facebook-pixel

Australian Data Breach Notification Scheme: Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Since February 2018, Australian organisations have operated under one of the region's most consequential privacy regulations: the Notifiable Data Breaches (NDB) scheme. Administered by the Office of the Australian Information Commissioner (OAIC), the scheme establishes clear legal obligations for how and when businesses must respond to serious data breaches. With penalties dramatically increased in 2022 and further reforms rolling through Parliament, understanding your responsibilities under the Australian data breach notification scheme has never been more important.

This guide breaks down what the NDB scheme requires, who it applies to, how to determine whether a breach is notifiable, and the step-by-step process for responding to an incident in line with Australian law.

What Is the Australian Data Breach Notification Scheme?

The Notifiable Data Breaches scheme is a mandatory reporting framework established under Part IIIC of the Privacy Act 1988 (Cth). It requires covered entities to notify affected individuals and the OAIC whenever a data breach is likely to result in serious harm to any person whose personal information is involved.

The scheme applies to "eligible data breaches" — a defined legal term meaning:

  1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by an entity;
  2. The access, disclosure, or loss is likely to result in serious harm to one or more individuals; and
  3. The entity has been unable to prevent the likely risk of serious harm through remedial action.

If all three conditions are met, notification is not optional — it is a legal requirement, generally within 30 days of becoming aware of the breach.

Who Must Comply With the NDB Scheme?

The NDB scheme applies to all entities already covered by the Privacy Act's Australian Privacy Principles (APPs). This includes:

  • Australian Government agencies
  • Businesses and not-for-profit organisations with an annual turnover of more than AUD $3 million
  • Private sector health service providers (regardless of turnover)
  • Credit reporting bodies and credit providers
  • Tax File Number (TFN) recipients
  • Entities that trade in personal information
  • Some small businesses that opt in or are otherwise covered

Notably, small businesses under the $3 million threshold may still be captured if they handle health information, provide services under a Commonwealth contract, or are related to a larger APP entity. The proposed Privacy Act reforms are expected to remove the small business exemption entirely, significantly expanding the scheme's reach.

Does the Scheme Apply to Overseas Organisations?

Yes. The Privacy Act has extraterritorial application under section 5B. Overseas organisations with an "Australian link" — such as collecting personal information from individuals in Australia — must comply with the NDB scheme even if they have no physical presence in the country.

What Counts as "Personal Information" Under the Scheme?

Personal information is broadly defined as information or an opinion about an identified or reasonably identifiable individual. This includes obvious identifiers like names and addresses, but also extends to:

  • Email addresses and phone numbers
  • IP addresses (in many contexts)
  • Financial and credit information
  • Health and medical records
  • Biometric data and photographs
  • Employment details and government identifiers
  • Location data

"Sensitive information" — a subset that includes health data, racial or ethnic origin, political opinions, sexual orientation, and religious beliefs — attracts additional protections and is more likely to trigger a serious harm assessment.

Defining "Serious Harm" — the Key Threshold

The NDB scheme only requires notification when a breach is likely to result in serious harm. This is a legal test, not a subjective judgment, and the OAIC provides detailed guidance on how to assess it.

"Serious harm" can include:

  • Physical harm — such as stalking risk from leaked home addresses
  • Psychological harm — distress, humiliation, or reputational damage
  • Financial harm — identity theft, fraud, or economic loss
  • Emotional harm — anxiety and loss of confidence
  • Reputational harm — damage to standing in the community or workplace

When assessing the likelihood, entities must consider factors such as the kind and sensitivity of information, whether it was encrypted, who obtained it, and whether protections like multi-factor authentication would limit exploitability.

The 30-Day Assessment Window

When an entity suspects an eligible data breach may have occurred but is not yet certain, it has up to 30 calendar days to carry out a reasonable and expeditious assessment. This isn't a grace period to delay action — the OAIC expects entities to move as quickly as possible.

A defensible assessment process typically includes:

  1. Containment — immediately stopping the breach from continuing or expanding
  2. Evaluation — determining what personal information was involved and who is affected
  3. Risk analysis — assessing likelihood and severity of harm
  4. Remediation review — deciding whether action can prevent serious harm
  5. Decision and documentation — recording the outcome and rationale

If the assessment concludes the breach is eligible and remediation cannot eliminate the serious harm risk, notification must occur "as soon as practicable."

Notification Requirements: What You Must Do

Notifying the OAIC

Entities must submit a statement to the Australian Information Commissioner using the online Notifiable Data Breach form. The statement must include:

  • The identity and contact details of the entity
  • A description of the eligible data breach
  • The kinds of information involved
  • Recommendations about the steps individuals should take in response

Notifying Affected Individuals

There are three options for notifying individuals, chosen in order of preference:

  1. Option 1: Notify each individual to whom the information relates
  2. Option 2: Notify only those individuals at likely risk of serious harm
  3. Option 3: If neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it

Notifications should use the entity's usual communication channels (email, letter, SMS) and be written in plain language.

Penalties for Non-Compliance

The 2022 Privacy Legislation Amendment (Enforcement and Other Measures) Act significantly increased maximum penalties for serious or repeated privacy interferences. The current penalty framework is set out below.

Entity TypeMaximum Penalty (per contravention)
IndividualsAUD $2.5 million
Body corporate — greater of:AUD $50 million, OR
3× the benefit obtained from the misuse of information, OR
30% of adjusted turnover in the relevant period

Beyond financial penalties, the OAIC now has expanded enforcement powers including infringement notices, enforceable undertakings, and the ability to conduct assessments and investigations. Reputational damage from public breach announcements often exceeds the direct regulatory cost.

