Australian Data Breach Notification Scheme: Complete 2026 Compliance Guide
The Australian Data Breach Notification Scheme — formally known as the Notifiable Data Breaches (NDB) scheme — is one of the most important privacy compliance obligations facing Australian organisations today. Since taking effect on 22 February 2018 under Part IIIC of the Privacy Act 1988, the scheme has fundamentally changed how businesses respond to cyber incidents, lost devices, and unauthorised data disclosures. With penalties now reaching up to $50 million per breach following the 2022 amendments, understanding and complying with the NDB scheme is no longer optional.
This guide explains exactly what the scheme requires, who it applies to, when notification is triggered, and how your organisation can build a defensible response plan.
What Is the Notifiable Data Breaches (NDB) Scheme?
The Notifiable Data Breaches scheme is an Australian federal law requiring covered entities to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. It is administered by the OAIC and enforced under the Privacy Act 1988.
The scheme was introduced to create transparency around data breaches, empower affected individuals to protect themselves, and encourage stronger security practices across the economy. Before 2018, notification was voluntary and inconsistent — many Australians never learned that their personal information had been compromised.
Key Objectives of the Scheme
- Ensure individuals are informed when their personal information has been compromised in a way that may cause them serious harm
- Give affected people the chance to mitigate damage (change passwords, monitor accounts, place credit alerts)
- Encourage organisations to invest in preventive security controls
- Provide the OAIC with visibility into national breach trends
Who Must Comply With the NDB Scheme?
The NDB scheme applies to all entities already covered by the Australian Privacy Principles (APPs) under the Privacy Act. If your organisation must comply with the APPs, you must comply with the NDB scheme.
Covered Entities Include:
- Australian Government agencies (federal departments and most statutory bodies)
- Businesses and not-for-profits with annual turnover above $3 million
- Private sector health service providers (regardless of turnover) — including medical practices, gyms, pharmacies, and allied health
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Entities that trade in personal information (buy or sell customer lists)
- Contracted service providers for Australian Government contracts
Small businesses under the $3 million turnover threshold are generally exempt, but exceptions apply for the categories above. The federal government has also signalled its intention to remove the small business exemption entirely as part of upcoming Privacy Act reforms.
What Counts as a Notifiable Data Breach?
Not every security incident triggers notification. A breach is only "notifiable" when three conditions are met simultaneously.
The Three-Part Test
- There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by the entity
- The access, disclosure or loss is likely to result in serious harm to one or more individuals
- The entity has not been able to prevent the likely risk of serious harm through remedial action
Examples of Data Breaches
- A cybercriminal successfully exfiltrates a customer database via ransomware or SQL injection
- An employee emails a spreadsheet of client records to the wrong recipient
- A laptop or USB drive containing unencrypted personal information is lost or stolen
- Paper records are left in a public place or disposed of insecurely
- Credentials are compromised through phishing, giving an attacker access to a CRM
- A misconfigured cloud storage bucket exposes files to the public internet
Understanding "Serious Harm"
The concept of "serious harm" is central to the scheme, but the Privacy Act deliberately does not define it exhaustively. Serious harm may include physical, psychological, emotional, financial, or reputational harm to an individual.
Factors the OAIC Considers
- The kind and sensitivity of the information (health records and financial data are highly sensitive)
- Whether the information is protected by security measures such as encryption
- The persons who have obtained or could obtain the information
- The likelihood those persons have the intention of causing harm
- The nature of the harm that could occur
A leaked list of publicly available business email addresses is unlikely to cause serious harm. A leaked spreadsheet containing Medicare numbers, dates of birth, and driver's licence details almost certainly will.
Notification Timeline and Process
Once you suspect a breach may have occurred, strict timelines apply. The scheme uses a two-stage process: assessment, then notification.
Step 1: Assessment (Maximum 30 Days)
If you have reasonable grounds to suspect an eligible data breach may have occurred but are not yet certain, you must carry out a reasonable and expeditious assessment within 30 calendar days. The OAIC expects most assessments to be completed much faster.
Step 2: Notification (As Soon as Practicable)
If the assessment confirms an eligible data breach, you must notify both the OAIC and affected individuals as soon as practicable. There is no fixed hour count, but delays of more than a few days without justification will attract regulatory scrutiny.
Required Content of a Notification
- The identity and contact details of the organisation
- A description of the data breach
- The kinds of information involved
- Recommendations about the steps individuals should take in response
Notification Methods
There are three permitted ways to notify affected individuals under section 26WL of the Privacy Act.
| Method | When to Use | Requirements |
|---|---|---|
| Option 1: Notify all individuals | When you can identify everyone affected | Direct communication via email, SMS, phone, or post |
| Option 2: Notify only those at risk of serious harm | When you can identify the specific subset at risk | Direct communication to the identified subset |
| Option 3: Publish a statement | When direct notification is impracticable | Publish on website + take reasonable steps to publicise |
Penalties for Non-Compliance
Penalties under the Privacy Act were dramatically increased in December 2022 following the Optus and Medibank breaches. Non-compliance is now a serious financial risk.
Maximum Penalties for Serious or Repeated Interferences with Privacy
- For corporations: The greater of $50 million, three times the value of any benefit obtained from the misuse of information, or 30% of adjusted turnover during the breach period
- For individuals: Up to $2.5 million
Beyond financial penalties, the OAIC has expanded investigative and enforcement powers, including the ability to require entities to prepare and publish statements about their conduct.
