Manegy

Notifiable Data Breaches: Privacy Act Rules & Fines for Australian Businesses

23 July 2026

Technology

SHARE

Notifiable Data Breaches: Privacy Act Rules & Fines for Australian Businesses

In October 2025, the Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million in civil penalties under the Privacy Act — the first such penalty in the Act's history. The penalties covered three separate failures: inadequate protection of personal information, a delayed assessment of the suspected breach, and delayed notification to the OAIC. The case established that assessment and notification obligations are each enforceable in their own right, and that the cost of non-compliance is no longer theoretical.


For organisations covered by the Privacy Act, a data breach is not a question of if but when. This article covers who the Notifiable Data Breaches scheme applies to, the two legal obligations it imposes, the OAIC's recommended response framework, and five steps organisations can take to build response readiness before an incident occurs.



Privacy Act 1988: NDB Scheme Coverage & Eligible Data Breaches


The Notifiable Data Breaches (NDB) scheme operates under the Privacy Act 1988 and requires organisations to notify both the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs. Understanding whether the scheme applies, and what constitutes an eligible breach, is the necessary starting point for any data breach response plan.



Which organisations are covered


The NDB scheme applies to all organisations and agencies covered by the Privacy Act. This includes:

  • Private sector organisations with an annual turnover of more than $3 million

  • Health service providers, regardless of turnover

  • organisations that hold tax file number (TFN) information, regardless of turnover

  • Credit reporting bodies and credit providers

  • Australian Government agencies


What counts as an eligible data breach


Not every data breach triggers a notification obligation. An eligible data breach occurs when all three of the following conditions are met:

  1. There has been unauthorised access to, unauthorised disclosure of, or loss of personal information held by the organisation

  2. The breach is likely to result in serious harm to one or more of the individuals whose information is involved

  3. The organisation has been unable to prevent the likely risk of serious harm through remedial action

The threshold of serious harm is central to the scheme. Examples of serious harm include identity theft, financial loss, physical harm, psychological harm, and reputational damage. Where there is uncertainty about whether serious harm is likely, the OAIC recommends erring on the side of notification.




Two legal obligations — assessment and notification


When a suspected data breach occurs, the Privacy Act imposes two distinct obligations on covered organisations. These obligations operate in sequence and on different timeframes. Understanding the difference between them is essential. Failing to meet either obligation can result in civil penalties, as the Australian Clinical Labs decision demonstrated.



The 30-day assessment obligation


Where an organisation has reasonable grounds to suspect that an eligible data breach may have occurred — but has not yet confirmed it — section 26WH of the Privacy Act requires the organisation to carry out a reasonable and expeditious assessment of whether an eligible data breach has in fact occurred. All reasonable steps must be taken to complete the assessment within 30 calendar days of becoming aware of the grounds for suspicion.


The OAIC treats 30 days as an outer limit, not a default timeframe. Organisations are expected to move as quickly as the circumstances allow. Containment measures should begin immediately, in parallel with the assessment, not after it. This includes isolating affected systems, resetting compromised credentials, and restricting access.


The assessment obligation is enforceable in its own right. In the Australian Clinical Labs matter, the Federal Court imposed a separate penalty of AUD 800,000 for the failure to complete the assessment within 30 days, independent of the notification failures.



Notification — as soon as practicable


Once an organisation has reasonable grounds to believe that an eligible data breach has occurred, the notification obligation under sections 26WK and 26WL is triggered. Notification must be provided to both the OAIC and affected individuals as soon as practicable.


Notification to the OAIC is made by submitting a statement through the online Notifiable Data Breach form at oaic.gov.au. Notification to affected individuals must be given directly where practicable. Where direct notification is not practicable — for example, where contact details are unavailable — the organisation must publish a statement on its website and take reasonable steps to publicise it.



When notification is not required


Two situations remove the notification obligation. First, where the organisation determines that the breach is not likely to result in serious harm to any individual. Second, where the organisation takes remedial action before any serious harm occurs, and a reasonable person would conclude that the action has prevented the likelihood of serious harm — in which case the breach is not an eligible data breach under section 26WF, and notification is not required.


In both cases, the organisation's reasoning should be documented. The OAIC may request evidence of the assessment process and the basis on which a decision not to notify was made.




OAIC's four-step response framework


The OAIC's data breach preparation and response guidance organises the response process into four steps: Contain, Assess, Notify, and Review. These steps are not strictly sequential. Containment begins immediately upon discovery, and assessment runs in parallel. The framework provides a structured basis for managing a breach response in a manner consistent with Privacy Act obligations.



Step 1 — Contain


The immediate priority upon discovering a suspected data breach is to limit its spread and prevent further unauthorised access or disclosure. Containment actions will vary depending on the nature of the breach, but may include:

  • Isolating or shutting down affected systems or accounts

  • Resetting compromised passwords and revoking access credentials

  • Quarantining affected devices

  • Terminating active sessions in cloud services or applications

  • Notifying third-party service providers where their systems are involved

Containment does not resolve the breach — it limits further harm while assessment proceeds.



Step 2 — Assess


The assessment step involves determining whether the incident constitutes an eligible data breach and, if so, identifying its scope and likely impact. The assessment should document:

  • What personal information was involved, and the approximate volume affected

  • How the breach occurred and how long it may have been active

  • Whether the information has been, or is likely to be, accessed, used, or disclosed

  • Whether serious harm to affected individuals is likely

  • Whether remedial action can prevent serious harm before it occurs

The assessment must be completed within 30 calendar days of becoming aware of grounds to suspect a breach. Documentation of each step taken — and the reasoning behind key decisions — is essential, as the OAIC may request this material during any subsequent investigation.



Step 3 — Notify


Where the assessment confirms an eligible data breach, notification to the OAIC and affected individuals must be provided as soon as practicable. The OAIC notification is submitted via the online Notifiable Data Breach form at oaic.gov.au.


In some circumstances, it may be appropriate to notify affected individuals before the assessment is fully complete — particularly where the risk of serious harm is high and individuals need to take protective action promptly, such as cancelling a compromised payment card or changing a password exposed in the breach.



Step 4 — Review


Following notification, a review of the breach and the response should be conducted. The review should identify the root cause, assess whether existing security measures were adequate, and determine what changes are needed to reduce the likelihood of recurrence. The outcomes of the review, and any actions taken as a result, should be documented.


The review step is also an opportunity to assess whether the organisation's data breach response plan performed as intended, and to update it accordingly.



Five things to prepare before a breach occurs


A data breach response plan is only effective if it exists before a breach occurs. The following five steps provide a practical basis for organisations to build response readiness in advance — reducing the time lost to improvisation when an incident is confirmed.


1. Document a data breach response plan


The OAIC recommends that all covered organisations have a documented data breach response plan in place. The plan should set out, at a minimum:

  • The roles and responsibilities of each person involved in the response

  • Internal escalation and reporting lines, including when to notify legal counsel and senior management

  • The process for assessing whether an incident constitutes an eligible data breach

  • Contact details for key internal and external stakeholders, including the organisation's legal adviser and any relevant third-party service providers

The OAIC provides guidance on developing a response plan at oaic.gov.au.



2. Audit personal information holdings


An organisation cannot assess the scope of a breach if it does not know what personal information it holds or where it is stored. A regular audit of personal information holdings should identify:

  • The types of personal information collected and held

  • Where that information is stored — including cloud services, third-party platforms, and physical records

  • Who has access to it and under what conditions

  • Retention periods and disposal practices

This audit also supports compliance with the Australian Privacy Principles more broadly, and provides the factual basis needed to respond quickly when an incident occurs.



3. Establish an incident log


All incidents involving potential unauthorised access to, disclosure of, or loss of personal information should be recorded — regardless of whether they are ultimately assessed as eligible data breaches. The log should capture the date the incident was identified, the nature of the incident, the steps taken in response, and the outcome of any assessment.


A documented incident log serves two purposes: it demonstrates to the OAIC that incidents are being identified and managed systematically, and it provides an audit trail if a subsequent investigation requires evidence of the organisation's response history.



4. Familiarise the team with the OAIC notification process


The OAIC's online Notifiable Data Breach form is the required channel for notifying the OAIC of an eligible data breach. Relevant staff should be familiar with the form's requirements before a breach occurs — including what information is needed and who in the organisation is authorised to submit the notification.



5. Check contractual and insurance notification requirements


Privacy Act obligations are not the only notification requirements that may apply. Cyber insurance policies frequently impose shorter notification timeframes — often 24 hours or less — as a condition of coverage. Contracts with clients, government agencies, or third-party service providers may also contain separate breach notification obligations.


Organisations should review all relevant contracts and insurance policies to identify any notification timeframes that are shorter than those required under the Privacy Act, and ensure these are incorporated into the response plan.





The NDB scheme places clear obligations on covered organisations: assess suspected breaches promptly, notify as soon as an eligible breach is confirmed, and maintain the documentation to demonstrate both. The Australian Clinical Labs matter illustrates that failure at any one of these stages carries independent consequences.


Response readiness is not a technical problem alone. Having a documented response plan, an up-to-date record of personal information holdings, and staff who know how to use the OAIC notification form are organisational measures that any business can put in place regardless of size or technical capability.


For guidance on specific obligations or complex breach scenarios, consult a privacy lawyer or contact the OAIC directly at oaic.gov.au.


Official sources:




Last updated: July 2026



SHARE

Latest

Technology

Australian Cyber Threats Hit Every 6 Mins: 2026 Security Guide for Back-Office Teams

Cyber threats targeting Australian organisations are increasing in both frequency and impact — and the data shows that s...

Australian Cyber Threats Hit Every 6 Mins: 2026 Security Guide for Back-Office Teams
HR

Australia’s Right to Disconnect: Employer Guide for HR & Managers (2026 Rules & Award Terms)

The right to disconnect now applies to all Australian private sector employers. For managers and HR teams, the practical...

Australia’s Right to Disconnect: Employer Guide for HR & Managers (2026 Rules & Award Terms)
Finance & Accounting

Permanent $20,000 Instant Asset Write-Off (FY2026-27): ATO Rules & Eligibility for Small Business

For more than a decade, Australian small businesses have navigated the $20,000 instant asset write-off as a temporary me...

Permanent $20,000 Instant Asset Write-Off (FY2026-27): ATO Rules & Eligibility for Small Business
Technology

AI in the back office: how Australian businesses are using it in 2026, and what your organisation needs to have in place

AI tools are already present in most Australian workplaces — including in Finance, HR, and Business Support functions —...

AI in the back office: how Australian businesses are using it in 2026, and what your organisation needs to have in place
HR

Same Job, Same Pay (RLHAOs) in 2026: A Compliance Checklist for Host Employers using Labour Hire

Same Job, Same Pay orders have been legally operative since November 2024, and the first year of enforcement delivered p...

Same Job, Same Pay (RLHAOs) in 2026: A Compliance Checklist for Host Employers using Labour Hire
advertisement