Exceptions to the Notification Requirement

Not every breach triggers notification. Key exceptions include:

  • Remedial action exception — if the entity acts quickly enough that serious harm becomes unlikely
  • Enforcement body exception — where notification would prejudice enforcement activities
  • Inconsistency with secrecy provisions — where another law prohibits disclosure
  • Multi-party breaches — only one entity needs to notify if multiple hold the same information

Building an NDB-Compliant Response Plan

Regulators consistently emphasise that preparation is the strongest defence. A robust data breach response plan should include the following elements.

1. A Designated Response Team

Assign clear roles across legal, IT security, communications, executive leadership, and privacy. Every member should know their responsibilities before a breach occurs.

2. Incident Classification Procedures

Document how incidents are categorised, escalated, and assessed against the eligible data breach test.

3. Containment and Forensic Capabilities

Either in-house or via retainer, ensure you can quickly isolate compromised systems and preserve evidence.

4. Communication Templates

Prepare draft notifications for individuals, regulators, media, and internal stakeholders. These should be reviewed by legal counsel in advance.

5. Post-Incident Review Process

Every breach — notifiable or not — should feed back into security improvements and staff training.

Reducing Breach Risk: Practical Security Measures

The best breach response is one you never have to execute. Australian organisations should consider layered controls including:

  • Data minimisation — collect and retain only what you truly need
  • Encryption — for data at rest and in transit
  • Access controls — role-based permissions and least-privilege principles
  • Multi-factor authentication — across all administrative and remote access
  • Employee training — phishing remains the leading breach vector
  • Vendor risk management — supply chain breaches are increasingly common
  • Secure link management — when sharing sensitive URLs externally, use tools like Lunyb that support expiration, password protection, and access analytics rather than exposing raw endpoints

For teams that regularly distribute links containing tracking parameters, campaign identifiers, or references to customer resources, choosing a privacy-conscious short link platform matters. Our 2026 buyer's guide to URL shorteners walks through what to look for from a security perspective.

Recent and Upcoming Reforms

The Privacy Act is undergoing its most significant overhaul in decades. Key reforms already enacted or under active consideration include:

  • Removal of the small business exemption
  • Introduction of a statutory tort for serious invasions of privacy
  • Direct rights of action for individuals
  • Tighter definitions of "consent" and "reasonable steps"
  • A children's online privacy code
  • Enhanced transparency requirements for automated decision-making

Organisations should treat 2026 as a year of compliance uplift rather than steady state. Reviewing your NDB response plan against emerging obligations now will save considerable pain later.

Notable Australian Breach Cases

Recent high-profile breaches — including large-scale incidents in telecommunications, health insurance, and financial services — have shaped both regulator expectations and public sentiment. Common lessons from OAIC determinations include:

  1. Retaining personal information beyond its useful purpose amplifies both risk and penalty exposure
  2. Failing to encrypt sensitive data is increasingly viewed as unreasonable
  3. Delayed notification attracts significantly harsher enforcement outcomes
  4. Public communications must be accurate — misleading statements can trigger separate contraventions
  5. Board and executive-level awareness of privacy risk is now an expectation, not a best practice

Frequently Asked Questions

How quickly must I notify a data breach in Australia?

You must notify the OAIC and affected individuals "as soon as practicable" after determining that an eligible data breach has occurred. If you only suspect a breach, you have up to 30 calendar days to complete a reasonable assessment — but the OAIC expects genuine urgency, not use of the full window as a default.

What is the difference between a data breach and an eligible data breach?

A data breach is any unauthorised access, disclosure, or loss of personal information. An eligible data breach is a subset that meets the "likely to result in serious harm" threshold and cannot be resolved through remediation. Only eligible data breaches trigger mandatory notification under the NDB scheme, though all breaches should be documented internally.

Does the NDB scheme apply to my small business?

Not automatically — the current small business exemption applies to entities with annual turnover under AUD $3 million. However, exceptions capture many small businesses, including health service providers, credit reporters, TFN recipients, and organisations that trade in personal information. Proposed reforms are expected to remove this exemption entirely, so smaller entities should begin preparing regardless.

What are the maximum penalties for failing to notify?

For serious or repeated interferences with privacy, body corporates face penalties of up to AUD $50 million, three times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. Individuals can be fined up to AUD $2.5 million. Additional civil penalties, enforceable undertakings, and infringement notices may also apply.

Do I need to notify if the stolen data was encrypted?

Encryption is a significant factor in assessing whether serious harm is likely, but it is not automatically exempting. If encryption keys were also compromised, or if the encryption used was weak, notification may still be required. Each breach must be assessed on its specific facts, and documentation of your reasoning is essential regardless of the outcome.

Final Thoughts

The Australian data breach notification scheme is not merely a compliance checkbox — it reflects a broader shift toward stronger accountability for how organisations handle personal information. With penalties now among the highest in the world and further reforms on the horizon, the cost of unpreparedness continues to rise.

The most resilient organisations treat privacy and security as continuous programs rather than periodic projects. That means investing in the right tools, training people at every level, and rehearsing your breach response before it's tested in real conditions. The businesses that will thrive under Australia's evolving privacy landscape are those that see notification obligations not as a burden, but as a discipline that builds lasting trust with customers, regulators, and the broader community.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles