Australian Data Breach Notification Scheme: The Complete 2026 Guide
The Australian Data Breach Notification Scheme—officially the Notifiable Data Breaches (NDB) scheme—has fundamentally reshaped how organisations across Australia respond to cyber incidents. Since coming into force in February 2018 under the Privacy Act 1988, the scheme requires eligible entities to notify both affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. With recent reforms increasing penalties into the tens of millions of dollars, understanding this framework is no longer optional for Australian businesses.
This guide walks you through everything you need to know: who the scheme applies to, what constitutes a notifiable breach, the exact steps to take when one occurs, and how to build a compliance programme that stands up to regulatory scrutiny.
What Is the Australian Data Breach Notification Scheme?
The Notifiable Data Breaches (NDB) scheme is an Australian law that requires organisations covered by the Privacy Act 1988 to notify individuals and the OAIC when a data breach is likely to cause serious harm. Introduced through the Privacy Amendment (Notifiable Data Breaches) Act 2017, it applies from 22 February 2018 onwards.
The scheme's core objective is transparency. Before its introduction, Australian organisations were not legally obligated to disclose breaches, meaning individuals often had no idea their personal information had been compromised. The NDB scheme changed that, aligning Australia with international standards such as the EU's GDPR and various US state notification laws.
Key Legislative Framework
- Privacy Act 1988 (Cth) — the primary legislation
- Australian Privacy Principles (APPs) — 13 principles governing personal information handling
- Privacy Amendment (Notifiable Data Breaches) Act 2017 — introduced Part IIIC of the Privacy Act
- Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 — dramatically increased penalties
Who Must Comply With the NDB Scheme?
The scheme applies to "APP entities," which is a broader category than many businesses realise. If your organisation must comply with the Australian Privacy Principles, you are also bound by the NDB scheme.
Entities Covered
- Australian Government agencies
- Businesses and not-for-profits with an annual turnover of more than AUD $3 million
- All private sector health service providers (regardless of turnover)
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Entities that trade in personal information
- Contracted service providers for Commonwealth contracts
Small Business Exemption
Businesses with turnover under $3 million are generally exempt, though there are notable exceptions. If you're a small business that handles health information, provides services to the Commonwealth, or trades in personal data, the scheme applies regardless of size. The Australian Government has flagged reforms that may remove this exemption entirely, so smaller organisations should prepare for potentially broader coverage.
What Qualifies as a Notifiable Data Breach?
A notifiable data breach occurs when three conditions are met: there is unauthorised access, disclosure, or loss of personal information; the incident is likely to result in serious harm to affected individuals; and the entity has been unable to prevent that harm through remedial action.
The "Serious Harm" Test
Serious harm can include physical, psychological, emotional, financial, or reputational damage. The OAIC assesses likelihood using several factors:
- The kind and sensitivity of the information involved
- Whether the information was protected by security measures such as encryption
- The persons or types of persons who could obtain the information
- The nature of the harm that could result
- Any other relevant matters
Common Examples of Notifiable Breaches
- Lost or stolen laptops, USBs, or mobile devices containing unencrypted personal information
- Cyber attacks resulting in access to customer databases
- Employee misuse or unauthorised access to customer records
- Personal information mistakenly sent to the wrong recipient
- Ransomware attacks where data exfiltration is suspected
- Compromised login credentials on business systems
Notification Timelines and Requirements
The NDB scheme sets strict timelines for both assessment and notification, and missing them can attract regulatory action.
The 30-Day Assessment Window
When you become aware of a suspected eligible data breach, you have 30 calendar days to complete a reasonable and expeditious assessment. If assessment confirms an eligible breach, notification must occur "as soon as practicable."
What Must Be Included in a Notification
| Required Element | Details |
|---|---|
| Entity identity and contact | Name and contact details of the organisation |
| Description of breach | What happened, when, and how |
| Information involved | Types of personal information compromised |
| Recommended steps | Actions individuals should take to protect themselves |
| OAIC notification | Statement submitted via OAIC's online form |
How to Notify Individuals
Organisations have three notification options:
- Option 1: Notify each individual whose information was involved
- Option 2: Notify only those at likely risk of serious harm
- Option 3: Publish the notification on your website and take reasonable steps to publicise it (only if options 1 and 2 are not practicable)
Penalties for Non-Compliance
The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 dramatically increased penalties following the Optus and Medibank breaches. For serious or repeated interferences with privacy, penalties for corporations can now reach:
- AUD $50 million, or
- Three times the value of any benefit obtained from the conduct, or
- 30% of the entity's adjusted turnover in the relevant period
Whichever is greater applies. For individuals, penalties can reach AUD $2.5 million. Beyond financial penalties, the OAIC can issue enforceable undertakings, seek civil penalty orders, and initiate representative complaints on behalf of affected individuals.
Building an NDB-Compliant Response Plan
A robust Data Breach Response Plan is your best defence against both breaches themselves and regulatory scrutiny. Here's a step-by-step framework:
Step 1: Contain the Breach
Immediately limit further unauthorised access. This might include disabling compromised accounts, isolating affected systems from the network, revoking access tokens, or shutting down specific services temporarily.
Step 2: Assess the Risk
Assemble a response team including IT security, legal, privacy officers, and executive leadership. Document what information was involved, how many individuals are affected, and the likelihood of serious harm.
Step 3: Notify If Required
If the breach qualifies as notifiable, prepare the statement for the OAIC and communications for affected individuals. Clear, plain-language communication reduces reputational damage.
Step 4: Review and Remediate
Conduct a post-incident review. Identify root causes—was it a phishing attack, misconfigured cloud storage, weak credentials, or an insider threat? Update policies, controls, and training accordingly.
Practical Security Measures to Reduce Breach Risk
Prevention is dramatically cheaper than notification. Consider these controls as foundational elements of NDB compliance:
Technical Controls
- Encryption of data at rest and in transit (particularly for laptops, backups, and databases)
- Multi-factor authentication (MFA) on all business-critical accounts
- Encrypted DNS and secure network configurations
- Endpoint detection and response (EDR) tools
- Regular patching and vulnerability management
- Access controls based on least privilege
Administrative Controls
- Written Data Breach Response Plan reviewed annually
- Privacy Impact Assessments for new projects
- Staff training on phishing and social engineering
- Vendor risk management for third-party processors
- Data minimisation—only collect what you need
Safer Link Sharing
Many breaches begin with a click. Whenever your organisation shares links externally—in marketing emails, customer communications, or campaigns—using a reputable link management platform such as Lunyb lets you monitor, revoke, and audit link activity in ways raw URLs never allow. This visibility supports both incident detection and post-breach analysis. If you're evaluating options, our guide on the best URL shorteners reviewed and compared for 2026 provides a detailed comparison.
How the NDB Scheme Compares Internationally
| Feature | Australia (NDB) | EU (GDPR) | USA (State Laws) |
|---|---|---|---|
| Notification deadline | As soon as practicable (30-day assessment) | 72 hours to regulator | Varies (often 30–60 days) |
| Threshold | Likely serious harm | Risk to rights and freedoms | Varies by state |
| Maximum penalty | AUD $50M / 30% turnover | €20M / 4% turnover | Varies widely |
| Regulator | OAIC | National DPAs | State AGs / FTC |
Recent Trends and Enforcement Priorities
The OAIC publishes six-monthly Notifiable Data Breaches Reports that reveal enforcement patterns. Key trends observed in recent reporting periods include:
- Malicious or criminal attacks remain the leading cause of breaches (~65%)
- Human error accounts for roughly 25–30% of breaches
- Health service providers consistently top the industry breach rankings
- Finance, education, and government follow closely
- Cyber incidents involving ransomware and compromised credentials are increasing sharply
The OAIC has become notably more assertive since the 2022 amendments, launching investigations into high-profile breaches and pursuing civil penalty proceedings against organisations that fail to protect personal information adequately.
Preparing for Future Reforms
The Privacy Act Review Report released by the Attorney-General's Department proposes significant changes that will affect NDB compliance:
- Removal of the small business exemption
- A statutory tort for serious invasions of privacy
- Direct rights of action for individuals
- Enhanced OAIC investigative powers
- 72-hour notification timeline aligned with GDPR
- Stricter consent and transparency requirements
Organisations should begin preparing now, even if final legislation is pending. Building processes that can meet a 72-hour timeline is significantly harder than adapting existing 30-day workflows retrospectively.
Frequently Asked Questions
Do I have to notify the OAIC before affected individuals?
No, notification to the OAIC and affected individuals should generally happen at the same time. Both must occur "as soon as practicable" after determining that an eligible data breach has occurred. There is no requirement to notify one before the other.
What if I'm unsure whether a breach is notifiable?
You have up to 30 days to conduct a reasonable and expeditious assessment. During this period, document your assessment process thoroughly. If you conclude the breach is not notifiable, retain evidence of that determination. If you cannot complete the assessment in 30 days, you should notify as if it were an eligible breach.
Are small businesses exempt from the NDB scheme?
Generally, businesses with annual turnover under AUD $3 million are exempt from the Privacy Act and therefore the NDB scheme. However, exceptions apply to health service providers, credit reporting bodies, TFN recipients, and businesses that trade in personal information. Proposed reforms may remove the small business exemption entirely.
What happens if I notify late or not at all?
Failing to notify a notifiable data breach is a serious interference with privacy. The OAIC can issue infringement notices, seek enforceable undertakings, or pursue civil penalties of up to AUD $50 million for corporations. Beyond regulatory penalties, non-notification typically causes far greater reputational damage when the breach eventually becomes public.
Does the scheme cover overseas data breaches affecting Australians?
Yes. The Privacy Act has extraterritorial reach. If an overseas entity has an Australian link—such as carrying on business in Australia and collecting personal information from within Australia—it must comply with the NDB scheme regardless of where the breach physically occurs.
Final Thoughts
The Australian Data Breach Notification Scheme is more than a compliance obligation—it's a framework for building trust with customers, employees, and partners. Organisations that treat it as a checkbox exercise expose themselves to enormous financial and reputational risk. Those that embed privacy and security into their operational DNA turn it into a competitive advantage.
Start with a written response plan, invest in preventive controls, train your people, and review your practices annually. With penalties now reaching tens of millions of dollars and reforms tightening the framework further, the cost of inaction has never been higher. The good news? The steps required to comply are also the steps required to run a resilient, modern Australian business.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: A Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 introduces sweeping new duties for platforms, from scam link interception to deepfake labelling. This complete guide explains who must comply, the seven categories of harmful content, penalties, and practical compliance steps for businesses and users.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal information but take very different approaches to consent, enforcement, and individual rights. This guide compares the two frameworks and explains what Canadian businesses need to know for 2026 compliance.
UK Data Protection Act vs GDPR Explained: Key Differences in 2026
The UK Data Protection Act 2018 and GDPR work together to protect personal data in Britain, but they are not identical. This guide explains the differences, shared principles, and what UK businesses must do to stay compliant in 2026.
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland eight powerful privacy rights, from accessing your data to demanding its deletion. This guide explains each right, how to exercise them, and how to complain to the Irish Data Protection Commission when companies get it wrong.