IronSights

Privacy Act 1988 · Part IIIC

The Notifiable Data Breaches scheme: who must notify, when, and how.

If personal information you hold is accessed, disclosed or lost and someone could be seriously harmed, the Privacy Act gives you a process and a clock. Here is the scheme in plain English: who it covers, what an eligible data breach is, the 30-day assessment, and what you send to the OAIC.

General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.

Who the scheme covers

Everyone the Privacy Act covers, which is more businesses than assume so.

The NDB scheme applies to “APP entities”: Australian Government agencies and the organisations the Privacy Act reaches. The $3 million turnover line is the headline, but the exceptions catch a lot of small businesses that hold sensitive information.

Organisations with annual turnover over $3 million

The general rule. If your business turns over more than $3 million a year, the Privacy Act and the NDB scheme apply to you.

Health service providers, whatever their size

A medical practice, allied health clinic, gym with health records or childcare centre holding health information is covered even under $3 million. The small business exemption does not reach them.

Businesses that trade in personal information

Buying or selling personal information, credit reporting bodies and credit providers, and recipients of tax file numbers are in, regardless of turnover.

Contracted service providers to the Commonwealth

If you hold personal information under a Commonwealth contract, the scheme follows the contract into your business.

Medical or allied health practice under $3 million? You are still covered. The small business exemption itself is under review in the second tranche of Privacy Act reforms.

What has to be notified

An “eligible data breach” has three parts.

  1. 1Unauthorised access to, unauthorised disclosure of, or loss of personal information you hold.
  2. 2A reasonable person would conclude the access, disclosure or loss is likely to result in serious harm to one or more individuals.
  3. 3You have not been able to prevent the likely risk of serious harm with remedial action.

“Loss” matters: a laptop left in a taxi or a backup drive that cannot be accounted for is a breach if the information on it could be accessed. And a breach at a contractor or cloud provider you use is your breach to assess, not only theirs.

Is serious harm likely? What the OAIC weighs

  • The kind and sensitivity of the information: health, financial, identity documents and children's data weigh heavily.
  • Whether the information was protected, for example encrypted with a key the attacker did not get.
  • Who has it, and whether they are likely to misuse it (a ransomware crew is not a misdirected email).
  • How many people are affected and how easily the data could be combined with other information.
  • The nature of the harm: identity theft, financial loss, physical safety, discrimination, humiliation, reputational damage.

Ransomware note claiming data theft? Treat the claim as something to verify, not accept: what was actually taken decides the assessment, and the forensic timeline is how you find out.

The process

Five steps, two clocks.

The assessment clock (30 days from suspicion, at most) and the notification clock (as soon as practicable once you believe it is eligible). Both run while you are also trying to contain the incident, which is why the first step is the technical one.

  1. 01

    Contain and preserve

    Stop the access, isolate what you can without destroying evidence, and start a timeline. The clock on the assessment starts when you have reasonable grounds to suspect a breach, so note the time.

  2. 02

    Assess, within 30 days at most

    Decide whether it is an eligible data breach: was personal information accessed, disclosed or lost, and is serious harm to any individual likely? The Act says the assessment must be reasonable and expeditious, and finished within 30 days of the suspicion. Thirty days is the ceiling, not the target.

  3. 03

    Apply remedial action if it truly removes the risk

    If you act quickly enough that serious harm is no longer likely (for example, a misdirected email recalled and deleted with confirmation), it is not an eligible data breach. Document why you concluded that.

  4. 04

    Notify the OAIC and the people affected

    As soon as practicable after you form the view that it is eligible: prepare a statement and submit it to the OAIC through its Notifiable Data Breach form, then notify the individuals at likely risk, or publish the statement if you cannot reach them.

  5. 05

    Keep records, fix the cause

    The OAIC can ask what you found and when. The incident report, the root cause and the hardening you did afterwards are what demonstrate you took reasonable steps, which is its own obligation under APP 11.

What you send

The statement to the OAIC, and to the people affected.

The statement goes to the OAIC through its online Notifiable Data Breach form. Then you notify individuals: all of them, or those at likely risk of serious harm, by the way you would normally contact them. If you cannot reasonably do either, you publish the statement on your website and take steps to publicise it.

Write it for the reader, not the regulator: what happened, what of theirs is involved, and what they should do now (change passwords, watch accounts, use IDCARE). A good incident report makes this a short exercise.

The statement must include

  • Your organisation's identity and contact details
  • A description of the breach, including how and when it happened
  • The kinds of personal information involved
  • What you recommend affected people do in response
  • (If notifying individuals directly) the same content, in plain language, by the method you normally use to contact them

Other obligations can run alongside: a ransomware payment report under the Cyber Security Act 2024, ASIC or APRA expectations in regulated sectors, contractual notice to customers, and your cyber insurer's notification clause, which is often the shortest of all.

Common questions

Asked and answered.

Mid-incident and not sure whether it is notifiable? That is precisely the question our incident reports are built to answer, on evidence.

  1. What is the Notifiable Data Breaches scheme?

    Part IIIC of the Privacy Act 1988, in force since 22 February 2018. It requires entities covered by the Privacy Act to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs: unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to any of the people it relates to, and that remedial action has not prevented.

  2. Does the NDB scheme apply to my small business?

    If your annual turnover is over $3 million, yes. Under $3 million you are generally exempt from the Privacy Act, with important exceptions: private-sector health service providers of any size, businesses that trade in personal information, credit reporting bodies and credit providers, tax file number recipients, and contracted service providers to the Commonwealth are all covered. Our article on the medical practice exemption explains the most common surprise.

  3. What counts as serious harm?

    The Act does not define it with a threshold; the OAIC's guidance lists the factors: the kind and sensitivity of the information, whether it was protected (for example encrypted), who is likely to have obtained it and what they might do, and the nature of the harm, which includes identity theft, financial loss, threats to physical safety, discrimination, humiliation and reputational damage. Health, financial and identity-document data almost always clears the bar.

  4. How long do we have to notify?

    Two clocks. The assessment: if you suspect a breach, you must assess whether it is eligible reasonably and expeditiously, and within 30 days of the suspicion at the latest. The notification: once you have reasonable grounds to believe it is an eligible data breach, you must notify the OAIC and affected individuals as soon as practicable. In practice, serious incidents are notified in days, not weeks; the 30 days is a backstop for genuinely uncertain cases.

  5. Who do we notify, and how?

    The OAIC, through its online Notifiable Data Breach form, with a statement describing the breach, the information involved and your recommendations to affected people. Then the individuals: either everyone whose information was involved, or only those at likely risk of serious harm, by your normal means of contact; if neither is practicable, you publish the statement and take reasonable steps to publicise it.

  6. What are the penalties for not notifying?

    Failing to comply with the scheme is an interference with privacy under the Privacy Act. Since December 2022 the maximum civil penalty for serious or repeated interferences is the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover for the period, and the 2024 reforms added lower penalty tiers and infringement notices for less serious contraventions. Beyond penalties, the OAIC can investigate, issue determinations and require remediation, and the publicity of a late or missing notification is usually the larger cost.

  7. We paid a ransom. Is that a separate report?

    Yes. A ransomware or cyber extortion payment by a business with annual turnover of $3 million or more must be reported to the Department of Home Affairs within 72 hours under the Cyber Security Act 2024, which is entirely separate from any NDB notification. Both can apply to the same incident.

  8. Does IronSights help with NDB notifications?

    Yes. Our incident response reports are structured to support the assessment and the OAIC statement (what happened, when, what information, what we recommend), and we help with the notification process directly. Whether and what to notify remains a decision for you and your legal adviser; we make sure it rests on evidence rather than guesswork.

Incident now, or preparing for one?

Breach in progress, or want the plan written before you need it?

Our incident response runs contain, investigate, eradicate, recover and report, with the report structured for the OAIC statement. A retainer puts the terms and the plan in place ahead of time.