Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches (NDB) scheme has fundamentally changed how organisations across the country handle personal information. Since taking effect in February 2018 under the Privacy Act 1988, the scheme requires eligible entities to notify individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. With record-breaking penalties introduced in late 2022 and further reforms rolling through 2024 and 2025, understanding your obligations has never been more important.
This guide breaks down everything Australian businesses, not-for-profits, and public sector agencies need to know about the Australian data breach notification scheme, from the assessment process to reporting timelines, penalties, and practical steps you can take today.
What Is the Australian Data Breach Notification Scheme?
The Australian data breach notification scheme, formally known as the Notifiable Data Breaches (NDB) scheme, is a legal framework under Part IIIC of the Privacy Act 1988 (Cth) that requires organisations to report eligible data breaches. An eligible data breach occurs when there is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any of the individuals to whom the information relates.
The scheme is administered by the OAIC and applies to entities already covered by the Australian Privacy Principles (APPs). It exists to give affected individuals the opportunity to protect themselves — for example, by changing passwords, cancelling cards, or monitoring for identity theft — as quickly as possible after a breach is identified.
Key Objectives of the Scheme
- Enhance transparency around how organisations handle personal information
- Empower affected individuals to mitigate harm from breaches
- Strengthen community trust in data handling practices
- Encourage stronger security and privacy governance across the economy
Who Must Comply With the NDB Scheme?
The NDB scheme applies to all entities that have existing obligations under the Australian Privacy Principles. This includes a broad range of organisations, not just large corporations.
Entities Covered
- Australian Government agencies at the federal level
- Businesses and not-for-profits with an annual turnover of more than $3 million
- Private sector health service providers (regardless of turnover)
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Entities that trade in personal information
- Contracted service providers for Australian Government contracts
It's worth noting that the small business exemption (organisations under the $3 million turnover threshold) is currently under review as part of ongoing Privacy Act reform. Draft legislation released in 2024 flagged the eventual removal of this exemption, which would bring hundreds of thousands of additional Australian businesses under the scheme.
What Counts as an Eligible Data Breach?
Not every security incident triggers a notification obligation. Under the scheme, three conditions must be met for a breach to be "eligible":
- Unauthorised access, unauthorised disclosure, or loss of personal information held by the entity
- The breach is likely to result in serious harm to one or more individuals
- The entity has not been able to prevent the likely risk of serious harm through remedial action
Examples of Common Eligible Breaches
- A cyber attacker gains access to a customer database containing names, addresses, and identification documents
- A laptop containing unencrypted client health records is stolen from an employee's car
- A staff member accidentally emails a spreadsheet of superannuation account details to the wrong recipient
- A misconfigured cloud storage bucket exposes employee payroll data to the public internet
- Ransomware encrypts records and threat actors exfiltrate personal information before deployment
What "Serious Harm" Means
Serious harm isn't defined exhaustively in the Act, but the OAIC considers a range of factors, including:
- The kind and sensitivity of the information involved
- Whether the information is protected by security measures such as encryption
- The persons or kinds of persons who have obtained or could obtain the information
- The nature of the harm — physical, psychological, emotional, financial, or reputational
- The likelihood that identifiers such as passwords could be used maliciously
The 30-Day Assessment Timeline
When an entity has reasonable grounds to suspect that an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment within 30 calendar days. If, at any point during that period, the entity has reasonable grounds to believe a breach has occurred, it must notify immediately — the full 30 days is not a grace period to delay reporting.
Recommended Assessment Steps
- Initiate: Trigger the incident response plan and assemble the response team
- Contain: Take immediate steps to limit further unauthorised access or disclosure
- Investigate: Identify what data was affected, how, and who might be impacted
- Evaluate: Determine whether serious harm is likely and whether remediation can prevent it
- Decide: Formally document the outcome — notifiable or not — with reasoning
How to Notify: OAIC and Affected Individuals
Once you conclude that an eligible data breach has occurred, notification must happen "as soon as practicable." There are two audiences you must consider.
