Key takeaways
- Under the Notifiable Data Breaches (NDB) scheme, eligible data breaches must be reported to the OAIC and the people affected.
- A breach is eligible when personal information is lost or accessed without authorisation, serious harm is likely, and remedial action can't prevent it.
- If you suspect an eligible breach, you must take reasonable steps to assess it within 30 days.
- Businesses that provide a health service and hold health information are covered by the Privacy Act regardless of turnover.
Who the scheme applies to
The NDB scheme applies to organisations covered by the Privacy Act 1988, known as APP entities. Most businesses with annual turnover above $3 million are covered, and any business that provides a health service and holds health information is covered whatever its turnover. If your practice holds health information, assume the scheme applies to you.
What makes a breach eligible
- Personal information has been lost, or accessed or disclosed without authorisation.
- That is likely to result in serious harm to one or more individuals.
- You haven't been able to prevent the likely risk of serious harm with remedial action.
Common examples include a lost or stolen laptop, a hacked email account, ransomware on a server, or patient documents sent to the wrong recipient.
The 30-day clock
Suspicion starts the clock. When you have reasonable grounds to suspect an eligible breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. If you then believe an eligible breach has occurred, you must notify the OAIC and affected individuals as soon as practicable.
A response plan in four steps
1. Contain
Stop it getting worse: disconnect affected devices from the network, reset compromised passwords, revoke access, and recall misdirected emails where possible. Don't wipe devices, because you may need the evidence.
2. Assess
Work out what information was involved, whose it was, whether it was protected (for example encrypted), and whether remedial action can still prevent serious harm. Record every step and decision.
3. Notify
If it is an eligible breach, prepare a statement for the OAIC covering who you are, what happened, the kinds of information involved and what individuals should do. Then notify the people affected.
4. Review
Fix the cause, and update policies, training and technical controls so it doesn't happen again.
Prepare before it happens
- A written data breach response plan, with names and phone numbers
- Staff who know to report a suspected breach immediately
- Encrypted laptops and phones, so a lost device is less likely to cause serious harm
- Multi-factor authentication on email and remote access
- Logging switched on, so you can see what was accessed
- An IT provider who can contain and investigate quickly
This guide is general information, not legal advice. For a specific incident, refer to the OAIC's guidance and consider getting legal advice.
Common questions
How long do I have to report a data breach in Australia?
You must take reasonable steps to assess a suspected eligible breach within 30 days. If it is confirmed as eligible, notify the OAIC and affected individuals as soon as practicable.
Does every data breach need to be reported?
No. Only eligible breaches, where serious harm is likely and can't be prevented by remedial action. You should still record and learn from other incidents.
Is a ransomware attack a notifiable data breach?
It can be. If personal information was accessed, taken or lost without a usable backup, and serious harm is likely, it may well be eligible. Assess it promptly.
Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.
Sources
- OAIC, Part 4: Notifiable Data Breach (NDB) Scheme
- OAIC, Notifiable data breaches statistics dashboard (notes)
- OAIC, Small business
General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.
