IronSights

Australia · Privacy, breach and cyber law

What Australian businesses actually have to do.

There is no single cyber security law in Australia. There is a Privacy Act with thirteen principles and a breach scheme, a Cyber Security Act with a 72-hour reporting clock, sector rules on top, and a reform program that keeps moving. This guide separates what binds you today from what is merely coming.

General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.

What applies

Four bodies of obligation, and who each one catches.

Most Australian businesses are touched by the first three. The fourth is the one to watch if you are planning past this financial year.

If it is happening now

The obligations start before you know what you have.

Both clocks start on suspicion, not on certainty: the 30-day assessment runs from when you have reasonable grounds to suspect a breach, and the 72-hour ransomware report runs from the payment. So the first hour is about evidence as much as containment. If you cannot say later what was accessed and when, the assessment defaults to the worst case.

Practically: isolate but do not wipe, keep logs and attacker messages, write down times, and get advice before paying anything. Our incident response and ransomware recovery pages cover the technical first hour.

Who you may need to tell

  • The OAIC and affected individuals, if it is an eligible data breach.
  • The Department of Home Affairs, within 72 hours, if a ransom was paid.
  • The ASD's ACSC via ReportCyber (voluntary, and how you get help).
  • Your cyber insurer, often within 24 to 72 hours under the policy.
  • Your sector regulator: APRA, ASIC, a law society, or a funding body.
  • Customers and partners, where contracts require notice.

Common questions

Asked and answered.

These are the questions we get asked mid-incident, when the answer needs to be quick and correct.

  1. What are an Australian business's cyber security legal obligations?

    There is no single cyber security law. For most businesses the obligations come from the Privacy Act 1988 (the Australian Privacy Principles, especially APP 11 security, and the Notifiable Data Breaches scheme), the Cyber Security Act 2024 (ransomware payment reporting and smart device standards), and sector rules such as APRA's CPS 234 or ASIC's expectations of licensees. Contracts and cyber insurance policies usually add more.

  2. Do we have to report every cyber incident?

    No. Reporting to the ASD's ACSC via ReportCyber is voluntary and recommended. What is mandatory: notifying the OAIC and affected individuals for an eligible data breach under the NDB scheme, and reporting a ransomware or extortion payment to Home Affairs within 72 hours if the Cyber Security Act applies to you. Sector regulators and your insurer may add their own.

  3. Is paying a ransom illegal in Australia?

    Not in itself, and the Cyber Security Act does not prohibit it. It requires payment to be reported within 72 hours. Payment can be unlawful under sanctions or proceeds-of-crime law depending on who receives it, so take advice before paying, not after.

  4. What happens if we get it wrong?

    Failing to comply with the Privacy Act is an interference with privacy: the maximum civil penalty for serious or repeated interferences is the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, with lower tiers and infringement notices for less serious contraventions. Not reporting a ransomware payment carries its own civil penalty, and Home Affairs moved to active enforcement from 1 January 2026. Since 10 June 2025 individuals can also sue directly for serious invasions of privacy.

  5. Does a security certification satisfy these obligations?

    Not automatically, but it helps you evidence them. APP 11 asks for reasonable steps, and an Essential Eight assessment or SMB1001 certification is a documented, independent way to show what you did and why. Certification is evidence, not a defence in itself.

  6. Where does this guidance come from?

    It summarises publicly available material from the OAIC, the Department of Home Affairs and the legislation itself, current as at August 2026. It is general guidance for Australian businesses, not legal advice: privacy and cyber law is changing quickly and your circumstances matter, so take your own advice before acting.

Incident now, or preparing for one?

Obligations are easier to meet when the plan already exists.

We build the NDB assessment and the 72-hour report into your incident response plan, with owners and templates, and our incident reports are structured to support the OAIC statement.