedial action. Covered organisations must assess a suspected breach within 30 days and, if it is eligible, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
Who does the NDB scheme apply to?
The scheme is part of the Privacy Act 1988 and has applied since February 2018. It covers organisations and agencies with obligations to protect personal information under the Act, including:
- Australian Government agencies
- businesses and not-for-profits with annual turnover of more than $3 million
- certain smaller businesses regardless of turnover, such as private sector health service providers, credit reporting bodies, credit providers, and businesses that trade in personal information
- small businesses that hold tax file number information, for breaches involving that information
- since 1 July 2026, businesses that became reporting entities under the expanded anti-money laundering regime, for their AML/CTF activities
What about the small business exemption?
At the time of writing, most businesses with turnover of $3 million or less remain exempt from the Privacy Act. The Government has agreed in principle to remove the exemption, but that change has not yet been legislated. Separately, the statutory tort for serious invasions of privacy, in force since June 2025, applies regardless of business size. Many smaller organisations follow the NDB process voluntarily because customers, partners, and insurers expect it.
What counts as an eligible data breach?
Work through three questions:
- Was there a data breach? Personal information was accessed or disclosed without authorisation, or lost in circumstances where that is likely to happen. Examples include a hacked database, a stolen laptop, an email sent to the wrong recipient, or a misconfigured cloud folder.
- Is serious harm likely? Consider the kind and sensitivity of the information, whether it was protected (for example, encrypted), who may have obtained it, and the nature of the potential harm, which can be physical, psychological, emotional, financial, or reputational.
- Did remedial action remove the risk? If you act quickly enough that serious harm is no longer likely, for example recovering a lost device before it is accessed, the breach may not be notifiable. Document your reasoning either way.
Is there a 72-hour deadline in Australia?
Not under the NDB scheme. Unlike the European GDPR's 72-hour rule, the Privacy Act requires a reasonable and expeditious assessment of a suspected breach within 30 days, and notification as soon as practicable once there are reasonable grounds to believe an eligible breach has occurred.
Other obligations may apply alongside it and set shorter timeframes, for example:
- APRA-regulated entities must notify APRA of material information security incidents within 72 hours under Prudential Standard CPS 234
- critical infrastructure entities have separate cyber incident reporting obligations under the Security of Critical Infrastructure Act 2018
- businesses with annual turnover over $3 million that make a ransomware or cyber extortion payment must report it to ASD within 72 hours
Check your insurance policy and customer contracts too. Both often require prompt notice.
What should you do if you suspect a data breach?
The OAIC's guidance describes four key steps: contain, assess, notify, and review.
- Contain. Stop further access or disclosure: reset credentials, isolate affected systems, recall misdirected emails, or disable compromised accounts. Preserve evidence for later investigation.
- Assess. Establish what information was involved, whose it was, how sensitive it is, and whether serious harm is likely. Complete the assessment within 30 days, and sooner where possible.
- Notify. If the breach is eligible, lodge a statement with the OAIC using its online form and notify affected individuals directly. If direct notification is not practicable, publish the statement on your website and take reasonable steps to publicise it.
- Review. Identify the root cause, fix control gaps, update your response plan, and brief leadership and the board.
What must a notification include?
- your organisation's name and contact details
- a description of the data breach
- the kinds of personal information involved
- recommendations about the steps individuals should take in response
Where personal information is held jointly, for example by you and a cloud or IT provider, only one entity needs to notify. The OAIC suggests this is generally the entity with the most direct relationship with the affected individuals. Agree who does what in your supplier contracts before an incident.
What are the penalties?
Failing to assess or notify an eligible breach is an interference with privacy. Penalties have been tiered since reforms took effect in December 2024. For the most serious interferences, the maximum civil penalty for a company can reach the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover for the relevant period. In practice, response effort, customer trust, and management time often cost more than any penalty.
How do you prepare before a breach happens?
- Know your data. Keep a simple register of the personal information you hold, where it is stored, and who can access it.
- Write and test a response plan. Name who assesses a breach, who decides on notification, who communicates, and who contacts insurers and suppliers.
- Hold less. Information you have securely deleted cannot be breached. Review retention periods.
- Strengthen baseline controls. Multi-factor authentication, patching, restricted admin access, and tested backups, as set out in the Essential Eight, reduce both the likelihood and impact of many breaches.
- Check supplier contracts. Require prompt breach notification from IT and cloud providers and clarify responsibilities.
- Rehearse. A short tabletop exercise with executives exposes gaps faster than any document review.
Where to get help
If a breach is under way, IT crisis management support can coordinate containment, suppliers, and executive decisions. For preparation, IT governance and risk consulting can build the response plan and board reporting. Not-for-profits may also find the NFP cyber incident response guide useful.
This article is general information, not legal advice. Seek legal advice on the circumstances of any specific breach.
Frequently asked questions
What is an eligible data breach?
A loss of, or unauthorised access to or disclosure of, personal information that is likely to result in serious harm to one or more individuals, where the organisation has not been able to prevent that harm through remedial action.
How long do you have to report a data breach in Australia?
Under the NDB scheme you must assess a suspected breach within 30 days, and notify the OAIC and affected individuals as soon as practicable once you believe it is eligible. There is no general 72-hour deadline, although other regimes may set one.
Does the NDB scheme apply to small businesses?
Most businesses with turnover of $3 million or less are exempt, but some are covered regardless of size, including private sector health service providers, credit reporting bodies, businesses that trade in personal information, and, since 1 July 2026, AML/CTF reporting entities for those activities.
Do you have to report a breach if serious harm is unlikely?
Only breaches likely to result in serious harm are notifiable. If prompt remedial action removes the likelihood of serious harm, notification may not be required, but you should document the assessment.
How do you notify the OAIC of a data breach?
Use the OAIC's online Notifiable Data Breach form. You must also notify affected individuals directly or, if that is not practicable, publish a statement on your website and take reasonable steps to publicise it.
Sources and further reading
- About the Notifiable Data Breaches scheme — Office of the Australian Information Commissioner
- Part 4: Notifiable Data Breach (NDB) Scheme — Office of the Australian Information Commissioner
- Data breach preparation and response — Office of the Australian Information Commissioner
- Report a data breach — Office of the Australian Information Commissioner
Mentioned services
These service and regional NSW pages expand on the topics covered in this article.
Need help applying this?
Bring in senior technology leadership without the full-time overhead.
The Technology Office works with Sydney and regional NSW businesses on embedded CIO support, Head of IT leadership, governance, vendor management, cost optimisation, crisis stabilisation, and no-cost technology reviews as a lighter first step.