facebook-pixel

Australian Data Breach Notification Scheme: Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Australia's Notifiable Data Breaches (NDB) scheme has fundamentally changed how organisations across the country handle personal information. Since taking effect in February 2018 under the Privacy Act 1988, the scheme requires eligible entities to notify individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. With record-breaking penalties introduced in late 2022 and further reforms rolling through 2024 and 2025, understanding your obligations has never been more important.

This guide breaks down everything Australian businesses, not-for-profits, and public sector agencies need to know about the Australian data breach notification scheme, from the assessment process to reporting timelines, penalties, and practical steps you can take today.

What Is the Australian Data Breach Notification Scheme?

The Australian data breach notification scheme, formally known as the Notifiable Data Breaches (NDB) scheme, is a legal framework under Part IIIC of the Privacy Act 1988 (Cth) that requires organisations to report eligible data breaches. An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any of the individuals to whom the information relates.

The scheme is administered by the OAIC and applies to entities already covered by the Australian Privacy Principles (APPs). It exists to give affected individuals the opportunity to protect themselves — for example, by changing passwords, cancelling cards, or monitoring for identity theft — as quickly as possible after a breach is identified.

Key Objectives of the Scheme

  • Enhance transparency around how organisations handle personal information
  • Empower affected individuals to mitigate harm from breaches
  • Strengthen community trust in data handling practices
  • Encourage stronger security and privacy governance across the economy

Who Must Comply With the NDB Scheme?

The NDB scheme applies to all entities that have existing obligations under the Australian Privacy Principles. This includes a broad range of organisations, not just large corporations.

Entities Covered

  • Australian Government agencies at the federal level
  • Businesses and not-for-profits with an annual turnover of more than $3 million
  • Private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Contracted service providers for Australian Government contracts

It's worth noting that the small business exemption (organisations under the $3 million turnover threshold) is currently under review as part of ongoing Privacy Act reform. Draft legislation released in 2024 flagged the eventual removal of this exemption, which would bring hundreds of thousands of additional Australian businesses under the scheme.

What Counts as an Eligible Data Breach?

Not every security incident triggers a notification obligation. Under the scheme, three conditions must be met for a breach to be "eligible":

  1. Unauthorised access, unauthorised disclosure, or loss of personal information held by the entity
  2. The breach is likely to result in serious harm to one or more individuals
  3. The entity has not been able to prevent the likely risk of serious harm through remedial action

Examples of Common Eligible Breaches

  • A cyber attacker gains access to a customer database containing names, addresses, and identification documents
  • A laptop containing unencrypted client health records is stolen from an employee's car
  • A staff member accidentally emails a spreadsheet of superannuation account details to the wrong recipient
  • A misconfigured cloud storage bucket exposes employee payroll data to the public internet
  • Ransomware encrypts records and threat actors exfiltrate personal information before deployment

What "Serious Harm" Means

Serious harm isn't defined exhaustively in the Act, but the OAIC considers a range of factors, including:

  • The kind and sensitivity of the information involved
  • Whether the information is protected by security measures such as encryption
  • The persons or kinds of persons who have obtained or could obtain the information
  • The nature of the harm — physical, psychological, emotional, financial, or reputational
  • The likelihood that identifiers such as passwords could be used maliciously

The 30-Day Assessment Timeline

When an entity has reasonable grounds to suspect that an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment within 30 calendar days. If, at any point during that period, the entity has reasonable grounds to believe a breach has occurred, it must notify immediately — the full 30 days is not a grace period to delay reporting.

Recommended Assessment Steps

  1. Initiate: Trigger the incident response plan and assemble the response team
  2. Contain: Take immediate steps to limit further unauthorised access or disclosure
  3. Investigate: Identify what data was affected, how, and who might be impacted
  4. Evaluate: Determine whether serious harm is likely and whether remediation can prevent it
  5. Decide: Formally document the outcome — notifiable or not — with reasoning

How to Notify: OAIC and Affected Individuals

Once you conclude that an eligible data breach has occurred, notification must happen "as soon as practicable." There are two audiences you must consider.

Notifying the OAIC

Entities must lodge a statement with the Australian Information Commissioner using the online Notifiable Data Breach form. The statement must contain:

  • The identity and contact details of the entity
  • A description of the breach
  • The kind or kinds of information involved
  • Recommendations about the steps individuals should take in response

Notifying Affected Individuals

You have three options for notifying individuals:

  1. Option 1: Notify all individuals whose information was involved in the breach
  2. Option 2: Notify only those individuals at likely risk of serious harm
  3. Option 3: If neither option is practicable, publish the statement on your website and take reasonable steps to publicise it

Penalties for Non-Compliance

The consequences of ignoring the NDB scheme became dramatically more serious in December 2022, when Parliament passed the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 in response to the Optus and Medibank incidents.

Breach TypeMaximum Penalty (Body Corporate)Maximum Penalty (Individuals)
Serious or repeated interference with privacyThe greater of: $50 million; three times the value of benefit obtained; or 30% of adjusted turnover for the relevant period$2.5 million
Failure to notify an eligible data breachCivil penalties, enforceable undertakings, infringement noticesCivil penalties applicable
Failure to comply with an OAIC determinationCourt-ordered damages and compensationCourt-ordered damages

Beyond direct financial penalties, organisations face reputational damage, class action litigation, ASX disclosure obligations for listed companies, and significant remediation costs. The 2022 Medibank breach, for example, triggered a class action, an OAIC investigation, and estimated remediation costs exceeding $126 million.

Recent Trends in Australian Data Breaches

The OAIC publishes biannual Notifiable Data Breach reports that reveal important patterns. Recent editions consistently highlight:

  • Malicious or criminal attacks account for the majority of reported breaches (typically 65–70%)
  • Human error remains the second most common cause (around 25–30%)
  • Health service providers, finance, and government consistently rank as the most-affected sectors
  • Contact information and identity details are the most commonly compromised data types
  • Phishing remains the leading initial attack vector

High-Profile Australian Breaches

  • Optus (2022): Approximately 9.8 million customer records exposed via an unsecured API endpoint
  • Medibank (2022): Health records of 9.7 million current and former customers exfiltrated and later published
  • Latitude Financial (2023): Personal data of around 14 million customers, including historical drivers' licence numbers
  • MediSecure (2024): Ransomware incident affecting the e-prescription provider

Building an NDB-Ready Response Plan

Compliance with the Australian data breach notification scheme starts long before an incident. A well-tested data breach response plan is one of the most valuable investments an organisation can make.

Essential Components of a Response Plan

  1. Clear roles and responsibilities — designate a response leader, legal counsel, communications lead, and IT/security representatives
  2. Detection and reporting channels — internal mechanisms for staff to escalate suspected incidents quickly
  3. Assessment procedures — decision trees aligned with the OAIC's serious harm criteria
  4. Containment playbooks — pre-approved actions for common scenarios (ransomware, credential theft, misdirected email)
  5. Notification templates — draft statements for the OAIC and individuals, ready for customisation
  6. Stakeholder communications plans — for media, regulators, partners, and affected customers
  7. Post-incident review — structured lessons-learned process feeding into continuous improvement

Practical Security Measures That Reduce Breach Risk

Prevention remains the best strategy. The OAIC expects entities to take "reasonable steps" under APP 11 to protect personal information. Consider layering the following controls.

Technical Controls

  • Multi-factor authentication for all remote and privileged access
  • Encryption of data at rest and in transit
  • Regular patching and vulnerability management aligned with the ACSC Essential Eight
  • Network segmentation to limit lateral movement
  • Encrypted DNS resolvers and private browsers for staff handling sensitive matters
  • Continuous logging, monitoring, and endpoint detection and response (EDR)
  • Secure link sharing tools such as Lunyb when distributing URLs internally or externally, so that click activity and referrers on sensitive resources can be monitored and controlled

Organisational Controls

  • Privacy impact assessments for new projects
  • Data minimisation — only collect and retain what you genuinely need
  • Vendor and supply chain due diligence
  • Regular staff training focused on phishing recognition and safe data handling
  • Documented data retention and secure destruction schedules

How the NDB Scheme Compares Internationally

Australia's regime shares DNA with other major privacy frameworks but has some distinguishing features.

FeatureAustralia (NDB)EU (GDPR)UK (UK GDPR)USA (State laws)
RegulatorOAICNational DPAsICOState AGs
Notification thresholdLikely serious harmRisk to rights and freedomsRisk to rights and freedomsVaries by state
Regulator deadlineAs soon as practicable72 hours72 hoursVaries (often 30–90 days)
Individual noticeRequired if serious harm likelyRequired if high riskRequired if high riskGenerally required
Maximum corporate penalty$50M / 30% turnover€20M / 4% turnover£17.5M / 4% turnoverVaries significantly

Ongoing Privacy Act Reform

The Australian privacy landscape is in active reform. The Privacy and Other Legislation Amendment Act 2024 introduced tranche one reforms, including a statutory tort for serious invasions of privacy, new rules on automated decision-making, and enhanced enforcement powers. Further tranches are expected to address the small business exemption, consent standards, direct rights of action for individuals, and stronger requirements around "fair and reasonable" data handling.

Organisations should assume the compliance bar will keep rising and design their privacy programs to be adaptable rather than minimum-compliant.

Related Reading

Frequently Asked Questions

Does the NDB scheme apply to small businesses under $3 million turnover?

Generally no — the small business exemption in the Privacy Act means most organisations with annual turnover under $3 million are not covered. However, exceptions apply, including private sector health service providers, credit reporting bodies, TFN recipients, and entities that trade in personal information. Further, the Privacy Act reform process is expected to remove or narrow this exemption in coming years, so small businesses should not become complacent.

How quickly must I notify the OAIC after discovering a breach?

You must notify "as soon as practicable" after forming a reasonable belief that an eligible data breach has occurred. If you only suspect a breach, you have up to 30 days to complete an assessment — but you must act expeditiously within that period, and immediately notify once belief is formed. Unlike GDPR's rigid 72-hour rule, Australia's timeline is principles-based, but delays without justification can attract enforcement action.

What happens if I decide a breach isn't notifiable but the OAIC disagrees?

The OAIC has the power to direct an entity to notify individuals if it disagrees with the entity's assessment. Failing to comply with such a direction is a serious matter and can attract civil penalties. This is why documenting your assessment reasoning is critical — you need to be able to demonstrate that your decision was reasonable and well-founded.

Do I need to notify overseas individuals affected by an Australian breach?

Yes. The NDB scheme's notification obligations extend to all individuals whose personal information was involved in the breach and who are at likely risk of serious harm, regardless of their country of residence. You may also have additional obligations under foreign laws such as the GDPR if EU residents are affected, so coordinated legal review is essential for cross-border incidents.

Are cyber attacks the only cause of notifiable breaches?

No. While malicious cyber attacks are the leading cause reported to the OAIC, human error accounts for a significant share of notifications each reporting period. This includes misdirected emails, incorrect disclosure of personal information, unintended release of data via unsecured systems, and loss of physical devices or paperwork. A comprehensive privacy program must address both technical and human risk factors.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles