Australia’s breach regime is built around one judgment call: is serious harm likely? No fixed record-count thresholds, no data-category checklists, an objective reasonable-person test applied entity by entity. That design makes the scheme flexible and makes documentation decisive: the entities that fare well with the OAIC are the ones that can show a defensible harm assessment run at speed, and remedial action taken early enough to engage the scheme’s built-in escape valve.
| Scheme | Privacy Act Part IIIC (NDB), since 22 February 2018 |
|---|---|
| Trigger | Eligible data breach: serious harm likely |
| Clocks | 30-day assessment; notify as soon as practicable |
| Regulator | OAIC NDB portal |
The workflow
1. Detect and contain. Anything that might be an eligible breach starts the assessment duty. Containment first, it feeds the remedial-action exception.
2. Assess within 30 days. A reasonable and expeditious inquiry into what happened, whose data, what protections applied, and whether serious harm is likely. The 30 days are a ceiling, not a target; the OAIC’s reports repeatedly flag entities that consume the full period for straightforward incidents, and the Medibank-era expectation is days, not weeks, for large incidents.
3. Apply the exceptions. Remedial action (harm no longer likely, e.g., a lost device remotely wiped, a misdirected email verifiably deleted), enforcement-related exceptions, and inconsistent-law carve-outs. Document the reasoning either way; the exception analysis is what the OAIC audits after the fact.
4. Notify. Prepare the statement (identity, description, information kinds, recommended steps), submit to the OAIC via its NDB form, and notify individuals through the practicable channel. Where an overseas parent or processor is involved, coordinate so Australian notification content still meets Part IIIC requirements.
5. Remediate and record. The OAIC expects post-incident review evidence, security uplift, and updated response plans, connected to the APP 11 security duty that most post-breach enforcement actually targets.
What the statistics teach
OAIC half-yearly reports consistently show: malicious or criminal attacks cause roughly two-thirds of notifications (phishing, ransomware, credential stuffing), human error most of the rest (misdirected email is perennial), health providers and finance lead sectors, and contact information is the most-exposed data type. Notification volumes hit record levels in 2024, over 1,100 for the year, meaning the scheme now generates the primary public dataset on Australian security failure modes. Treat it as free threat intelligence for your own APP 11 posture, and pressure-test what your public web surfaces expose with a free scan.