Act now: Notifiable data breaches for Australian compliance teams
Immediate, practical steps for Australian compliance teams after a suspected data breach. Run the 30 day assessment, follow the 72 hour checklist, and...
If your organisation is an APP entity and a data breach is likely to cause serious harm to individuals, you must notify the Office of the Australian Information Commissioner and the affected people as soon as practicable. Start your assessment and containment work immediately, don’t wait for a full picture before acting, and document every step. If your organisation turns over more than AU$3 million, handles health information, holds tax file numbers, or trades in personal information, the Notifiable Data Breaches scheme almost certainly applies to you.
TL;DR:
- Eligible breaches are those involving unauthorized access, disclosure, or loss of personal information that are likely to cause serious harm and have not been effectively remedied.
- Organizations handling health information, tax file numbers, or trading personal data, especially with over AU$3 million turnover, must comply and report within a maximum of 30 days.
- Notifications to the OAIC and affected individuals must be clear, timely, and include specific details such as the breach description and recommended actions, with multiple regulators potentially involved.
- Rapid remediation measures, documented timelines, and secure communication channels are crucial to prevent a breach from becoming legally “eligible.”
- Staying within Australia-hosted infrastructure and maintaining detailed records significantly reduces breach risks and supports compliance efforts.
Table of Contents
- What the notifiable data breaches scheme covers
- The three-part test for an eligible data breach
- Assessment timing and the 30-day window
- What to include in OAIC and individual notifications
- Concurrent reporting obligations beyond the OAIC
- Remedial action, and why documentation decides your outcome
- Communicating with affected people when direct contact isn’t possible
- A 72-hour checklist for the first response
- Reducing NDB risk with Australia hosted infrastructure
- A quick note on transparency and trust
- Notifying affected people fast, without sending data offshore
- Where to go for authoritative guidance
- Sources
What the notifiable data breaches scheme covers
The NDB scheme sits in Part IIIC of the Privacy Act 1988 and has applied to breaches occurring on or after 22 February 2018. It requires entities to tell the OAIC and affected individuals when an eligible data breach occurs.
Coverage catches more businesses than most compliance officers expect. It applies to government agencies, organisations with annual turnover above AU$3 million, health service providers of any size, and any entity that holds tax file numbers or trades in personal information. A small allied health clinic or a boutique recruitment firm can be squarely in scope even with modest revenue, purely because of what they hold or what they do with it.
The three-part test for an eligible data breach
An eligible breach under the NDB scheme has three elements, and all three need to be satisfied before notification duties kick in. First, there must be unauthorised access, unauthorised disclosure, or loss of personal information. That covers a phishing compromise, a misdirected email with attached client files, a stolen laptop, or a breach at a third-party vendor holding your data.
Second, the breach must be likely to result in serious harm. Think identity theft, financial loss, or genuine psychological or reputational harm, not mere inconvenience. Third, remedial action must not have already removed that likely harm. If you can demonstrate effective remediation, the breach may never become “eligible” in a legal sense, even though something clearly went wrong.
Assessment timing and the 30-day window
Once you suspect a breach, you must run a reasonable and expeditious assessment, and 30 calendar days is the outer limit, not a target. If the facts point clearly to serious harm on day three, you notify on day three. Waiting out the full 30 days when the answer was obvious earlier is itself a compliance failure.
Keep a running log during the assessment: when you first suspected the breach, who you consulted, what evidence you reviewed, and the date you reached a conclusion. Regulators expect that paper trail, and it’s your best defence if the timeline is ever questioned.
What to include in OAIC and individual notifications
Once you’ve confirmed an eligible breach, the OAIC statement needs specific content, and the individual notice needs a different tone. For the OAIC, submit through the NDB online form, which has a read-only training version worth reviewing before your first real submission. Your statement must include:
- Your organisation’s identity and contact details
- A description of the breach itself, in plain terms
- The kinds of personal information involved
- Recommended steps individuals should take in response
For individual notices, be direct rather than defensive. Tell people exactly what happened, avoid softening language that plays down the risk, and give them a concrete action, such as resetting a password or watching for unusual account activity.
Concurrent reporting obligations beyond the OAIC
An eligible breach rarely triggers only one reporting duty. Cyber incidents often need reporting to the Australian Cyber Security Centre as well as the OAIC. Financial entities may owe APRA a separate notification, and tax-related incidents can involve the ATO. Health providers connected to My Health Record have their own reporting channel that runs alongside, not instead of, the NDB scheme.
When several entities or regulators are involved in one incident, work out early who leads communications to avoid conflicting messages. Contact regulator liaison teams as soon as you know an incident is serious, and write down every decision about who was told and when.
Remedial action, and why documentation decides your outcome
Fast, effective remediation can mean a breach never becomes legally “eligible,” even after a genuine security failure. Accepted examples include remotely wiping a device before anyone accessed the data, revoking exposed credentials within hours, and patching an exploited vulnerability before it was used to extract information.
The catch is proof. Regulators scrutinise whether your security obligations under Australian Privacy Principle 11 were met before the incident, not just how you responded after. Document the exact timeline: when the exposure occurred, when you acted, and how you confirmed the risk of harm was removed. Vendor-related incidents need the same rigour, which is one reason vendor due-diligence practices matter well before an incident happens, not during one.

Communicating with affected people when direct contact isn’t possible
Choose your notification channel based on speed and security, not habit. A direct, encrypted email or a phone call usually beats a generic mass mailing when the information involved is sensitive.
If you genuinely cannot reach individuals, the OAIC’s guidance is clear: publish the notification on your website and take reasonable steps to draw attention to it, including social media posts, media outreach, or paid placements where the audience warrants it.
- Draft the notice in plain language, no jargon, no legal hedging.
- Give recipients a clear, specific action, not a vague “be careful” line.
- Provide one dedicated contact point for questions, not a general switchboard.
- Record exactly which channel you used, when, and to how many people.
Pro Tip: Save every draft of your notification, including the versions your lawyers marked up. If the OAIC ever asks how you arrived at the final wording, that revision history shows genuine diligence rather than a rushed afterthought.
A 72-hour checklist for the first response
The first three days set the tone for everything that follows. Work through this order rather than everything at once:
- Contain the incident and capture evidence before anything is altered or deleted.
- Assign an incident owner and begin the documented assessment immediately.
- If the breach looks eligible, draft the OAIC statement and individual notices in parallel.
- Notify the OAIC, affected individuals, and any sector regulators (ACSC, APRA, ATO) without delay.
- Start remediation, brief your regulator liaison contacts, and schedule a formal incident review within the week.
Reducing NDB risk with Australia hosted infrastructure
Where your data physically sits changes your risk profile. Infrastructure hosted entirely within Australia avoids the cross-border disclosure questions that complicate APP 11 compliance the moment data or logs move offshore, a problem covered in more detail in guidance on offshore data transfers.
Practical controls matter more than policy documents. Least-privilege access, encryption at rest and in transit, defined retention limits, and vendor contracts requiring rapid incident disclosure and remote-wipe support all reduce the odds a breach becomes “eligible” in the first place. Retention discipline specifically helps limit what’s exposed if something does go wrong, which is why a documented chatbot data retention policy is worth having before an incident, not after.
A quick note on transparency and trust
Regulators and customers both notice candour. Organisations that notify promptly and explain plainly tend to come out the other side with less lasting damage than those that hedge or delay, a pattern the SprintLaw guidance on NDB compliance backs up. Fast, honest notification isn’t a legal chore, it’s part of a genuine privacy culture.
— Sowrabh
Notifying affected people fast, without sending data offshore
Once you’ve decided notification is required, speed and control matter just as much as legal accuracy. The platform runs on Australia-hosted infrastructure, helping ensure that breach notifications, whether by voice, SMS, email, or chat, remain within the country. That matters when you’re trying to reach thousands of affected customers within hours while your legal team is still finalising wording.
Multichannel agents can push notifications across several channels simultaneously, log when and how each person was contacted, and provide that record for compliance. For organisations in sectors requiring high data privacy standards, this approach offers advantages over using disconnected tools to manage notifications.
If you want to see how this fits your incident response plan, visit Conversational AI and book a compliance discussion before you need it.

Where to go for authoritative guidance
Start with the OAIC directly. Its main NDB scheme page and quick reference guide are the primary sources compliance officers should bookmark, alongside the OAIC’s plain-English explanation of what counts as notifiable.
For practical legal interpretation, DLA Piper’s breach notification summary and SprintLaw’s compliance guidance both translate the legislation into workable business steps. If your organisation is weighing what an unmanaged breach actually costs, the real-world consequences of data breaches are worth a read before you finalise your incident response plan, not after.