Asia-Pacific Australia

Australia's NDB Scheme: Notifiable Data Breach Rules

The Notifiable Data Breaches scheme under the Privacy Act: eligible breaches, the 30-day assessment, OAIC notification, remedial-action exceptions, and statistics.

Regulation

Privacy Act 1988 (Cth) Part IIIC (Notifiable Data Breaches scheme, in force 22 February 2018)

Max Penalty

Failure to notify is an interference with privacy: penalties up to AUD 50M / 3x benefit / 30% turnover tier

Enforcing Authority

Office of the Australian Information Commissioner (OAIC)

Official Source

www.oaic.gov.au

Executive Summary

  • Since 22 February 2018, APP entities must notify the OAIC and affected individuals of 'eligible data breaches': unauthorized access, disclosure, or loss likely to result in serious harm to any individual.
  • Suspected breaches trigger a reasonable and expeditious assessment, completed within 30 days, an outer limit the OAIC increasingly criticizes as too slow in practice.
  • Notification must include the entity's identity, breach description, information kinds, and recommended steps for individuals; 'notify as soon as practicable' governs timing once a breach is eligible.
  • The remedial action exception removes the duty where action taken before serious harm materializes makes harm no longer likely, the scheme's main design incentive.
  • OAIC statistics run 800-1,100+ notifications per year, with malicious attacks around two-thirds of them, health and finance leading sectors, and the 2024 period recording the highest counts since inception.

Australia’s breach regime is built around one judgment call: is serious harm likely? No fixed record-count thresholds, no data-category checklists, an objective reasonable-person test applied entity by entity. That design makes the scheme flexible and makes documentation decisive: the entities that fare well with the OAIC are the ones that can show a defensible harm assessment run at speed, and remedial action taken early enough to engage the scheme’s built-in escape valve.

SchemePrivacy Act Part IIIC (NDB), since 22 February 2018
TriggerEligible data breach: serious harm likely
Clocks30-day assessment; notify as soon as practicable
RegulatorOAIC NDB portal

The workflow

1. Detect and contain. Anything that might be an eligible breach starts the assessment duty. Containment first, it feeds the remedial-action exception.

2. Assess within 30 days. A reasonable and expeditious inquiry into what happened, whose data, what protections applied, and whether serious harm is likely. The 30 days are a ceiling, not a target; the OAIC’s reports repeatedly flag entities that consume the full period for straightforward incidents, and the Medibank-era expectation is days, not weeks, for large incidents.

3. Apply the exceptions. Remedial action (harm no longer likely, e.g., a lost device remotely wiped, a misdirected email verifiably deleted), enforcement-related exceptions, and inconsistent-law carve-outs. Document the reasoning either way; the exception analysis is what the OAIC audits after the fact.

4. Notify. Prepare the statement (identity, description, information kinds, recommended steps), submit to the OAIC via its NDB form, and notify individuals through the practicable channel. Where an overseas parent or processor is involved, coordinate so Australian notification content still meets Part IIIC requirements.

5. Remediate and record. The OAIC expects post-incident review evidence, security uplift, and updated response plans, connected to the APP 11 security duty that most post-breach enforcement actually targets.

What the statistics teach

OAIC half-yearly reports consistently show: malicious or criminal attacks cause roughly two-thirds of notifications (phishing, ransomware, credential stuffing), human error most of the rest (misdirected email is perennial), health providers and finance lead sectors, and contact information is the most-exposed data type. Notification volumes hit record levels in 2024, over 1,100 for the year, meaning the scheme now generates the primary public dataset on Australian security failure modes. Treat it as free threat intelligence for your own APP 11 posture, and pressure-test what your public web surfaces expose with a free scan.

Frequently Asked Questions

What makes a breach 'eligible'?

Three elements: (1) unauthorized access to, disclosure of, or loss of personal information; (2) a reasonable person would conclude serious harm to any affected individual is likely; (3) remedial action has not removed that likelihood. Serious harm spans identity theft, financial loss, physical safety, and serious psychological or reputational harm, judged on data sensitivity, protections (encryption), and who obtained it.

How long do we have to notify?

Two clocks: up to 30 days to assess whether a suspected breach is eligible (faster if practicable), then notification to the OAIC and individuals 'as soon as practicable' once eligibility is established. Contractual, insurance, and ASX continuous-disclosure timelines often run shorter in parallel.

Do we have to notify every affected person?

Notify each individual at risk of serious harm, or, if targeting is impracticable, all individuals whose data was involved, or, failing both, publish the statement on your website and publicize it. The OAIC's preferred order is direct notification; publication-only is the fallback and draws scrutiny.

What if our processor or cloud vendor has the breach?

Where multiple entities hold the same records, one notification can cover all, typically the entity with the direct relationship notifies, but the legal duty sits on every entity that 'holds' the information, so contracts should allocate assessment cooperation, notification lead, and cost. APP 11 accountability cannot be outsourced.

What happens if we fail to notify?

Non-compliance with the scheme is an interference with privacy, exposing the entity to OAIC investigation, determinations, enforceable undertakings, and civil penalties up to the top tier (AUD 50M / 3x benefit / 30% turnover for serious interferences). Post-2022 practice shows the OAIC treating late or absent notification as an aggravating factor in wider enforcement.

Regulatory Crosswalk

GDPR Art. 33-34Australian Privacy Principles

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.