Exceptions to Notification
The Privacy Act provides limited exceptions where notification is not required, even for an eligible breach.
Main Exceptions
- Remedial action: If you take action quickly enough that serious harm is no longer likely (e.g. remote-wiping a lost laptop before it is accessed)
- Multi-party breaches: If another entity involved in the same breach has already provided compliant notification
- Enforcement bodies: Where notification would prejudice an enforcement-related activity
- Inconsistency with secrecy provisions: Where another Commonwealth law prohibits disclosure
- OAIC declaration: Where the Commissioner has declared that notification is not required
Building an NDB Response Plan
The OAIC strongly recommends every covered entity maintain a documented data breach response plan. Here is a practical framework.
1. Contain
- Immediately isolate affected systems or accounts
- Revoke compromised credentials and rotate keys
- Preserve logs and forensic evidence
2. Assess
- Identify what data was involved and how many individuals are affected
- Determine the cause and extent of the incident
- Evaluate the likelihood of serious harm using OAIC criteria
3. Notify
- Prepare notifications to the OAIC and affected individuals
- Use the OAIC's online Notifiable Data Breach form
- Coordinate messaging with legal, PR, and executive teams
4. Review
- Conduct a post-incident review
- Update policies, controls, and training
- Test the updated response plan through tabletop exercises
Preventing Data Breaches in the First Place
Notification is a last resort. The real goal is preventing breaches through layered security controls.
Foundational Controls
- Encryption: Encrypt data at rest and in transit. Encrypted data lost on a device may not trigger notification
- Access control: Enforce least-privilege access and multi-factor authentication on every account
- Patching: Apply security updates promptly, guided by the ACSC Essential Eight
- Staff training: Phishing simulations and privacy awareness training reduce human error, still the leading cause of Australian breaches
- Vendor management: Audit third parties handling personal information — many notified breaches originate with suppliers
- Secure link handling: Where you share URLs containing sensitive parameters, use a privacy-respecting shortener like Lunyb to avoid leaking data through referrer headers or shared analytics platforms
Watch Your Marketing and Tracking Stack
Many breaches in Australia have involved third-party marketing tools inadvertently collecting or exposing personal information. Audit the trackers on your website, the shorteners embedded in your emails, and the analytics scripts running in your app. For a review of privacy-focused link tools, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
Recent Trends in Australian Breach Reporting
The OAIC publishes six-monthly Notifiable Data Breaches Reports. Consistent trends have emerged across recent reporting periods:
- Malicious or criminal attacks account for roughly two-thirds of notified breaches
- Health service providers are consistently the most-breached sector, followed by finance
- Phishing and compromised credentials remain the top attack vectors
- Contact information and identity information are the most commonly exposed data types
- Ransomware notifications continue to rise year-on-year
Upcoming Privacy Act Reforms
The Australian Government has committed to sweeping Privacy Act reforms, many of which will affect the NDB scheme directly. Expected changes include:
- Removal of the small business exemption, dramatically expanding coverage
- A statutory tort for serious invasions of privacy
- Shorter mandatory notification timeframes (a 72-hour standard has been proposed, aligning with GDPR)
- Enhanced children's privacy protections
- New rights to erasure, objection, and de-indexing
Organisations should treat current compliance as a baseline and prepare for tighter obligations within the next reform cycle.
Frequently Asked Questions
Do I need to notify the OAIC if the breach affects only one person?
Yes. The NDB scheme applies whenever an eligible data breach is likely to result in serious harm to one or more individuals. There is no minimum threshold on the number of affected people.
How long do I have to notify after discovering a breach?
You have up to 30 days to assess whether a suspected breach is notifiable. Once confirmed as an eligible data breach, you must notify the OAIC and affected individuals as soon as practicable — typically within days, not weeks. Upcoming reforms may reduce this to 72 hours.
Does encryption exempt me from notifying?
Not automatically, but strong encryption is a critical factor. If lost or stolen data was properly encrypted and the decryption key was not compromised, serious harm may no longer be likely, meaning notification may not be required. Document your encryption standards to support this position.
What happens if I fail to notify when I should have?
Failure to comply with the NDB scheme is an interference with privacy under the Privacy Act. The OAIC can investigate, issue determinations, seek enforceable undertakings, or pursue civil penalties of up to $50 million for corporations for serious or repeated contraventions.
Do overseas businesses need to comply with the Australian NDB scheme?
Yes, if they have an "Australian link" — for example, carrying on business in Australia and collecting or holding personal information about Australians. Many global platforms fall within scope even without a local office, especially after 2022 amendments strengthened extraterritorial reach.
Final Thoughts
The Australian Data Breach Notification Scheme is more than a legal checkbox — it is a framework for treating personal information as a genuine responsibility rather than a business asset. With penalties now measured in tens of millions of dollars, and reforms set to expand coverage further, every Australian organisation handling personal information should have a documented response plan, tested incident procedures, and preventive controls aligned to the ACSC Essential Eight.
The organisations that fare best when a breach occurs are not those that avoid incidents entirely — they are those that detect quickly, assess honestly, notify transparently, and demonstrate genuine care for the individuals affected.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.