facebook-pixel

Australian Data Breach Notification Scheme: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

The Australian Data Breach Notification Scheme—officially the Notifiable Data Breaches (NDB) scheme—has fundamentally reshaped how organisations across Australia respond to cyber incidents. Since coming into force in February 2018 under the Privacy Act 1988, the scheme requires eligible entities to notify both affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. With recent reforms increasing penalties into the tens of millions of dollars, understanding this framework is no longer optional for Australian businesses.

This guide walks you through everything you need to know: who the scheme applies to, what constitutes a notifiable breach, the exact steps to take when one occurs, and how to build a compliance programme that stands up to regulatory scrutiny.

What Is the Australian Data Breach Notification Scheme?

The Notifiable Data Breaches (NDB) scheme is an Australian law that requires organisations covered by the Privacy Act 1988 to notify individuals and the OAIC when a data breach is likely to cause serious harm. Introduced through the Privacy Amendment (Notifiable Data Breaches) Act 2017, it applies from 22 February 2018 onwards.

The scheme's core objective is transparency. Before its introduction, Australian organisations were not legally obligated to disclose breaches, meaning individuals often had no idea their personal information had been compromised. The NDB scheme changed that, aligning Australia with international standards such as the EU's GDPR and various US state notification laws.

Key Legislative Framework

  • Privacy Act 1988 (Cth) — the primary legislation
  • Australian Privacy Principles (APPs) — 13 principles governing personal information handling
  • Privacy Amendment (Notifiable Data Breaches) Act 2017 — introduced Part IIIC of the Privacy Act
  • Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 — dramatically increased penalties

Who Must Comply With the NDB Scheme?

The scheme applies to "APP entities," which is a broader category than many businesses realise. If your organisation must comply with the Australian Privacy Principles, you are also bound by the NDB scheme.

Entities Covered

  • Australian Government agencies
  • Businesses and not-for-profits with an annual turnover of more than AUD $3 million
  • All private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Contracted service providers for Commonwealth contracts

Small Business Exemption

Businesses with turnover under $3 million are generally exempt, though there are notable exceptions. If you're a small business that handles health information, provides services to the Commonwealth, or trades in personal data, the scheme applies regardless of size. The Australian Government has flagged reforms that may remove this exemption entirely, so smaller organisations should prepare for potentially broader coverage.

What Qualifies as a Notifiable Data Breach?

A notifiable data breach occurs when three conditions are met: there is unauthorised access, disclosure, or loss of personal information; the incident is likely to result in serious harm to affected individuals; and the entity has been unable to prevent that harm through remedial action.

The "Serious Harm" Test

Serious harm can include physical, psychological, emotional, financial, or reputational damage. The OAIC assesses likelihood using several factors:

  1. The kind and sensitivity of the information involved
  2. Whether the information was protected by security measures such as encryption
  3. The persons or types of persons who could obtain the information
  4. The nature of the harm that could result
  5. Any other relevant matters

Common Examples of Notifiable Breaches

  • Lost or stolen laptops, USBs, or mobile devices containing unencrypted personal information
  • Cyber attacks resulting in access to customer databases
  • Employee misuse or unauthorised access to customer records
  • Personal information mistakenly sent to the wrong recipient
  • Ransomware attacks where data exfiltration is suspected
  • Compromised login credentials on business systems

Notification Timelines and Requirements

The NDB scheme sets strict timelines for both assessment and notification, and missing them can attract regulatory action.

The 30-Day Assessment Window

When you become aware of a suspected eligible data breach, you have 30 calendar days to complete a reasonable and expeditious assessment. If assessment confirms an eligible breach, notification must occur "as soon as practicable."

What Must Be Included in a Notification

Required ElementDetails
Entity identity and contactName and contact details of the organisation
Description of breachWhat happened, when, and how
Information involvedTypes of personal information compromised
Recommended stepsActions individuals should take to protect themselves
OAIC notificationStatement submitted via OAIC's online form

How to Notify Individuals

Organisations have three notification options:

  1. Option 1: Notify each individual whose information was involved
  2. Option 2: Notify only those at likely risk of serious harm
  3. Option 3: Publish the notification on your website and take reasonable steps to publicise it (only if options 1 and 2 are not practicable)

Penalties for Non-Compliance

The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 dramatically increased penalties following the Optus and Medibank breaches. For serious or repeated interferences with privacy, penalties for corporations can now reach:

  • AUD $50 million, or
  • Three times the value of any benefit obtained from the conduct, or
  • 30% of the entity's adjusted turnover in the relevant period

Whichever is greater applies. For individuals, penalties can reach AUD $2.5 million. Beyond financial penalties, the OAIC can issue enforceable undertakings, seek civil penalty orders, and initiate representative complaints on behalf of affected individuals.

Building an NDB-Compliant Response Plan

A robust Data Breach Response Plan is your best defence against both breaches themselves and regulatory scrutiny. Here's a step-by-step framework:

Step 1: Contain the Breach

Immediately limit further unauthorised access. This might include disabling compromised accounts, isolating affected systems from the network, revoking access tokens, or shutting down specific services temporarily.

Step 2: Assess the Risk

Assemble a response team including IT security, legal, privacy officers, and executive leadership. Document what information was involved, how many individuals are affected, and the likelihood of serious harm.

Step 3: Notify If Required

If the breach qualifies as notifiable, prepare the statement for the OAIC and communications for affected individuals. Clear, plain-language communication reduces reputational damage.

Step 4: Review and Remediate

Conduct a post-incident review. Identify root causes—was it a phishing attack, misconfigured cloud storage, weak credentials, or an insider threat? Update policies, controls, and training accordingly.

Practical Security Measures to Reduce Breach Risk

Prevention is dramatically cheaper than notification. Consider these controls as foundational elements of NDB compliance:

Technical Controls

  • Encryption of data at rest and in transit (particularly for laptops, backups, and databases)
  • Multi-factor authentication (MFA) on all business-critical accounts
  • Encrypted DNS and secure network configurations
  • Endpoint detection and response (EDR) tools
  • Regular patching and vulnerability management
  • Access controls based on least privilege

Administrative Controls

  • Written Data Breach Response Plan reviewed annually
  • Privacy Impact Assessments for new projects
  • Staff training on phishing and social engineering
  • Vendor risk management for third-party processors
  • Data minimisation—only collect what you need

Safer Link Sharing

Many breaches begin with a click. Whenever your organisation shares links externally—in marketing emails, customer communications, or campaigns—using a reputable link management platform such as Lunyb lets you monitor, revoke, and audit link activity in ways raw URLs never allow. This visibility supports both incident detection and post-breach analysis. If you're evaluating options, our guide on the best URL shorteners reviewed and compared for 2026 provides a detailed comparison.

How the NDB Scheme Compares Internationally

FeatureAustralia (NDB)EU (GDPR)USA (State Laws)
Notification deadlineAs soon as practicable (30-day assessment)72 hours to regulatorVaries (often 30–60 days)
ThresholdLikely serious harmRisk to rights and freedomsVaries by state
Maximum penaltyAUD $50M / 30% turnover€20M / 4% turnoverVaries widely
RegulatorOAICNational DPAsState AGs / FTC

Recent Trends and Enforcement Priorities

The OAIC publishes six-monthly Notifiable Data Breaches Reports that reveal enforcement patterns. Key trends observed in recent reporting periods include:

  • Malicious or criminal attacks remain the leading cause of breaches (~65%)
  • Human error accounts for roughly 25–30% of breaches
  • Health service providers consistently top the industry breach rankings
  • Finance, education, and government follow closely
  • Cyber incidents involving ransomware and compromised credentials are increasing sharply

The OAIC has become notably more assertive since the 2022 amendments, launching investigations into high-profile breaches and pursuing civil penalty proceedings against organisations that fail to protect personal information adequately.

Preparing for Future Reforms

The Privacy Act Review Report released by the Attorney-General's Department proposes significant changes that will affect NDB compliance:

  • Removal of the small business exemption
  • A statutory tort for serious invasions of privacy
  • Direct rights of action for individuals
  • Enhanced OAIC investigative powers
  • 72-hour notification timeline aligned with GDPR
  • Stricter consent and transparency requirements

Organisations should begin preparing now, even if final legislation is pending. Building processes that can meet a 72-hour timeline is significantly harder than adapting existing 30-day workflows retrospectively.

Frequently Asked Questions

Do I have to notify the OAIC before affected individuals?

No, notification to the OAIC and affected individuals should generally happen at the same time. Both must occur "as soon as practicable" after determining that an eligible data breach has occurred. There is no requirement to notify one before the other.

What if I'm unsure whether a breach is notifiable?

You have up to 30 days to conduct a reasonable and expeditious assessment. During this period, document your assessment process thoroughly. If you conclude the breach is not notifiable, retain evidence of that determination. If you cannot complete the assessment in 30 days, you should notify as if it were an eligible breach.

Are small businesses exempt from the NDB scheme?

Generally, businesses with annual turnover under AUD $3 million are exempt from the Privacy Act and therefore the NDB scheme. However, exceptions apply to health service providers, credit reporting bodies, TFN recipients, and businesses that trade in personal information. Proposed reforms may remove the small business exemption entirely.

What happens if I notify late or not at all?

Failing to notify a notifiable data breach is a serious interference with privacy. The OAIC can issue infringement notices, seek enforceable undertakings, or pursue civil penalties of up to AUD $50 million for corporations. Beyond regulatory penalties, non-notification typically causes far greater reputational damage when the breach eventually becomes public.

Does the scheme cover overseas data breaches affecting Australians?

Yes. The Privacy Act has extraterritorial reach. If an overseas entity has an Australian link—such as carrying on business in Australia and collecting personal information from within Australia—it must comply with the NDB scheme regardless of where the breach physically occurs.

Final Thoughts

The Australian Data Breach Notification Scheme is more than a compliance obligation—it's a framework for building trust with customers, employees, and partners. Organisations that treat it as a checkbox exercise expose themselves to enormous financial and reputational risk. Those that embed privacy and security into their operational DNA turn it into a competitive advantage.

Start with a written response plan, invest in preventive controls, train your people, and review your practices annually. With penalties now reaching tens of millions of dollars and reforms tightening the framework further, the cost of inaction has never been higher. The good news? The steps required to comply are also the steps required to run a resilient, modern Australian business.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles