A cyber breach in a legal practice is not only a privacy event. It can touch privileged material, documents produced on discovery, and matter under suppression. Legal professional privilege does not switch off when a breach happens. It also does not excuse you from notifying. The two sit alongside each other, and managing both at once is what makes breach response in a law firm different from breach response anywhere else.
Privilege does not override notification
Start with the point that catches some practices out. Legal professional privilege does not relieve you of your obligations under the Privacy Act 1988 or the . If has been accessed without authority and serious harm is likely, the duty to assess and to notify the still applies.
What privilege shapes is the detail: what you can say, and to whom. You can describe that a breach occurred and what categories of information were involved without disclosing the privileged content of the documents themselves. The obligation to notify and the duty to protect privilege are not in conflict, but they have to be handled together, with care taken over wording.
Assessing the breach can raise waiver questions
To notify, you have to know what was accessed. That assessment itself raises questions. Does the affected material remain privileged. Has privilege been waived by the access or by what you do next. These are not abstract worries. The answers affect how you can use the material later and how you describe the breach.
Bringing in external forensic investigators is often the right step, but it can raise waiver questions of its own. Giving a third party access to privileged material, and creating reports about it, can affect the privilege that attaches to that material. This is why the engagement should be structured carefully, frequently through counsel, so that the investigation is conducted in a way that protects privilege rather than quietly eroding it.
Discovery and the implied undertaking
Many legal files contain documents produced by another party on discovery. Those documents come with an implied undertaking: they may only be used for the proceedings in which they were produced. They are not yours to use freely, and they are not yours to lose freely either.
If a breach touches that material, you have a problem that reaches beyond privacy. The undertaking is owed to the court. A breach that exposes documents held under it can engage obligations to the court, separate from anything owed to the individuals concerned or to the OAIC. That is a second front to manage, and it is easy to miss if you treat the incident as a privacy matter alone.
Suppression orders and the risk of contempt
Some matters are subject to suppression orders. The material is restricted from publication by order of the court. If a breach leads to suppressed material being published, the practice may face a contempt risk on top of everything else. This is a particular concern for criminal defence practices, where suppression orders, public interest immunity and the protection of informants are part of ordinary work.
The point is not that a breach makes you guilty of contempt automatically. It is that a breach can put you in a position where suppressed material is exposed, and the consequences of that sit in a different and serious category. Your response plan has to recognise which files carry that exposure before anything goes wrong.
Work it through with counsel, in advance
None of this should be improvised at the moment of crisis. Whether forensic investigators can be engaged without waiving privilege, how a notification can be written without disclosing privileged content, which files are under suppression or held on discovery undertakings: these questions should be worked through with experienced counsel before a breach, and recorded in a tested response plan.
A plan written calmly, with counsel involved, gives you a path to follow when you have very little time and a great deal at stake. It tells you who to call, how to structure the investigation, and what you can and cannot say.
Build the plan now
IronSights helps Australian legal practices, including criminal defence firms, build a breach response plan that accounts for privilege, discovery undertakings and court obligations, not just the privacy steps. We work with your technical controls in and with your counsel so the plan holds together. A security review is a practical first step toward knowing where you stand.



