facebook-pixel

Australian Data Breach Notification Scheme: Complete Compliance Guide

L
Lunyb Security Team
··8 min read

The Australian Data Breach Notification Scheme — formally known as the Notifiable Data Breaches (NDB) scheme — is one of the most important privacy obligations facing organisations operating in Australia today. Whether you run a small e-commerce store, manage a healthcare practice, or lead IT security for an ASX-listed enterprise, understanding when and how to notify a data breach is no longer optional. Following major reforms in 2022 and continued enforcement action by the Office of the Australian Information Commissioner (OAIC), the stakes have never been higher.

This comprehensive guide explains everything you need to know about the scheme: who it applies to, what counts as an eligible data breach, notification timelines, penalties for non-compliance, and practical steps to prepare your organisation.

What Is the Australian Data Breach Notification Scheme?

The Notifiable Data Breaches (NDB) scheme is a legal framework under Part IIIC of the Privacy Act 1988 (Cth) that requires certain Australian organisations to notify affected individuals and the OAIC when a data breach is likely to result in serious harm. The scheme commenced on 22 February 2018 and has become a cornerstone of Australian privacy law.

The scheme exists to give individuals the opportunity to take protective action — such as changing passwords, monitoring financial accounts, or requesting credit report freezes — when their personal information has been compromised. It also promotes transparency and accountability across the Australian economy.

Legislative Background

The NDB scheme is administered by the OAIC and enforced by the Australian Information Commissioner. It operates alongside the 13 Australian Privacy Principles (APPs), which set out how personal information must be handled. Following the high-profile Optus, Medibank, and Latitude Financial breaches, the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 dramatically increased maximum penalties, signalling a new era of stricter enforcement.

Who Must Comply With the NDB Scheme?

The scheme applies to any entity that has obligations under the Privacy Act to safeguard personal information. This includes:

  • Australian Government agencies (federal departments and statutory bodies)
  • Businesses and not-for-profits with annual turnover above AUD $3 million
  • Private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Contractors that provide services under a Commonwealth contract

Importantly, smaller businesses under the $3 million threshold may still be covered if they handle sensitive categories of data. The upcoming Privacy Act reforms are expected to remove the small business exemption entirely, meaning organisations of all sizes should prepare now.

What Is an Eligible Data Breach?

An eligible data breach occurs when three conditions are met simultaneously:

  1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by an entity.
  2. The access, disclosure, or loss is likely to result in serious harm to one or more affected individuals.
  3. The entity has been unable to prevent the likely risk of serious harm through remedial action.

Understanding "Serious Harm"

Serious harm is not defined exhaustively in the Act, but the OAIC considers factors including:

  • Physical, psychological, emotional, financial, or reputational harm
  • The type and sensitivity of the information involved (health, financial, identity documents)
  • Whether the information is protected by security measures such as encryption
  • The nature and number of people who could access the data
  • The likelihood the information will be misused

Examples of breaches likely to cause serious harm include leaks of Medicare numbers, passport details, banking credentials, or combinations of identifying information that enable identity theft.

Notification Obligations and Timelines

When an eligible data breach occurs, organisations have strict obligations under the scheme. Here is the standard process:

  1. Assess suspected breaches within 30 days. If you suspect an eligible data breach may have occurred, you must carry out a reasonable and expeditious assessment within 30 calendar days to determine whether it qualifies.
  2. Contain the breach. Take immediate steps to limit further unauthorised access or disclosure.
  3. Notify the OAIC as soon as practicable. Submit a statement through the OAIC's online Notifiable Data Breach form.
  4. Notify affected individuals. Communicate directly with those whose information was compromised, or if that is not practicable, publish a notice on your website.
  5. Document everything. Maintain records of the breach, assessment process, and remediation actions.

What the Notification Must Contain

Your statement to the OAIC and affected individuals must include:

  • The identity and contact details of your organisation
  • A description of the breach
  • The kinds of information involved
  • Recommendations about steps individuals should take in response

Penalties for Non-Compliance

The penalties under the amended Privacy Act are among the most severe in Australian regulatory history. For serious or repeated interferences with privacy, corporate entities can face maximum penalties of the greater of:

Penalty TierMaximum Amount
Fixed monetary penaltyAUD $50 million
Three times the value of any benefit obtained from the misuse of informationVariable
30% of the entity's adjusted turnover in the relevant periodVariable (uncapped)

Individuals can also face civil penalties of up to AUD $2.5 million. Beyond financial penalties, non-compliance can trigger investigations, enforceable undertakings, class action lawsuits, and severe reputational damage.