Notifying the OAIC
Entities must lodge a statement with the Australian Information Commissioner using the online Notifiable Data Breach form. The statement must contain:
- The identity and contact details of the entity
- A description of the breach
- The kind or kinds of information involved
- Recommendations about the steps individuals should take in response
Notifying Affected Individuals
You have three options for notifying individuals:
- Option 1: Notify all individuals whose information was involved in the breach
- Option 2: Notify only those individuals at likely risk of serious harm
- Option 3: If neither option is practicable, publish the statement on your website and take reasonable steps to publicise it
Penalties for Non-Compliance
The consequences of ignoring the NDB scheme became dramatically more serious in December 2022, when Parliament passed the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 in response to the Optus and Medibank incidents.
| Breach Type | Maximum Penalty (Body Corporate) | Maximum Penalty (Individuals) |
|---|---|---|
| Serious or repeated interference with privacy | The greater of: $50 million; three times the value of benefit obtained; or 30% of adjusted turnover for the relevant period | $2.5 million |
| Failure to notify an eligible data breach | Civil penalties, enforceable undertakings, infringement notices | Civil penalties applicable |
| Failure to comply with an OAIC determination | Court-ordered damages and compensation | Court-ordered damages |
Beyond direct financial penalties, organisations face reputational damage, class action litigation, ASX disclosure obligations for listed companies, and significant remediation costs. The 2022 Medibank breach, for example, triggered a class action, an OAIC investigation, and estimated remediation costs exceeding $126 million.
Recent Trends in Australian Data Breaches
The OAIC publishes biannual Notifiable Data Breach reports that reveal important patterns. Recent editions consistently highlight:
- Malicious or criminal attacks account for the majority of reported breaches (typically 65–70%)
- Human error remains the second most common cause (around 25–30%)
- Health service providers, finance, and government consistently rank as the most-affected sectors
- Contact information and identity details are the most commonly compromised data types
- Phishing remains the leading initial attack vector
High-Profile Australian Breaches
- Optus (2022): Approximately 9.8 million customer records exposed via an unsecured API endpoint
- Medibank (2022): Health records of 9.7 million current and former customers exfiltrated and later published
- Latitude Financial (2023): Personal data of around 14 million customers, including historical drivers' licence numbers
- MediSecure (2024): Ransomware incident affecting the e-prescription provider
Building an NDB-Ready Response Plan
Compliance with the Australian data breach notification scheme starts long before an incident. A well-tested data breach response plan is one of the most valuable investments an organisation can make.
Essential Components of a Response Plan
- Clear roles and responsibilities — designate a response leader, legal counsel, communications lead, and IT/security representatives
- Detection and reporting channels — internal mechanisms for staff to escalate suspected incidents quickly
- Assessment procedures — decision trees aligned with the OAIC's serious harm criteria
- Containment playbooks — pre-approved actions for common scenarios (ransomware, credential theft, misdirected email)
- Notification templates — draft statements for the OAIC and individuals, ready for customisation
- Stakeholder communications plans — for media, regulators, partners, and affected customers
- Post-incident review — structured lessons-learned process feeding into continuous improvement
Practical Security Measures That Reduce Breach Risk
Prevention remains the best strategy. The OAIC expects entities to take "reasonable steps" under APP 11 to protect personal information. Consider layering the following controls.
Technical Controls
- Multi-factor authentication for all remote and privileged access
- Encryption of data at rest and in transit
- Regular patching and vulnerability management aligned with the ACSC Essential Eight
- Network segmentation to limit lateral movement
- Encrypted DNS resolvers and private browsers for staff handling sensitive matters
- Continuous logging, monitoring, and endpoint detection and response (EDR)
- Secure link sharing tools such as Lunyb when distributing URLs internally or externally, so that click activity and referrers on sensitive resources can be monitored and controlled
Organisational Controls
- Privacy impact assessments for new projects
- Data minimisation — only collect and retain what you genuinely need
- Vendor and supply chain due diligence
- Regular staff training focused on phishing recognition and safe data handling
- Documented data retention and secure destruction schedules
How the NDB Scheme Compares Internationally
Australia's regime shares DNA with other major privacy frameworks but has some distinguishing features.
| Feature | Australia (NDB) | EU (GDPR) | UK (UK GDPR) | USA (State laws) |
|---|---|---|---|---|
| Regulator | OAIC | National DPAs | ICO | State AGs |
| Notification threshold | Likely serious harm | Risk to rights and freedoms | Risk to rights and freedoms | Varies by state |
| Regulator deadline | As soon as practicable | 72 hours | 72 hours | Varies (often 30–90 days) |
| Individual notice | Required if serious harm likely | Required if high risk | Required if high risk | Generally required |
| Maximum corporate penalty | $50M / 30% turnover | €20M / 4% turnover | £17.5M / 4% turnover | Varies significantly |
Ongoing Privacy Act Reform
The Australian privacy landscape is in active reform. The Privacy and Other Legislation Amendment Act 2024 introduced tranche one reforms, including a statutory tort for serious invasions of privacy, new rules on automated decision-making, and enhanced enforcement powers. Further tranches are expected to address the small business exemption, consent standards, direct rights of action for individuals, and stronger requirements around "fair and reasonable" data handling.
Organisations should assume the compliance bar will keep rising and design their privacy programs to be adaptable rather than minimum-compliant.
Related Reading
- Is Lunyb Legit? An Honest Review of the URL Shortener in 2026
- Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide
- Rebrandly Review 2026: Is It Worth the Price?
Frequently Asked Questions
Does the NDB scheme apply to small businesses under $3 million turnover?
Generally no — the small business exemption in the Privacy Act means most organisations with annual turnover under $3 million are not covered. However, exceptions apply, including private sector health service providers, credit reporting bodies, TFN recipients, and entities that trade in personal information. Further, the Privacy Act reform process is expected to remove or narrow this exemption in coming years, so small businesses should not become complacent.
How quickly must I notify the OAIC after discovering a breach?
You must notify "as soon as practicable" after forming a reasonable belief that an eligible data breach has occurred. If you only suspect a breach, you have up to 30 days to complete an assessment — but you must act expeditiously within that period, and immediately notify once belief is formed. Unlike GDPR's rigid 72-hour rule, Australia's timeline is principles-based, but delays without justification can attract enforcement action.
What happens if I decide a breach isn't notifiable but the OAIC disagrees?
The OAIC has the power to direct an entity to notify individuals if it disagrees with the entity's assessment. Failing to comply with such a direction is a serious matter and can attract civil penalties. This is why documenting your assessment reasoning is critical — you need to be able to demonstrate that your decision was reasonable and well-founded.
Do I need to notify overseas individuals affected by an Australian breach?
Yes. The NDB scheme's notification obligations extend to all individuals whose personal information was involved in the breach and who are at likely risk of serious harm, regardless of their country of residence. You may also have additional obligations under foreign laws such as the GDPR if EU residents are affected, so coordinated legal review is essential for cross-border incidents.
Are cyber attacks the only cause of notifiable breaches?
No. While malicious cyber attacks are the leading cause reported to the OAIC, human error accounts for a significant share of notifications each reporting period. This includes misdirected emails, incorrect disclosure of personal information, unintended release of data via unsecured systems, and loss of physical devices or paperwork. A comprehensive privacy program must address both technical and human risk factors.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
A complete 2026 guide to privacy rights in Canada, from PIPEDA and Quebec's Law 25 to the upcoming Consumer Privacy Protection Act under Bill C-27. Learn what rights individuals hold, what organisations must do to comply, and how to enforce your privacy.
UK Data Protection Act vs GDPR Explained: Key Differences for 2026
Confused about how the UK Data Protection Act 2018, UK GDPR, and EU GDPR fit together? This guide breaks down the key differences, overlaps, and compliance duties UK organisations face in 2026, with a practical checklist and comparison table.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ in consent rules, individual rights, breach timelines, and penalties. This guide compares the two frameworks and outlines what Singapore businesses need to stay compliant with both.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn exactly how to file a data protection complaint with the DPC Ireland — from gathering evidence and contacting the organisation first, to submitting the webform and understanding the investigation process. A step-by-step 2026 guide.