Privacy Ready
← Learn

What Happens If My Australian Business Has a Data Breach?

The short answer

If your business has a data breach that is likely to result in serious harm to any individual, you have 30 days under Part IIIC of the Privacy Act 1988 (Cth) to assess it and — if eligible — notify both the OAIC and affected individuals. Failing to notify an eligible breach is itself a serious interference with privacy, attracting penalties of up to $50 million or 30% of adjusted annual turnover.

Step 1 Contain the breach — immediately
Step 2 Assess eligibility — within 30 days
Step 3 Notify the OAIC — as soon as practicable after determination
Step 4 Notify affected individuals — as soon as practicable
Regulator OAIC
Maximum penalty Up to $50M / 30% turnover / 3× benefit (whichever is greatest)

Step 1: Contain the breach immediately

The first priority is limiting ongoing harm. Containment steps depend on the type of incident:

  • Ransomware or cyberattack — isolate affected systems, take them offline if necessary, engage your IT provider, preserve logs
  • Unauthorised access — revoke credentials for the involved account and reset affected passwords immediately
  • Accidental disclosure — contact the unintended recipient and request deletion or return; document whether they confirm compliance
  • Lost or stolen device — initiate remote wipe if the capability exists; record when the device was last confirmed in your possession

Do not delay containment while assessing whether notification is required. They are separate steps.

Step 2: Assess whether the breach is "eligible"

Within 30 days of becoming aware of a suspected breach, complete a reasonable written assessment. The eligible data breach threshold requires all three of the following:

  1. There has been unauthorised access to, disclosure of, or loss of personal information
  2. The information is held by an APP entity
  3. The breach is likely to result in serious harm to one or more affected individuals

Document in writing: what happened and when; what type and volume of information was involved; how many individuals are affected; the realistic probability of serious harm; what containment steps were taken. If you conclude the breach is not eligible, retain the documentation — no formal notification is required.

Step 3: Notify the OAIC

If the breach is eligible, notify the OAIC as soon as practicable using the online form at oaic.gov.au. The notification must include:

  • Your organisation's name and contact details
  • A description of what happened
  • The kinds of personal information involved
  • The number of individuals affected (or a reasonable estimate)
  • Recommended steps individuals should take to protect themselves
  • What actions you have taken or intend to take in response

Step 4: Notify affected individuals

Take reasonable steps to notify each affected individual directly — by email, letter, or phone. The notification should:

  • Explain what happened in plain language
  • Describe what information was involved
  • State what you are doing in response
  • List specific steps the individual should take (e.g., change passwords, monitor bank accounts, contact their bank)
  • Provide your contact details for questions

If direct contact is not practicable for some individuals, you may publish a notification on your website or in a newspaper of general circulation.

What happens after you notify?

After an OAIC notification, the OAIC may close the matter if satisfied with your response, conciliate a related individual complaint, commence a formal investigation under s 40 of the Privacy Act, or apply to the Federal Court for civil penalty orders.

Proactive notification, cooperation, and prompt remediation are consistently treated as mitigating factors in OAIC enforcement. Attempting to conceal an eligible breach significantly increases enforcement risk.

Frequently asked questions

We were breached through a third-party cloud provider. Is it their responsibility to notify?

Both parties may have obligations, but you — as the APP entity that collected and held the personal information — bear primary responsibility for notifying the OAIC and your customers. Review all supplier agreements and include breach notification clauses in future contracts.

Do I need a lawyer before notifying the OAIC?

No. The OAIC's online notification form is straightforward and completing it yourself is appropriate. Legal advice may be valuable for large breaches or if you anticipate a formal investigation. But waiting for legal advice is not a recognised extension to the 30-day timeframe.

Can the OAIC pursue us for the security failure as well as for failing to notify?

Yes. If the breach resulted from a failure to maintain reasonable security measures, that failure is a potential separate contravention of APP 11 — distinct from any notification obligation. The OAIC can investigate and pursue penalties for both the underlying security failure and the notification failure.

If we notify and cooperate fully, will the OAIC still investigate?

Notification triggers a review, not automatically an investigation. The OAIC closes many notifications without further action where the breach was modest in scale, harm was low, the response was appropriate, and notification was timely. Investigations are more likely for large breaches, repeated incidents, or evidence of systemic failure.

What should we tell affected customers to do?

Tailor the advice to what was compromised. For passwords: recommend changing them and enabling two-factor authentication. For financial credentials: contact their bank and monitor accounts. For government identifiers (TFN, Medicare): contact the ATO or Services Australia. Always provide a contact point for their questions.

The free Privacy Act Business Applicability Check confirms whether the NDB scheme applies to your business and what your breach response obligations look like from 1 July 2026.

Check my breach obligations →