Recent High-Profile Breaches and Lessons Learned

Australia has experienced several landmark breaches that shaped enforcement priorities:

Optus (September 2022)Approximately 9.8 million customer records were exposed, including passport and driver's licence numbers. The incident triggered legislative reform and remains subject to ongoing class action litigation.

Medibank (October 2022)

Sensitive health records of 9.7 million current and former customers were stolen and published on the dark web. The OAIC commenced civil penalty proceedings in 2024.

Latitude Financial (March 2023)

Around 14 million customer records, including historical driver's licence numbers dating back to 2005, were compromised — raising serious questions about data retention practices.

The common lessons: retain only what you need, encrypt sensitive data, enforce multi-factor authentication, and audit third-party access regularly.

How to Prepare Your Organisation

Compliance is not just about reacting to breaches — it requires proactive governance. Here is a practical preparation checklist:

  1. Conduct a data mapping exercise. Know exactly what personal information you hold, where it lives, and who can access it.
  2. Establish a data breach response plan. Document roles, escalation paths, and communication templates before an incident occurs.
  3. Train staff regularly. Human error remains the leading cause of breaches in Australia.
  4. Implement technical controls. Encryption at rest and in transit, MFA, network segmentation, and regular patching are baseline expectations.
  5. Review third-party vendors. Contractual clauses should require immediate notification of any suspected breach.
  6. Test your response. Run tabletop exercises simulating ransomware, credential compromise, and insider threats.
  7. Minimise data collection. Only collect what is necessary and delete it when no longer required.

Secure Link Sharing and Communication

Sharing sensitive information — even internally — is often a weak point. When distributing links to internal documents, customer portals, or breach response resources, using a privacy-respecting link management tool such as Lunyb can help track access, apply expiration dates, and reduce the risk of unauthorised link sharing. For a broader comparison of secure link platforms, see our 2026 buyer's guide to URL shorteners.

The Future: Privacy Act Reform

The Australian Government is progressing a significant tranche of Privacy Act reforms following the 2022 review. Expected changes include:

  • Removal of the small business exemption
  • Introduction of a statutory tort for serious invasions of privacy
  • Shorter mandatory notification timeframes (potentially 72 hours, aligning with GDPR)
  • Enhanced rights for individuals, including a right to erasure
  • Stricter requirements for automated decision-making transparency

Organisations should treat these reforms as inevitable and begin adjusting their privacy programs now rather than waiting for the legislation to pass.

Comparing Australia to Global Frameworks

FrameworkNotification DeadlineMaximum Penalty
Australia (NDB)As soon as practicable (30-day assessment window)AUD $50m / 30% turnover
EU (GDPR)72 hours€20m / 4% global turnover
United States (state-by-state)Varies (typically 30-60 days)Varies significantly
Singapore (PDPA)72 hours (severe breaches)SGD $1m or 10% turnover

Frequently Asked Questions

Does the NDB scheme apply to small businesses?

Currently, most businesses with annual turnover under AUD $3 million are exempt, though exceptions apply (health providers, credit reporting bodies, TFN recipients, and businesses trading in personal information). Proposed reforms are expected to abolish this exemption, so all Australian businesses should prepare.

How quickly must I notify the OAIC of a breach?

You must notify "as soon as practicable" after you become aware of an eligible data breach. You have up to 30 days to assess whether a suspected breach qualifies, but once confirmed, notification should be immediate. Delays without justification can attract enforcement action.

What if I'm not sure whether a breach is "eligible"?

Conduct a documented assessment considering the type of data, likelihood of misuse, protective measures in place, and potential harm. When in doubt, err on the side of notification. The OAIC generally responds more favourably to over-reporting than to organisations that fail to notify legitimate breaches.

Can I avoid notification if I take remedial action?

Yes. If you take action quickly enough that serious harm to affected individuals is no longer likely — for example, by remotely wiping a lost device before data is accessed — the breach may not be "eligible" and notification may not be required. However, this exception is narrowly interpreted.

Are encrypted data breaches notifiable?

If personal information is protected by strong encryption and the encryption keys were not compromised, the risk of serious harm may be significantly reduced, potentially removing the notification obligation. However, encryption alone is not an automatic exemption — a full assessment is still required.

Conclusion

The Australian Data Breach Notification Scheme reflects a broader global shift toward transparency, accountability, and individual empowerment in the digital economy. With penalties now reaching tens of millions of dollars and further reforms on the horizon, Australian organisations can no longer treat privacy compliance as a back-office function. It is a board-level risk that demands strategic investment.

By understanding your obligations, mapping your data, preparing a robust response plan, and building a culture of privacy-by-design, you can protect not only your customers but also your organisation's reputation and long-term viability. When breaches do occur — and statistically they will — a well-prepared response can be the difference between a manageable incident and an existential crisis.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles