Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches (NDB) scheme fundamentally changed how organisations handle personal information incidents. Since February 2018, eligible entities have been legally required to notify both the Office of the Australian Information Commissioner (OAIC) and affected individuals whenever a data breach is likely to result in serious harm. With penalties now reaching into the tens of millions of dollars following the 2022 Privacy Act amendments, understanding your obligations has never been more critical.
This guide walks Australian businesses, not-for-profits and government contractors through the entire scheme — who it applies to, when the clock starts, how to assess harm, and exactly what the OAIC expects in a notification.
What is the Australian Data Breach Notification Scheme?
The Australian Data Breach Notification Scheme — formally known as the Notifiable Data Breaches (NDB) scheme — is a mandatory framework established under Part IIIC of the Privacy Act 1988 (Cth). It requires covered organisations to report eligible data breaches to the OAIC and notify affected individuals when there is a likely risk of serious harm.
The scheme sits alongside the 13 Australian Privacy Principles (APPs) and is enforced by the Information Commissioner. Its purpose is twofold: give individuals the chance to protect themselves after their data is compromised, and create accountability pressure on organisations to invest in stronger security.
Key legislative framework
- Privacy Act 1988 (Cth) — the primary legislation
- Privacy Amendment (Notifiable Data Breaches) Act 2017 — introduced the NDB scheme
- Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 — dramatically increased penalties
- Australian Privacy Principles (APPs) — ongoing data handling requirements
Who Must Comply With the NDB Scheme?
The scheme applies to "APP entities" — the same organisations bound by the Australian Privacy Principles. If you're already subject to the Privacy Act, you're subject to the NDB scheme.
Covered entities include:
- Australian Government agencies (excluding some intelligence bodies)
- Businesses and not-for-profits with annual turnover above AUD $3 million
- Private sector health service providers (regardless of turnover)
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Organisations that trade in personal information
- Contracted service providers to the Commonwealth
- Residential tenancy database operators
Small business exemption — and when it doesn't apply
Small businesses with turnover under $3 million are generally exempt, but exceptions are broad. If your small business handles health information, provides services under a Commonwealth contract, is related to a larger APP entity, or trades in personal data, the exemption is lost. The Attorney-General's ongoing Privacy Act review has also signalled the small business exemption may be removed entirely in future reforms.
What Counts as an Eligible Data Breach?
An eligible data breach has three components that must all be present:
- Unauthorised access, unauthorised disclosure, or loss of personal information held by the entity
- The breach is likely to result in serious harm to one or more affected individuals
- The entity has not been able to prevent the likely risk of serious harm through remedial action
Examples of eligible breaches
- A ransomware attack where customer records were exfiltrated
- An employee emailing a spreadsheet of client details to the wrong recipient
- A lost unencrypted laptop containing patient files
- A misconfigured cloud storage bucket exposing identity documents
- Credential stuffing attacks that successfully access customer accounts
Assessing "Serious Harm" Under the Scheme
Serious harm is the pivotal test. The OAIC considers a non-exhaustive list of factors in section 26WG of the Privacy Act, including:
- The kind and sensitivity of the information (health, financial, identity documents score high)
- Whether the information is protected by security measures (e.g. strong encryption)
- The persons or kinds of persons who have obtained the information
- The likelihood those persons have the intention of causing harm
- The nature of the harm — financial, reputational, physical, psychological or emotional
Harm severity reference table
| Data type exposed | Typical harm risk | Likely notifiable? |
|---|---|---|
| Name + email only | Low (phishing risk) | Usually no |
| Name + DOB + address | Moderate (identity theft) | Often yes |
| Driver licence / passport numbers | High (identity fraud) | Yes |
| Medicare / health records | High (sensitive information) | Yes |
| Financial account credentials | Very high (direct financial loss) | Yes |
| TFN or superannuation details | Very high | Yes |
The 30-Day Assessment Timeline
Once an entity becomes aware there are reasonable grounds to suspect an eligible data breach may have occurred, it has 30 calendar days to carry out a reasonable and expeditious assessment. If, during assessment, the entity becomes aware that an eligible breach has occurred, notification must happen "as soon as practicable" — not 30 days later.
