Insights › Privacy & Compliance

Notifiable Data Breaches: What Australian Businesses Must Do When Data Is Exposed

Conceptual illustration of an alert notification broadcasting after exposed data on a navy background.

Most Australian business owners know the Privacy Act exists. Far fewer realise that since 2018, the Notifiable Data Breaches (NDB) scheme can require them to formally notify both the individuals affected and the Office of the Australian Information Commissioner (OAIC) when personal information is exposed. Getting this wrong compounds a bad week into a regulatory problem.

Does the scheme apply to you?

Broadly, the Privacy Act applies to businesses with annual turnover above $3 million, and to some smaller businesses regardless of turnover, including health service providers and businesses that trade in personal information. Even if you sit below the threshold, your contracts with larger customers often impose equivalent obligations, and the scheme is best practice for everyone.

What counts as a notifiable breach?

Three ingredients: personal information is lost or accessed without authorisation; a reasonable person would conclude it’s likely to result in serious harm to the individuals; and you haven’t been able to prevent that harm through remedial action. Think stolen customer databases, a mailbox compromise exposing identity documents, or a lost unencrypted laptop containing client records.

The clock: what you must do, and when

  1. Contain it immediately. Disable compromised accounts, isolate affected systems, stop the bleeding first.
  2. Assess within 30 days. If you suspect a breach may be notifiable, you have 30 days to complete a reasonable and expeditious assessment of whether serious harm is likely.
  3. Notify promptly if it is. Tell affected individuals and the OAIC as soon as practicable, including what happened, what information was involved, and what people should do.

Prepare now, not during the incident

The businesses that handle breaches well all made the same three preparations: a data inventory (knowing what personal information they hold and where), a one-page response plan (who acts, who decides, who calls the lawyer and insurer), and preventive basics like device encryption, MFA and access controls that stop most breaches happening at all. Notably, encrypting laptops and phones can be the difference between “lost property” and “notifiable breach”.

This article is general information, not legal advice. For advice on your specific obligations, consult a privacy lawyer.

Related reading: understand the wider Privacy Act changes for Australian SMBs, reduce breach risk at the source with multi-factor authentication, and see the complete guide to cyber security for small business in Australia.

Would a breach catch you unprepared?

Our free assessment checks your privacy readiness alongside 26 other controls, and gives you a prioritised action plan in about 10 minutes.

Get my free Security Score

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading