Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches (NDB) scheme is one of the most important pieces of privacy legislation that organisations handling personal information must understand. Introduced in February 2018 as part of the Privacy Act 1988, the scheme sets out legally binding obligations for notifying individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to cause serious harm.
With the 2022 amendments significantly increasing penalties and the ongoing 2024–2026 Privacy Act reforms expanding its reach, compliance has never been more consequential. This guide walks you through everything your organisation needs to know about the Australian data breach notification scheme — from legal thresholds to practical response steps.
What Is the Australian Data Breach Notification Scheme?
The Australian data breach notification scheme, formally known as the Notifiable Data Breaches (NDB) scheme, is a legal framework under Part IIIC of the Privacy Act 1988 (Cth) that requires covered entities to notify affected individuals and the OAIC when an "eligible data breach" occurs. An eligible data breach is any incident involving unauthorised access, disclosure, or loss of personal information that is likely to result in serious harm to one or more individuals.
The scheme exists to improve transparency, allow individuals to take protective steps after their data is compromised, and incentivise organisations to invest in stronger information security. It operates alongside the Australian Privacy Principles (APPs), which govern how personal information is collected, used, stored and disclosed.
Key Objectives of the NDB Scheme
- Protect individuals by giving them timely notice to mitigate harm (e.g. changing passwords, monitoring credit).
- Promote accountability and trust in organisations that handle personal data.
- Enable the OAIC to monitor breach trends and enforce privacy obligations.
- Align Australia with international privacy standards such as the EU's GDPR.
Who Must Comply With the NDB Scheme?
The scheme applies to all "APP entities" — the same organisations bound by the Australian Privacy Principles. Understanding whether your business is covered is the first compliance step.
Entities Covered
- Australian Government agencies (federal departments and most statutory bodies).
- Private sector organisations with an annual turnover of more than A$3 million.
- All health service providers, regardless of turnover (GPs, pharmacies, allied health, gyms with fitness assessments).
- Credit reporting bodies, credit providers and TFN recipients, regardless of size.
- Entities trading in personal information (e.g. list brokers).
- Not-for-profits that meet the turnover threshold or opt in.
Importantly, the 2024 Privacy Act reforms are progressively removing the A$3 million small business exemption, meaning tens of thousands of additional Australian businesses will become subject to the scheme. If you are a small operator today, you should begin preparing now.
What Counts as an Eligible Data Breach?
An eligible data breach has three essential elements that must all be satisfied before notification obligations are triggered.
- Unauthorised access, disclosure, or loss of personal information held by the entity.
- The breach is likely to result in serious harm to one or more individuals.
- The entity has been unable to prevent the likely risk of serious harm through remedial action.
Examples of Eligible Data Breaches
- A ransomware attack that exfiltrates customer records including names, addresses, and Medicare numbers.
- A lost unencrypted laptop containing employee tax file numbers.
- An email containing a spreadsheet of patient diagnoses sent to the wrong recipient.
- A misconfigured cloud storage bucket exposing identity documents to the public internet.
- Credential stuffing attacks exposing login details and linked personal data.
What "Serious Harm" Means
The OAIC interprets serious harm broadly. It can be physical, psychological, emotional, financial or reputational. Relevant factors include the sensitivity of the information, whether it is protected by encryption, the type of people likely to have obtained the data, and the nature of the harm that could follow (identity theft, discrimination, blackmail, family violence risks, etc.).
Notification Timelines and Obligations
Timing is critical under the NDB scheme. Once an entity becomes aware there are reasonable grounds to suspect an eligible data breach may have occurred, a strict clock starts ticking.
The 30-Day Assessment Window
Entities have a maximum of 30 calendar days to carry out a reasonable and expeditious assessment of whether the suspected incident is in fact an eligible data breach. This is a ceiling, not a target — the OAIC expects assessments to be completed as quickly as practicable.
Notification Requirements
If the assessment confirms an eligible data breach, the entity must as soon as practicable:
- Prepare a statement for the Commissioner using the OAIC's online Notifiable Data Breach form.
- Notify affected individuals of the contents of that statement, or publish the statement if direct notification is not practicable.
What the Statement Must Contain
- The identity and contact details of the entity.
- A description of the eligible data breach.
- The kinds of information involved.
- Recommended steps individuals should take in response.
Comparison: NDB Scheme vs GDPR vs New Zealand Privacy Act
Australian businesses operating internationally often need to understand how the NDB scheme compares to similar frameworks. The table below summarises the key differences.
| Feature | Australia (NDB) | EU (GDPR) | New Zealand (Privacy Act 2020) |
|---|---|---|---|
| Notification trigger | Likely serious harm | Risk to rights and freedoms | Likely to cause serious harm |
| Regulator notification deadline | As soon as practicable (max 30 days to assess) | Within 72 hours of awareness | As soon as practicable |
| Individual notification | Required if serious harm likely | Required if high risk | Required if serious harm likely |
| Maximum penalty | Up to A$50M or 30% of adjusted turnover | €20M or 4% of global turnover | NZ$10,000 (criminal offence) |
| Regulator | OAIC | National DPAs / EDPB | Office of the Privacy Commissioner |
Penalties for Non-Compliance
The 2022 Privacy Legislation Amendment (Enforcement and Other Measures) Act dramatically increased penalties for serious or repeated interferences with privacy — including failure to notify eligible data breaches.
Current Maximum Penalties for Corporations
- A$50 million, or
- Three times the value of any benefit obtained through the misuse of information, or
- 30% of the entity's adjusted turnover in the relevant period — whichever is greatest.
For individuals, maximum penalties sit at A$2.5 million. The OAIC also has strengthened investigative powers, including the ability to conduct assessments, issue infringement notices, and share information with other regulators such as ASIC and the ACCC.
How to Respond to a Suspected Data Breach
A well-rehearsed response plan is the difference between a contained incident and a reportable crisis. The OAIC recommends a four-step response framework.
Step 1: Contain
Immediately take steps to limit any further compromise. This may include disabling affected accounts, isolating systems from the network, revoking API keys, or recalling misdirected emails. Preserve evidence — do not simply wipe affected systems.
Step 2: Assess
Form an incident response team and investigate the scope. Determine what personal information was involved, how many individuals are affected, who had unauthorised access, and whether serious harm is likely. Document every decision — this record protects you if the OAIC later reviews your response.
Step 3: Notify
If the breach is eligible, notify the OAIC and affected individuals promptly. Be clear, factual, and practical. Explain what happened, what information was involved, what you are doing about it, and what individuals should do to protect themselves (such as changing passwords, enabling multi-factor authentication, or placing a credit ban through Equifax, Experian or illion).
Step 4: Review
After the incident, conduct a post-mortem. Update your information security controls, staff training, vendor contracts and incident response plan. The OAIC views repeat failures very dimly.
Building a Privacy-First Operational Posture
The best way to manage NDB obligations is to minimise the risk of ever having to use them. Australian organisations should combine governance, technical controls and vendor hygiene.
Governance and Documentation
- Maintain an up-to-date Privacy Policy and APP-compliant collection notices.
- Keep a Record of Processing Activities and a data inventory of where personal information lives.
- Implement a documented Data Breach Response Plan with named roles and escalation paths.
- Run annual tabletop exercises simulating ransomware, insider threats, and misdirected disclosure incidents.
Technical Controls
- Encrypt personal information at rest and in transit using modern standards (AES-256, TLS 1.3).
- Enforce multi-factor authentication across all administrative access.
- Apply the principle of least privilege and review access quarterly.
- Use endpoint detection and response (EDR) tooling and centralised logging.
- Patch systems promptly — many notified breaches stem from unpatched known vulnerabilities.
Third-Party and Link Hygiene
Many breaches arise from third-party services, phishing and malicious links sent through marketing channels. When sharing campaign links, use trustworthy infrastructure that offers HTTPS, click analytics and the ability to disable compromised links immediately. Tools like Lunyb provide branded, trackable short links with privacy-aware analytics, which helps teams audit what has been shared and quickly deactivate any URL that becomes implicated in an incident. If you're evaluating options, see our 2026 buyer's guide to URL shorteners and our honest Lunyb review for comparison.
Common Mistakes Australian Organisations Make
The OAIC's half-yearly Notifiable Data Breaches Report consistently highlights the same categories of error. Avoiding these can dramatically reduce your exposure.
- Treating assessment as optional: entities must assess suspected breaches — ignoring the signal does not restart the clock.
- Over-relying on the "remedial action" exception: it only applies if the remedial action genuinely eliminates the likelihood of serious harm.
- Vague individual notifications: statements must be specific enough for individuals to take protective action.
- Forgetting about contractors and processors: you remain accountable even when a vendor causes the breach.
- No documentation: without written records, you cannot demonstrate your assessment was reasonable.
What's Changing: The 2024–2026 Privacy Act Reforms
The Australian Government has committed to the most significant overhaul of the Privacy Act since its introduction. Tranche 1 reforms passed in late 2024, with further tranches expected through 2025 and 2026. Changes relevant to the NDB scheme include:
- A statutory tort for serious invasions of privacy, enabling individuals to sue directly.
- A hard 72-hour notification window to the OAIC proposed to align with GDPR.
- Removal of the small business exemption, bringing most SMEs into scope.
- Expanded definition of "personal information" to clearly include technical identifiers such as IP addresses and device IDs.
- New requirements around automated decision-making transparency.
Organisations should treat the current environment as a transition period and uplift their privacy maturity now rather than wait for the final rules.
Frequently Asked Questions
Do I have to notify the OAIC for every data breach?
No. You only have to notify if the incident is an eligible data breach — meaning there is unauthorised access, disclosure or loss of personal information that is likely to result in serious harm, and you cannot prevent that harm through remedial action. However, you should still document every suspected incident and your assessment reasoning.
How long do I have to report a data breach in Australia?
You have a maximum of 30 calendar days to assess whether a suspected breach is eligible. Once confirmed, you must notify the OAIC and affected individuals "as soon as practicable". Proposed reforms would introduce a stricter 72-hour window for notifying the OAIC.
Does the NDB scheme apply to small businesses?
Currently, most businesses with annual turnover under A$3 million are exempt, but there are important exceptions — including all health service providers, credit reporting bodies and TFN recipients. The Government has committed to removing the small business exemption, so most SMEs should prepare to come into scope.
What happens if I don't notify a breach?
Failing to notify an eligible data breach is a serious interference with privacy. Penalties can reach A$50 million, three times the benefit obtained, or 30% of adjusted turnover — whichever is greatest. The OAIC can also issue enforceable undertakings, compliance notices and conduct public investigations that cause significant reputational damage.
Who should I notify first — the OAIC or affected individuals?
The Privacy Act does not strictly mandate an order, but best practice is to notify the OAIC at or around the same time you notify individuals. In many cases organisations file the statement with the Commissioner first (via the OAIC's online form) and then roll out individual notifications over the next 24–48 hours.
Final Thoughts
The Australian data breach notification scheme is more than a compliance checkbox — it is a framework for maintaining community trust in how organisations handle personal information. With penalties now among the highest in the world and reforms expanding the scheme's reach, every Australian organisation should treat privacy readiness as a board-level priority. Invest in prevention, document everything, and when an incident does occur, respond with speed, honesty and care for the individuals affected.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A practical, step-by-step guide to filing a privacy complaint with the Irish Data Protection Commission in 2026. Learn eligibility, required evidence, submission channels, realistic timelines, and your rights throughout the process.
Singapore PDPA: Your Personal Data Protection Rights Explained
Discover your rights under Singapore's Personal Data Protection Act (PDPA), including access, correction, consent, and data breach notifications. Learn how to file complaints, protect your NRIC, and understand how the PDPA compares to global privacy laws in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 implements the GDPR and sets out the powers of the Data Protection Commission. This complete guide explains who it applies to, your rights, business obligations, penalties and practical compliance steps.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in scope, consent rules, penalties, and individual rights. This guide breaks down the key differences every Singapore business should know to stay compliant across both frameworks.