facebook-pixel

Australian Data Breach Notification Scheme: Complete Compliance Guide

L
Lunyb Security Team
··10 min read

Since February 2018, Australian organisations have operated under one of the most consequential privacy reforms in the country's history: the Notifiable Data Breaches (NDB) scheme. Administered by the Office of the Australian Information Commissioner (OAIC), the scheme forces entities to confront data breaches head-on — assessing them, containing them, and notifying affected individuals when serious harm is likely. With penalties now reaching into the tens of millions of dollars and public scrutiny at an all-time high, understanding your obligations is not optional.

This guide walks through the Australian data breach notification scheme in practical terms: who it applies to, what triggers a notification obligation, how the 30-day assessment window works, and how to build an incident response plan that keeps your business on the right side of the Privacy Act 1988.

What Is the Australian Data Breach Notification Scheme?

The Notifiable Data Breaches scheme is a legal framework under Part IIIC of the Privacy Act 1988 (Cth) that requires covered Australian entities to notify the OAIC and affected individuals when an eligible data breach occurs. An eligible data breach is one where personal information is subject to unauthorised access, disclosure, or loss, and a reasonable person would conclude the incident is likely to result in serious harm.

The scheme was introduced to bring Australia into line with international privacy standards, giving individuals the ability to take protective steps — changing passwords, monitoring accounts, alerting banks — as soon as their information is compromised.

The Three Elements of an Eligible Data Breach

  1. Unauthorised access, unauthorised disclosure, or loss of personal information held by the entity.
  2. Likely to result in serious harm to one or more individuals whose information is involved.
  3. Remedial action has not prevented the likely risk of serious harm.

If all three elements are present, notification is mandatory. If remedial action successfully removes the likelihood of serious harm, notification is not required — but the assessment must still be documented.

Who Must Comply With the NDB Scheme?

The scheme applies to all entities that already have obligations under the Australian Privacy Principles (APPs). This is a broader group than many small business owners realise.

Covered Entities Include

  • Australian Government agencies
  • Businesses and not-for-profit organisations with an annual turnover of more than A$3 million
  • Private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Contracted service providers to the Australian Government
  • Small businesses that opt-in to be covered by the Privacy Act

Notably, the small business exemption is under active review, and reforms proposed in the Privacy Act review response signal it may be removed entirely in coming years. Businesses currently exempt should still consider voluntary compliance as a preparatory step.

What Counts as "Serious Harm"?

The concept of serious harm is central to the scheme, but the Act deliberately avoids a rigid definition. Instead, the OAIC provides a list of factors organisations must weigh when assessing likelihood.

Types of Serious Harm

  • Physical harm — e.g., disclosure of a domestic violence victim's address
  • Psychological or emotional harm — e.g., exposure of sensitive health or sexuality information
  • Financial harm — e.g., identity theft, fraud, unauthorised transactions
  • Reputational harm — e.g., leaked private communications or images

Assessment Factors

When evaluating a breach, consider:

  • The kind and sensitivity of the information (health, financial, government identifiers rank highest)
  • Whether the information was encrypted or otherwise protected
  • The persons or kinds of persons who obtained or could obtain the information
  • The likelihood the security measures could be overcome
  • The nature of the harm that could result
  • Any other relevant matter

The 30-Day Assessment Window

When an entity has reasonable grounds to suspect that an eligible data breach may have occurred — but is not yet certain — it must conduct a reasonable and expeditious assessment within 30 calendar days. This is one of the most misunderstood elements of the scheme.

Step-by-Step Assessment Process

  1. Initiate the assessment as soon as suspicion arises and document the trigger.
  2. Investigate the scope: what data, how many individuals, how the breach occurred.
  3. Evaluate whether the three elements of an eligible data breach are met.
  4. Consider remedial action — can steps be taken to eliminate the likelihood of serious harm?
  5. Decide and document whether notification is required.
  6. Notify the OAIC and affected individuals as soon as practicable if the breach is eligible.

The 30-day clock is a maximum, not a target. The OAIC expects assessments to be completed "expeditiously" — often much faster where the facts are clear.

Notification Requirements: What Must Be Included

Once you determine a breach is notifiable, you must prepare a statement for the OAIC and communicate with affected individuals as soon as practicable.

Mandatory Contents of the Statement

  • The identity and contact details of your organisation
  • A description of the eligible data breach
  • The kinds of information involved (e.g., names, dates of birth, Medicare numbers)
  • Recommended steps individuals should take in response

Three Options for Notifying Individuals

OptionWhen to UseMethod
Option 1: Notify all individualsWhen you have contact details and it's practicableEmail, letter, phone, SMS
Option 2: Notify only those at risk of serious harmWhen the breach affects a subset of individualsDirect contact with the affected subset
Option 3: Publish the statementWhen direct notification is not practicablePublic website notice plus reasonable steps to publicise

Penalties for Non-Compliance

Following the 2022 Privacy Legislation Amendment Act — passed in the wake of the Optus and Medibank breaches — penalties for serious or repeated interferences with privacy have increased dramatically.

Current Maximum Penalties for Bodies Corporate

The greater of:

  • A$50 million; or
  • Three times the value of any benefit obtained through the misuse of information; or
  • 30% of the entity's adjusted turnover in the relevant period

For individuals, the maximum civil penalty sits at A$2.5 million. Beyond fines, non-compliance risks OAIC investigations, enforceable undertakings, and severe reputational damage that often outstrips the direct financial cost.

Building an NDB-Ready Incident Response Plan

Compliance begins long before a breach occurs. A defensible response depends on preparation, documentation, and rehearsal.

Core Components of an NDB Response Plan

  1. Data inventory — Know what personal information you hold, where, and who can access it.
  2. Response team — Assign roles across legal, IT security, communications, and executive leadership.
  3. Detection capability — Deploy logging, monitoring, and alerting to shorten discovery time.
  4. Assessment playbook — Pre-written templates for the 30-day evaluation.
  5. Containment procedures — Steps to isolate systems, revoke credentials, and preserve evidence.
  6. Notification templates — Draft OAIC statements and individual notice letters ready to customise.
  7. Post-incident review — Root cause analysis and control improvements.

Reducing Breach Risk at the Link Level

Many breaches begin with a phishing link, a leaked internal URL, or credential-harvesting redirects. Using a controlled link management platform such as Lunyb lets teams centralise, monitor, and revoke shared URLs — reducing the surface area for accidental disclosure. For a broader look at how link tooling compares, see our 2026 URL shortener buyer's guide.

Common Breach Scenarios in Australia

The OAIC's biannual reports consistently highlight the same categories of incidents. Understanding them helps prioritise controls.

Breach TypeTypical CausePreventative Control
Malicious or criminal attackPhishing, ransomware, credential theftMFA, staff training, endpoint protection
Human errorEmail sent to wrong recipient, misconfigured cloud storageDLP tooling, mandatory recipient checks, access reviews
System faultSoftware bugs exposing dataSecure SDLC, penetration testing, code review
Insider threatDisgruntled employees, misuse of accessLeast-privilege access, activity monitoring, offboarding controls

Exceptions to the Notification Requirement

Not every eligible data breach must be individually notified. The Privacy Act includes narrow exceptions.

Key Exceptions

  • Enforcement-related activities — where notification would prejudice enforcement actions
  • Inconsistency with secrecy provisions — where other Commonwealth laws prohibit disclosure
  • Multiple entities affected — only one entity needs to notify where several hold the same information
  • Declaration by the Commissioner — the OAIC can grant an exemption in specific circumstances

These exceptions are narrowly interpreted. When in doubt, seek legal advice rather than assume an exception applies.

How the NDB Scheme Interacts With Other Laws

The NDB scheme does not exist in isolation. Depending on your industry and the nature of the data involved, additional notification duties may apply.

  • My Health Records Act 2012 — separate mandatory breach notifications for the My Health Record system
  • Security of Critical Infrastructure Act 2018 (SOCI) — cyber incident reporting for designated critical infrastructure assets
  • APRA CPS 234 — 72-hour information security incident notification for regulated financial entities
  • State and territory privacy laws — additional obligations for state government agencies
  • GDPR — where Australian entities offer goods or services to EU residents

A single incident can trigger multiple parallel notification obligations, each with its own timeframe and content requirements. Your response plan should map them.

The Road Ahead: Privacy Act Reform

The Australian Government's response to the Privacy Act Review Report signalled sweeping changes on the horizon, many of which will tighten the NDB scheme further. Proposed reforms include:

  • A statutory tort for serious invasions of privacy
  • Removing the small business exemption
  • Shorter maximum notification windows (potentially 72 hours to the OAIC)
  • Direct enforcement powers for the OAIC with tiered civil penalties
  • Enhanced rights for individuals, including the right to erasure

Organisations that build robust breach response capabilities now will find the transition to future obligations far less painful.

Frequently Asked Questions

How quickly must I notify the OAIC after discovering a breach?

You must notify "as soon as practicable" after determining an eligible data breach has occurred. The 30-day window applies to the assessment phase — the time you have to decide whether the breach is notifiable. Once that determination is made, delay in notification is not permitted.

Do I need to notify if the compromised data was encrypted?

Not necessarily. If the encryption is strong and the decryption key was not compromised, a reasonable person may conclude that serious harm is unlikely. This can amount to effective remedial action, removing the notification obligation. You still must document the assessment.

What if I'm a small business under the A$3 million turnover threshold?

You are generally exempt from the Privacy Act and the NDB scheme, unless you fall into a covered category (e.g., health service provider, TFN recipient, contractor to the Commonwealth). However, the small business exemption is under active review and expected to be removed. Voluntary compliance is strongly recommended.

Can I be penalised even if I notify on time?

Yes. The NDB scheme addresses notification, but the underlying breach may still constitute a failure to comply with the Australian Privacy Principles — particularly APP 11, which requires reasonable security safeguards. Timely notification is a mitigating factor, not a defence.

What records should I keep after a breach?

Maintain a complete incident file including: the initial trigger and timeline, assessment notes and decision rationale, remedial actions taken, copies of notifications sent, correspondence with the OAIC, and post-incident review findings. Retain these records for at least seven years to support any subsequent inquiry.

Final Thoughts

The Australian data breach notification scheme is more than a compliance checkbox — it is a framework for treating personal information with the seriousness it deserves. Entities that invest in prevention, detection, and well-rehearsed response will not only avoid penalties but also preserve the trust that underpins every customer relationship. With reform on the horizon and enforcement appetite growing, now is the time to audit your data holdings, refresh your incident response plan, and ensure every team member understands their role when a breach unfolds.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles