Privacy Ready
← Learn

What Counts as a Notifiable Data Breach in Australia?

The short answer

Under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth), a breach is notifiable when it involves personal information, there has been unauthorised access, disclosure, or loss, and the breach is likely to result in serious harm to one or more affected individuals. Once a suspected breach arises, you have 30 days to assess whether it meets the threshold and — if it does — notify both the OAIC and affected individuals.

Governing law Privacy Act 1988 (Cth), Part IIIC
Scheme Notifiable Data Breaches (NDB)
Who it applies to All APP entities — including ~100,000+ small businesses from 1 July 2026
Assessment window 30 days from becoming aware of a suspected breach
Who to notify OAIC + affected individuals
Threshold Likely to result in serious harm to one or more individuals
Maximum penalty Up to $50M for serious or repeated non-compliance

What is an "eligible data breach"?

The NDB scheme uses the term "eligible data breach." Three conditions must all be satisfied:

  1. There has been unauthorised access to, or unauthorised disclosure of, personal information — or personal information has been lost in circumstances where unauthorised access or disclosure is likely
  2. The breach involves personal information held by an APP entity
  3. The breach is likely to result in serious harm to one or more of the individuals whose information is involved

If any one of those three conditions is not met, the breach is not eligible and formal notification to the OAIC is not required — though internal documentation of the assessment is still good practice.

What types of incidents commonly trigger NDB?

Incidents that often qualify as eligible data breaches:

  • Ransomware or cyberattack — exfiltration of customer or employee data is almost always eligible; encryption-only incidents may still qualify depending on the sensitivity of the data
  • Accidental email disclosure — sending a customer file to the wrong recipient, or using CC instead of BCC for a group mailing
  • Lost or stolen devices — an unencrypted laptop or phone containing customer records
  • Insider access — an employee accessing files they are not authorised to see and potentially copying or disclosing them
  • Third-party breach — a SaaS vendor is compromised and your customers' data is exposed; you have obligations as the APP entity that originally collected and held the data

Incidents that typically do not meet the threshold: accidentally deleted data with no sensitive content and no confirmed unauthorised access; a staff member who briefly views the wrong record and immediately corrects the error with no onward disclosure.

What does "likely to result in serious harm" mean?

"Likely" means more probable than not — a greater than 50% chance. "Serious harm" under Part IIIC includes:

  • Serious physical, psychological, emotional, financial, or reputational harm
  • Identity theft or fraud
  • Discrimination
  • Exposure of sensitive information (health, sexual orientation, biometric data, etc.)
  • Physical danger arising from disclosure (e.g., location data of a person in a domestic violence situation)

The higher the sensitivity of the information, the lower the bar for concluding serious harm is likely. Health information, financial account credentials, and government identifiers (Tax File Numbers, Medicare numbers) are almost always treated as sensitive.

What must you do within the 30-day assessment window?

When your business becomes aware of a suspected breach, 30 days begins. During that window:

  1. Contain the breach — stop ongoing access, isolate affected systems, revoke credentials where possible
  2. Identify the information involved — type, sensitivity, volume
  3. Identify how many individuals are affected — or estimate if exact numbers are unavailable
  4. Assess the realistic risk of serious harm — considering the nature of the information and plausible ways it could be misused
  5. Document the assessment in writing — retain this regardless of whether the breach is ultimately notifiable

If after 30 days you conclude the breach is eligible, notify the OAIC and take reasonable steps to notify affected individuals — directly where practicable.

What must an OAIC notification include?

A notification to the OAIC must contain:

  • Your organisation's identity and contact details
  • A description of the breach — what happened, how, and when
  • The kinds of personal information involved
  • The number or estimate of individuals affected
  • The steps you recommend individuals take to protect themselves
  • Your response actions

There is an online notification form at oaic.gov.au.

Frequently asked questions

Does the NDB scheme apply to my business if I'm only newly regulated from 1 July 2026?

Yes. Once the small business exemption is removed on 1 July 2026, you become an APP entity and the NDB scheme applies immediately. Any eligible data breach occurring on or after that date must be assessed and, if eligible, notified under Part IIIC of the Privacy Act.

Do I need to notify every person whose data was in a breached file?

Only individuals for whom the breach is likely to result in serious harm. If a file of 500 customer records is breached but only a subset contains sensitive financial data, your notification obligation may be limited to those individuals — depending on your assessment of harm likelihood.

Can I self-report a breach without being penalised?

Proactive notification is not in itself an admission of wrongdoing and does not automatically attract penalties. Penalties are more likely for failure to report an eligible breach, or for the underlying security failures that caused it. Cooperating with the OAIC is consistently treated as a mitigating factor in enforcement outcomes.

Is there a minimum number of people affected before notification is required?

No. Even a breach affecting one individual is notifiable if it meets the eligibility threshold — particularly where sensitive information such as health data, financial details, or government identifiers is involved.

What if a third-party vendor caused the breach — is it their responsibility to notify?

Both parties may have obligations, but you as the APP entity that collected and held the personal information bear primary responsibility for notifying the OAIC and your customers. Review contracts with all third-party processors to ensure they are required to notify you promptly so your 30-day assessment window does not run while you remain unaware.

The free Privacy Act Business Applicability Check confirms whether the NDB scheme applies to your business and what your response obligations look like from 1 July 2026.

Check my NDB obligations →