All insights
Incident Response & Ransomware May 26, 2026 7 min read

Mandatory Data Breach Notification Under the Privacy Act

When a cyber incident exposes personal information, your obligations do not end with containing the technical problem. Under the Privacy Act 1988, many Australian organisations have a legal duty to assess the breach and, where it is serious enough, to notify both the regulator and the people affected. Getting this wrong, or simply forgetting about it amid the chaos of an incident, can compound the damage with regulatory and reputational consequences.

This guide explains how the Notifiable Data Breaches scheme works in practice, so that breach notification becomes a deliberate, well-managed process rather than an afterthought.

What the Notifiable Data Breaches scheme requires

The Notifiable Data Breaches scheme, commonly called the NDB scheme, has been in force since 2018 and forms part of the Privacy Act 1988. It is administered by the Office of the Australian Information Commissioner, the OAIC. In short, organisations covered by the scheme must notify the OAIC and affected individuals when they experience an eligible data breach.

The scheme is built on a harm-based threshold. Not every loss or exposure of personal information triggers notification; the obligation arises when a breach is likely to result in serious harm to the individuals concerned. This focuses attention and resources on the breaches that genuinely matter to people.

Does the scheme apply to you?

The NDB scheme applies to entities already covered by the Privacy Act. That includes Australian Government agencies, businesses and not-for-profit organisations with an annual turnover above the relevant threshold, private sector health service providers regardless of size, credit reporting bodies, credit providers, and tax file number recipients, among others.

A common and dangerous assumption is that small businesses are automatically exempt. Many are not, because specific categories of organisation are covered regardless of turnover, and the handling of certain information can bring an entity within scope. If you hold personal information, confirm your obligations rather than guessing. This is exactly the kind of question that comes up during cyber due diligence and broader compliance reviews.

What makes a breach eligible

An eligible data breach has three components, and all three must be present:

  1. A data breach has occurred: there is unauthorised access to, or unauthorised disclosure of, personal information, or the information has been lost in circumstances where unauthorised access or disclosure is likely.
  2. It is likely to result in serious harm: assessed from the perspective of a reasonable person, considering factors such as the kind and sensitivity of the information, whether it was protected by security measures such as encryption, the kinds of people who could access it, and the nature of the harm that could follow.
  3. Remedial action has not prevented that harm: if you take action that means the breach is no longer likely to result in serious harm, the breach may not be eligible and notification may not be required.

Serious harm can be physical, psychological, emotional, financial or reputational. Think identity theft, financial fraud, blackmail, threats to physical safety, or significant humiliation and distress.

The 30-day assessment clock

One of the most important and most misunderstood parts of the scheme is the assessment obligation. If you become aware of reasonable grounds to suspect that you may have had an eligible data breach, but you are not yet certain, you must carry out a reasonable and expeditious assessment.

This assessment must be completed within 30 calendar days of becoming aware of the grounds for suspicion. The 30 days is a maximum, not a target; the scheme expects you to move as quickly as the circumstances allow. The clock starts when you have grounds to suspect, which is often earlier than people assume, so it is wise to document when you became aware and to begin the assessment promptly.

If the assessment confirms an eligible data breach, you must notify as soon as practicable. There is no second 30-day window for notification; the expectation is prompt action once eligibility is established.

How to notify

When notification is required, there are two audiences.

  • The OAIC: you submit a statement using the OAIC’s online Notifiable Data Breach form. The statement must describe the breach, the kinds of personal information involved, and the steps the organisation recommends individuals take in response, along with your identity and contact details.
  • Affected individuals: you must inform the individuals at likely risk of serious harm. Where practicable, notify them directly, for example by email, phone or letter. If notifying each individual is not reasonably practicable, you may instead publish the statement on your website and take reasonable steps to publicise it.

The notification to individuals should be clear, honest and actionable. People need to understand what happened, what information of theirs was involved, and what they can do to protect themselves, such as changing passwords, watching for fraud, or contacting their bank.

How NDB fits with your wider obligations

The NDB scheme rarely operates in isolation. A serious cyber incident may trigger several reporting and regulatory pathways at once, and your incident response process should account for all of them:

  • ACSC reporting: cyber incidents can be reported to the Australian Signals Directorate through ReportCyber, which is separate from your NDB obligations and gives you access to advice and assistance.
  • Sector-specific rules: regulated entities may face additional duties. For example, APRA-regulated organisations have notification obligations under APRA CPS 234, and government and council bodies operate under their own frameworks.
  • Contractual obligations: your agreements with customers and partners may impose their own notification timeframes, sometimes shorter than the statutory ones.

Because these obligations run in parallel and on different clocks, the worst time to work out who needs to be told is during an active incident. Map your reporting triggers into your incident response playbooks ahead of time.

Common mistakes organisations make

Several recurring errors trip organisations up when the NDB scheme is in play. Watching for them will keep you on the right side of the obligation:

  • Starting the clock too late. The 30-day assessment period runs from when you have reasonable grounds to suspect, not from when you have confirmed everything. Delaying the start because you are still investigating can leave you out of time.
  • Treating it as purely a legal task. The assessment depends heavily on technical facts about what data was accessed and whether it was protected, so your security, privacy and legal people must work together.
  • Overlooking encrypted or secured data. Whether information was effectively encrypted is a genuine factor in the serious harm assessment, so document your security controls.
  • Under-notifying or over-notifying individuals. Notify those at likely risk of serious harm, with clear and actionable guidance, rather than either staying silent or flooding everyone with alarming notices that lack substance.
  • Forgetting to document the decision. Even where you conclude that a breach is not eligible, record your reasoning. If the OAIC ever asks, a contemporaneous record of a considered assessment is invaluable.

Prepare before the breach

The organisations that handle breach notification well are the ones that prepared for it. Before anything happens, you should know what personal information you hold and where it lives, who in your organisation owns the assessment decision, and how legal, privacy and communications functions will work together under pressure. Pre-drafted notification templates and a clear decision framework for the eligibility assessment save precious time and reduce the risk of errors when emotions and stakes are high.

This planning sits naturally within a broader incident response plan, where the privacy assessment becomes one defined workstream alongside technical containment and recovery. Treating breach notification as an integrated part of incident response, rather than a separate legal scramble afterwards, is what keeps you compliant and credible when it counts.

Get expert help

CISO Advisory helps Australian government, financial services and enterprise organisations build breach assessment and notification into their incident response capability, so that when an incident hits, the privacy obligations are handled calmly and correctly. If you want help getting ready, or support during a live incident, engage a virtual CISO or call 07 2112 8502 any time. You can also reach us through our contact page. We respond on-site same day or next business day, and remotely Australia-wide. This article is general information, not legal advice; obtain advice specific to your circumstances.

Frequently asked questions

What is the Notifiable Data Breaches scheme?

The Notifiable Data Breaches scheme is part of the Privacy Act 1988 and requires organisations covered by the Act to notify the Office of the Australian Information Commissioner and affected individuals when an eligible data breach occurs. An eligible data breach is one likely to result in serious harm to the individuals whose personal information is involved.

What counts as an eligible data breach?

An eligible data breach has three elements: there is unauthorised access to, unauthorised disclosure of, or loss of personal information; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that likely serious harm through remedial action. If remediation removes the likelihood of serious harm, notification may not be required.

How long do I have to assess and notify a breach?

If you suspect an eligible data breach but are not certain, you must carry out a reasonable and expeditious assessment, taking no more than 30 days from when you became aware of the grounds for suspicion. If the assessment confirms an eligible data breach, you must notify the OAIC and affected individuals as soon as practicable.

Who has to comply with the NDB scheme?

The scheme applies to entities covered by the Privacy Act 1988, including Australian Government agencies, businesses and not-for-profits with an annual turnover above the threshold, private health service providers regardless of size, credit reporting bodies, and certain others. Many small businesses are also covered through specific obligations, so check your status rather than assuming you are exempt.

What information must a notification include?

A notification must describe the breach, the kinds of information involved, and the steps individuals should take in response. It must include the organisation's identity and contact details. You notify the OAIC through its online form and inform affected individuals directly where practicable, or by publishing a notice if direct contact is not reasonably possible.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act