Most data breach assessments turn on a single question: is serious harm likely. In family law, that question is usually answered before you finish reading the file. The material these matters hold is sensitive by nature, and the people it concerns are often already in difficult circumstances. So a breach in a family law practice will rarely sit on the line. It will usually clear the threshold.
What a family law file actually holds
Consider the contents of an ordinary contested matter. Affidavits set out family violence disclosures in plain detail. Parenting documents record children's living arrangements, including the address of a parent and children who may be protected from the other party. Financial affidavits list assets, accounts and income. Medical and psychological reports are tendered as exhibits. Subpoenaed material from police, schools and hospitals sits in the same folder.
Any one of these documents, in the wrong hands, can cause real harm. Together, they describe a person's whole situation: where they live, what they fear, what they have, and what they have told the court. That is why unauthorised access to a family law file so readily meets the serious-harm test the applies under the . The Privacy Act 1988 sets the obligation, and for practices above the $3 million turnover threshold it applies directly.
A threat most commercial practices do not face
When people think about a breach, they tend to picture a criminal group looking for data to sell. Family law carries a different and more pointed threat. In a contested matter, there is an opposing party with a direct motive to reach the file. They want the address. They want the affidavit. They want to know what the other side has told the court.
This is not a theoretical concern. The OAIC has received complaints in family law matters where the issue was targeted access rather than a broad criminal attack. Someone with a personal interest in the proceedings sought information they were never entitled to see. That changes how you think about risk. The danger is not only the anonymous attacker on the internet. It can be a person already named in the matter.
Internal controls do most of the work
Because the threat is often targeted, internal controls matter as much as the perimeter. The principle is simple: staff should only see the matters they work on. Role-based access in your practice management system and in Microsoft 365 keeps a file from being open to everyone in the office by default.
A few measures carry most of the weight:
- Role-based access so a person assigned to a matter can open it, and others cannot.
- Microsoft Purview applied to family law documents, so the most protected material is marked and tracked.
- permissions set per matter, rather than a single shared folder the whole practice can browse.
- on every account, so a stolen password alone does not open the door.
These controls also help you answer the questions that follow a breach. If access is restricted and logged, you can establish who could have reached a file and who actually did. Without that, you are guessing, and you cannot guess your way through a notification assessment.
From discovery to notification
Once you suspect a breach, the clock starts. The steps are well established. Assess as soon as practicable. Contain the access so it cannot continue. Identify whose information was involved. Draft the notifications to affected individuals and to the OAIC. Tell your professional indemnity insurer early, because they will often want to be involved from the start.
Family law adds care that other matters do not need. A notification may reach someone in a vulnerable situation, and the notice itself should not make things worse. If a file is subject to a suppression order, what you can say, and to whom, is constrained. The contents of the notification, the timing, and the channel all need thought. A standard template written for a commercial breach will not be right here.
Plan it before you need it
The time to work out how you will respond is not the morning you discover the breach. It is now, while you can think clearly and involve the right people. IronSights works with Australian family law practices to protect their files with role-based access, sensitivity labels and tested controls, and to plan a breach response that accounts for the people these matters concern. A short security review is a sensible place to start.



