Australia · Privacy, breach and cyber law
What Australian businesses actually have to do.
There is no single cyber security law in Australia. There is a Privacy Act with thirteen principles and a breach scheme, a Cyber Security Act with a 72-hour reporting clock, sector rules on top, and a reform program that keeps moving. This guide separates what binds you today from what is merely coming.
General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.
The three deadlines worth memorising
72 hours
Ransomware payment report
From making (or learning of) a ransom or extortion payment, if you turn over $3m+ or run a critical infrastructure asset. To Home Affairs.
30 days
Data breach assessment
The outer limit to decide whether a suspected breach is an eligible data breach. Notification itself is 'as soon as practicable' once you believe it is.
Dec 2026
Automated decision-making
Privacy policies must disclose automated decisions that significantly affect people. Legislated, with a deferred start.
What applies
Four bodies of obligation, and who each one catches.
Most Australian businesses are touched by the first three. The fourth is the one to watch if you are planning past this financial year.
Notifiable Data Breaches scheme
Privacy Act entities: over $3m turnover, plus health providers and others of any size
Assess a suspected breach reasonably and expeditiously (30 days at the outside) and, if serious harm is likely and you cannot prevent it, notify the OAIC and the people affected.
Read the guide →Cyber Security Act 2024
Businesses over $3m turnover, and critical infrastructure entities
Report ransomware and cyber extortion payments to Home Affairs within 72 hours. Also introduced limited use for information shared with the National Cyber Security Coordinator, smart device security standards from 4 March 2026, and the Cyber Incident Review Board.
Read the guide →The Australian Privacy Principles
Every Privacy Act entity, all the time
Thirteen principles covering collection through to destruction. APP 11 (reasonable steps to secure, and delete what you no longer need) is the one a breach is judged against; APP 8 governs sending data offshore.
Read the guide →Privacy Act reforms
Anyone planning more than a year ahead
A statutory tort for serious invasions of privacy has been actionable since 10 June 2025, penalties have expanded, and automated decision-making transparency starts 10 December 2026. Removing the small business exemption remains proposed, not law.
Read the guide →If it is happening now
The obligations start before you know what you have.
Both clocks start on suspicion, not on certainty: the 30-day assessment runs from when you have reasonable grounds to suspect a breach, and the 72-hour ransomware report runs from the payment. So the first hour is about evidence as much as containment. If you cannot say later what was accessed and when, the assessment defaults to the worst case.
Practically: isolate but do not wipe, keep logs and attacker messages, write down times, and get advice before paying anything. Our incident response and ransomware recovery pages cover the technical first hour.
Who you may need to tell
- The OAIC and affected individuals, if it is an eligible data breach.
- The Department of Home Affairs, within 72 hours, if a ransom was paid.
- The ASD's ACSC via ReportCyber (voluntary, and how you get help).
- Your cyber insurer, often within 24 to 72 hours under the policy.
- Your sector regulator: APRA, ASIC, a law society, or a funding body.
- Customers and partners, where contracts require notice.
Sector rules on top
Your industry probably adds its own.
Legal practices
Uniform Law duties, trust account exposure, law society expectations, and why family law breaches are almost always notifiable.
Financial services
APRA CPS 234 for regulated entities and ASIC's expectations of AFSL holders, on top of the Privacy Act.
Medical and allied health
The small business exemption does not reach health service providers. Any size, still covered.
Not-for-profits and charities
Turnover thresholds, donor data, and the governance expectations that come with grants and government funding.
Want to see who is being breached in Australia right now? The Australian data breach tracker is our running, human-reviewed list.
Common questions
Asked and answered.
These are the questions we get asked mid-incident, when the answer needs to be quick and correct.
What are an Australian business's cyber security legal obligations?
There is no single cyber security law. For most businesses the obligations come from the Privacy Act 1988 (the Australian Privacy Principles, especially APP 11 security, and the Notifiable Data Breaches scheme), the Cyber Security Act 2024 (ransomware payment reporting and smart device standards), and sector rules such as APRA's CPS 234 or ASIC's expectations of licensees. Contracts and cyber insurance policies usually add more.
Do we have to report every cyber incident?
No. Reporting to the ASD's ACSC via ReportCyber is voluntary and recommended. What is mandatory: notifying the OAIC and affected individuals for an eligible data breach under the NDB scheme, and reporting a ransomware or extortion payment to Home Affairs within 72 hours if the Cyber Security Act applies to you. Sector regulators and your insurer may add their own.
Is paying a ransom illegal in Australia?
Not in itself, and the Cyber Security Act does not prohibit it. It requires payment to be reported within 72 hours. Payment can be unlawful under sanctions or proceeds-of-crime law depending on who receives it, so take advice before paying, not after.
What happens if we get it wrong?
Failing to comply with the Privacy Act is an interference with privacy: the maximum civil penalty for serious or repeated interferences is the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, with lower tiers and infringement notices for less serious contraventions. Not reporting a ransomware payment carries its own civil penalty, and Home Affairs moved to active enforcement from 1 January 2026. Since 10 June 2025 individuals can also sue directly for serious invasions of privacy.
Does a security certification satisfy these obligations?
Not automatically, but it helps you evidence them. APP 11 asks for reasonable steps, and an Essential Eight assessment or SMB1001 certification is a documented, independent way to show what you did and why. Certification is evidence, not a defence in itself.
Where does this guidance come from?
It summarises publicly available material from the OAIC, the Department of Home Affairs and the legislation itself, current as at August 2026. It is general guidance for Australian businesses, not legal advice: privacy and cyber law is changing quickly and your circumstances matter, so take your own advice before acting.
The obligations guide
Incident now, or preparing for one?
Obligations are easier to meet when the plan already exists.
We build the NDB assessment and the 72-hour report into your incident response plan, with owners and templates, and our incident reports are structured to support the OAIC statement.