Step-by-step response process
- Contain the breach — stop the ongoing data loss, revoke access, isolate systems
- Evaluate — identify what information was affected, who is impacted, and the cause
- Assess serious harm — apply the s.26WG factors objectively
- Consider remedial action — can you prevent the harm (e.g. forced password reset before credentials were used)?
- Notify the OAIC via the online Notifiable Data Breach form
- Notify affected individuals through the most appropriate channel
- Review and improve — post-incident analysis and control uplift
How to Notify the OAIC
Notifications are submitted through the OAIC's online NDB form. The statement must contain:
- The identity and contact details of the organisation
- A description of the breach
- The kinds of information involved
- Recommendations about steps individuals should take in response
If multiple entities jointly hold the breached information (common in outsourcing arrangements), only one needs to notify — but you should document who takes responsibility in your contracts before an incident occurs.
Notifying affected individuals — three options
- Option 1: Notify all individuals whose information was involved
- Option 2: Notify only those at likely risk of serious harm
- Option 3: If neither is practicable, publish the statement on your website and take reasonable steps to publicise it
Penalties and Enforcement
The 2022 amendments transformed the penalty regime. For serious or repeated interferences with privacy, maximum civil penalties for body corporates are now the greater of:
- AUD $50 million, or
- Three times the value of any benefit obtained through the misuse of information, or
- 30% of the entity's adjusted turnover in the relevant period
For individuals, the maximum is now $2.5 million. The OAIC also gained expanded investigative and information-gathering powers, and the ability to issue infringement notices for lower-tier breaches.
Recent enforcement signals
Since the Optus and Medibank breaches of 2022, the OAIC has pursued representative civil penalty proceedings and increased public reporting of trends. Half-yearly NDB reports consistently show malicious or criminal attacks (particularly phishing and compromised credentials) as the leading cause of notifiable breaches in Australia.
Building an NDB-Ready Compliance Program
Meeting your obligations isn't a one-off exercise. Here's a practical compliance checklist Australian organisations should implement:
Governance
- Appoint a privacy officer with clear authority
- Maintain an up-to-date APP Privacy Policy
- Keep a data inventory mapping where personal information is stored and processed
Prevention
- Enforce multi-factor authentication on all remote access and admin accounts
- Patch internet-facing systems on a defined schedule
- Use encrypted DNS and HTTPS-only policies on managed devices
- Minimise data collection — you can't lose what you don't hold
- Apply role-based access controls and review them quarterly
Detection and response
- Centralised logging with retention aligned to incident investigation needs
- A written Data Breach Response Plan rehearsed at least annually
- Pre-drafted notification templates for OAIC and individuals
- Legal and forensic incident response retainers in place before you need them
Third-party risk
- Contractual notification clauses with every processor and sub-processor
- Due diligence on cloud providers, including ISO 27001 and IRAP where relevant
- Audit rights for critical vendors
Safer Link Handling and Data Minimisation
A surprising number of notifiable breaches start with a phishing link or a leaked URL that exposes customer data. Treating link hygiene as part of your privacy program pays dividends.
When sharing links in marketing campaigns, internal communications or customer notifications, use a privacy-focused URL shortener that doesn't harvest unnecessary analytics, supports HTTPS by default, and gives you visibility over click activity so compromised links can be disabled quickly. Lunyb is one option built with these principles in mind — you can read our transparent honest review of Lunyb or compare the broader market in our 2026 URL shortener buyer's guide.
For teams already using a managed shortener, our Rebrandly review covers enterprise features worth evaluating alongside Australian privacy requirements.
Common Mistakes Australian Organisations Make
1. Starting the 30-day clock late
The clock starts when you have reasonable grounds to suspect, not when you've confirmed. Hesitating to formally recognise a suspicion is a frequent compliance failure.
2. Over-relying on encryption as a defence
Encryption only removes the serious harm risk if keys weren't also compromised and the implementation is current. Weak or legacy encryption won't save you.
3. Vague individual notifications
Telling customers "an incident occurred" without specifics on what data was affected and what they should do fails the content requirements and damages trust.
4. Forgetting overseas disclosures
APP 8 makes you accountable for breaches by overseas recipients of information you disclosed. If your US-based processor loses data, it's still your notification.
5. No post-incident review
The OAIC expects evidence that lessons learned feed back into controls. A notification without demonstrable improvement invites further scrutiny.
How the NDB Scheme Compares Internationally
| Regime | Notification trigger | Regulator timeline | Max penalty |
|---|---|---|---|
| Australia (NDB) | Likely serious harm | As soon as practicable (30-day assessment) | $50M / 30% turnover |
| EU GDPR | Risk to rights and freedoms | 72 hours | €20M / 4% turnover |
| UK GDPR | Risk to rights and freedoms | 72 hours | £17.5M / 4% turnover |
| New Zealand | Serious harm likely | As soon as practicable | NZ$10,000 per offence |
| Singapore PDPA | Significant harm or scale ≥500 | 3 calendar days | S$1M or 10% turnover |
Australia's "as soon as practicable" standard gives slightly more flexibility than the GDPR's hard 72-hour deadline, but the serious harm threshold still requires rapid triage.
What's Changing: The Privacy Act Review
The Australian Government's response to the Privacy Act Review Report signalled significant upcoming reforms, several of which will tighten the NDB scheme:
- Proposed statutory tort for serious invasions of privacy
- Potential removal of the small business exemption
- Shorter, prescribed notification timeframes (likely 72 hours to the OAIC)
- Expanded definition of personal information to clearly include technical identifiers
- Enhanced rights for individuals, including a right to erasure
Organisations should treat the current scheme as a floor, not a ceiling, and prepare now for a more prescriptive regime.
Frequently Asked Questions
Does the NDB scheme apply to my small business?
If your annual turnover is under $3 million, you're generally exempt — but exemptions are lost if you handle health information, hold a Commonwealth contract, trade in personal information, or are related to a larger APP entity. Many small businesses discover they're actually covered.
How quickly must I report a breach to the OAIC?
You have up to 30 days to assess a suspected eligible breach, but once you're aware that an eligible breach has occurred, you must notify "as soon as practicable". In practice, high-impact breaches should be reported within days, not weeks.
What happens if I don't notify?
Failure to notify can be treated as a serious or repeated interference with privacy, exposing body corporates to civil penalties up to $50 million, three times any benefit gained, or 30% of adjusted turnover — whichever is greatest. The OAIC can also seek enforceable undertakings and injunctions.
Do I have to notify every individual whose data was involved?
No. You can notify all affected individuals, only those at likely risk of serious harm, or — where neither is practicable — publish a statement on your website. The approach must be reasonable given the circumstances.
Does the scheme cover breaches by my overseas service providers?
Yes. Under APP 8, you remain accountable for personal information disclosed to overseas recipients. A breach by your US-based cloud provider or Indian support contractor can still trigger an Australian notification obligation.
Final Thoughts
The Australian Data Breach Notification Scheme is now a mature, well-enforced regime with penalties serious enough to materially damage any business. Treating NDB compliance as a technical and governance program — rather than a legal afterthought — is the only sustainable approach. Map your data, lock down your access, drill your response plan, and when something does go wrong, act decisively within the timeframes the scheme demands. The organisations that handle incidents transparently and quickly consistently emerge with their reputations more intact than those that delay.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
The Data Protection Act 2018 gives effect to the GDPR in Ireland and sets out the obligations of controllers and processors. This complete guide explains the Act's scope, key definitions, data subject rights, enforcement by the DPC, and a practical compliance checklist for Irish organisations.
Bill C-27 Digital Charter: What Canadian Businesses Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, overhauls private-sector privacy law and introduces the country's first federal AI legislation. Learn what the CPPA, PIDPTA, and AIDA mean for your business and how to prepare for compliance.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn exactly how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step 2026 guide covers your GDPR rights, evidence gathering, timelines, and what to expect after submission.
OAIC Complaints: How to Report a Privacy Breach in Australia
A complete Australian guide to lodging a privacy complaint with the OAIC. Learn the mandatory first steps, evidence to gather, timelines, conciliation outcomes, and when you can seek compensation under the Privacy Act 1988.