Someone has been in a staff mailbox for a fortnight. Or a laptop with client files has gone missing from a car. Or a supplier emails to say their systems were breached and your customers' details were in there. The first practical question, once the immediate mess is under control, is usually this: do we have to tell anyone?
In Australia the answer comes from the Notifiable Data Breaches scheme, part of the Privacy Act 1988, which has applied since February 2018. It is less complicated than people fear, but it has deadlines, and "we didn't think it applied to us" is a weak position to be in afterwards.
This is a plain English overview, not legal advice. If you think you have had a breach, check the specifics with your lawyer.
Who it covers
The scheme applies to organisations covered by the Privacy Act. As a rule, that means businesses and not-for-profits with annual turnover of more than $3 million, plus Australian Government agencies.
The $3 million line is where many owners stop reading, and that is a mistake. Some small businesses are covered regardless of turnover, including:
- private sector health service providers, which the OAIC defines broadly: GPs, dentists, pharmacists, allied health, psychologists and complementary therapists, but also childcare centres and private schools
- businesses that trade in personal information
- credit reporting bodies and credit providers
- businesses that hold tax file numbers, for their handling of that information
- reporting entities under the AML/CTF Act, for their AML/CTF activities
- Commonwealth contracted service providers, for the work done under the contract
- small businesses that have chosen to opt in to the Privacy Act
The OAIC has a short checklist on its small business page that walks through each of these. It takes five minutes and is worth doing before you need it.
What counts as an "eligible data breach"
An eligible data breach has three parts:
- There is unauthorised access to, or unauthorised disclosure of, personal information you hold, or it is lost in a way that makes that likely.
- A reasonable person would conclude it is likely to result in serious harm to one or more of the people it is about. "Likely" means more probable than not. Serious harm can be financial, physical, psychological, emotional or reputational.
- You have not been able to prevent that likely risk of serious harm with remedial action.
The third part matters. If you act quickly enough that serious harm is no longer likely, for example you remotely wipe a lost laptop that was encrypted, or you get an email sent to the wrong person deleted before it is opened and can confirm it, it may not be an eligible breach at all. Write down what you did and why you concluded that.
Identity documents, health information, bank details and anything that enables fraud or identity theft tend to point towards serious harm. So does information about people in vulnerable situations.
The 30 day assessment
If you suspect an eligible data breach but are not sure, you must take all reasonable steps to assess it within 30 calendar days of becoming aware of the grounds for suspicion. That clock starts when you first have reason to suspect, not when the investigation formally begins.
In practice, 30 days is not long once you need logs, forensic help, legal advice and answers from suppliers. Start the assessment the same day. Our article on ransomware: the first 24 hours covers the early steps that preserve the evidence you will need.
Notifying the OAIC and individuals
Once you have reasonable grounds to believe there has been an eligible data breach, you must notify as soon as practicable.
- The OAIC gets a statement, lodged through the OAIC's online form. It covers your organisation's identity and contact details, a description of the breach, the kinds of information involved, and what you recommend people do in response.
- The individuals get the same information. You can notify everyone whose information was involved, only those at risk of serious harm, or, if neither of those is practicable, publish the statement on your website and take reasonable steps to publicise it.
If more than one organisation holds the same data, such as you and your IT or cloud provider, only one needs to notify. Agree who that is, in writing.
What changed in the Privacy Act
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024. According to the OAIC, most of the changes within the Information Commissioner's remit commenced the next day, 11 December 2024. The main ones for a business:
- Clearer security obligations: the security principle (APP 11) now spells out that reasonable steps include technical and organisational measures.
- A wider range of OAIC enforcement tools, including infringement notices and tiers of civil penalties for less serious breaches.
- A power for the Attorney-General to make an eligible data breach declaration, allowing personal information to be shared to reduce harm after a major breach.
- A statutory tort for serious invasions of privacy, which commenced on 10 June 2025. It lets individuals sue for serious invasions of privacy that were intentional or reckless. It is broader than the rest of the Privacy Act and is not limited to organisations the Act covers.
- New transparency rules for automated decisions, which commence on 10 December 2026: privacy policies must explain when personal information is used in automated decisions that significantly affect people.
A second round of reform is on the way. On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, with consultation closing on 18 September 2026. Among other changes, the draft proposes notifying the Information Commissioner within 72 hours of an eligible data breach. It is a draft, not law, so watch for the final bill. As at the time of writing, the small business exemption is still in place.
If you are hit by ransomware and pay, there is a separate obligation to report the payment. See our article on ransomware payment reporting in Australia.
If you think it already happened
Contain it first: reset passwords, revoke sessions, isolate affected machines. Keep the logs. Report the cyber incident to ReportCyber at cyber.gov.au or call 1300 CYBER1 (1300 292 371). Then start the eligible data breach assessment, with your lawyer, and diary the 30 day date.
Where Geidi fits
Geidi's cyber security services include a 24/7 security operations centre and security practices aligned to Essential Eight, ISO/IEC 27001 and SMB1001. To talk about being ready before a breach, contact us.
Sources
- OAIC: Quick reference guide for responding to data breaches
- OAIC: Part 4, Notifiable Data Breach (NDB) Scheme
- OAIC: Small business
- OAIC: History of the Privacy Act
- OAIC: Statutory tort for serious invasions of privacy
- Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024
- Attorney-General's Department: Privacy reform, consultation on exposure draft legislation

