A lost laptop, compromised email account or confidential file sent to the wrong person may be a data breach. But that does not automatically make it a notifiable data breach under Australian law.
The key question is whether the incident meets the threshold for an eligible data breach under the Notifiable Data Breaches (NDB) Scheme.
For organisations covered by the scheme, that means assessing whether personal information has been compromised, whether serious harm to an individual is likely, and whether remedial action can remove that risk. If the breach is eligible, the Office of the Australian Information Commissioner (OAIC) and relevant individuals must be notified.
This article explains that test, the often-misunderstood 30-day timeframe and the practical steps to take after a suspected breach.
What Is a Notifiable Data Breach?
“Notifiable data breach” is the phrase people commonly search for, but the Privacy Act 1988 uses the term eligible data breach for an incident that triggers notification obligations under the NDB Scheme.
A data breach may occur when personal information held by an organisation or agency is:
- accessed without authorisation;
- disclosed without authorisation; or
- lost in circumstances where unauthorised access or disclosure is likely.
However, a breach is not automatically eligible for notification simply because personal information was involved.
In general, the NDB Scheme requires notification where the breach is likely to result in serious harm to one or more individuals and remedial action has not removed that likely risk. The OAIC explains this decision process in its guidance on when to report a data breach.
The NDB Scheme sits within Australia's broader privacy framework. Businesses that need the wider context can first look at how the Australian Privacy Principles work.
Quick answer: A data breach generally becomes an eligible data breach when personal information has been compromised, serious harm is likely, and effective remedial action has not removed that risk.
Does Every Data Breach Have To Be Reported?
No. Australian organisations do not need to report every privacy or security incident to the OAIC.
The first task is to determine whether the breach satisfies the NDB Scheme's eligibility requirements.
The Three-Part Eligible Data Breach Test
A useful way to assess the issue is to work through three questions.
1. Has a data breach occurred?
There must first have been unauthorised access to or disclosure of personal information, or a loss of information in circumstances where unauthorised access or disclosure is likely.
This could include an employee accessing records without a legitimate reason, an external attacker gaining access to customer information, a confidential file being accidentally published or physical records being lost in public. These are examples reflected in the OAIC's quick reference guide for responding to data breaches.
2. Is serious harm likely?
The question is not whether harm is merely possible. The OAIC's current NDB guidance explains that serious harm is “likely” where it is more probable than not, assessed from the perspective of a reasonable person in the entity's position.
3. Has remedial action prevented the likely serious harm?
Prompt remedial action matters. If an organisation acts effectively and the breach is no longer likely to cause serious harm, the incident may not become an eligible data breach requiring notification.

In simple terms:
Data breach + likely serious harm + unsuccessful remedial action = eligible data breach
What Can Count As Serious Harm?
The Privacy Act does not reduce serious harm to one fixed outcome.
According to the OAIC's eligible data breach decision guidance, serious harm may include:
- physical harm;
- psychological or emotional harm;
- financial harm; or
- reputational harm.
The assessment should consider the actual circumstances. Relevant factors may include the sensitivity of the information, how strongly it was protected, who may have obtained it, whether that person could overcome security measures, how the information could be misused and the consequences for affected individuals.
That is why the same type of incident can produce different notification outcomes in different organisations.
Who Does The Notifiable Data Breaches Scheme Apply To?
The NDB Scheme applies broadly to entities that have relevant personal information security obligations under the Privacy Act.
The OAIC's 2026 quick reference guidance identifies covered entities including Australian Government agencies, businesses and not-for-profit organisations with annual turnover above $3 million, private-sector health service providers, credit reporting bodies, credit providers and some smaller organisations.
A business with annual turnover of $3 million or less should not automatically assume the scheme does not apply.
The Privacy Act can still cover particular small businesses, including certain health service providers, businesses trading in personal information, Commonwealth contractors, credit reporting bodies, businesses accredited under the Consumer Data Right system and businesses that have opted into Privacy Act coverage.
The OAIC guidance for small businesses provides a fuller coverage checklist.
Coverage can also depend on the information involved and the particular activity being carried out, so businesses with uncertainty about their legal position should check the current requirements that apply to their circumstances.
What Is The 30-Day Rule For A Notifiable Data Breach?
One of the most common misunderstandings about the NDB Scheme is that Australian organisations simply have 30 days to report a data breach.
That is not the rule.
The 30-day period relates to assessing a suspected eligible data breach. It is not a blanket 30-day reporting deadline.
When Does The 30-Day Assessment Period Start?
Under section 26WH of the Privacy Act, where an entity becomes aware of reasonable grounds to suspect that an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment.
The entity must also take all reasonable steps to ensure that assessment is completed within 30 days after becoming aware of the grounds for suspicion.
The 30 days should therefore not be treated as a period in which nothing needs to happen. The legal requirement is to assess the incident reasonably and expeditiously.
When Must The Breach Be Reported?
There is an important change in language once the evidence becomes stronger:
Reasonable grounds to suspect → assess
Reasonable grounds to believe → notify
Under the Privacy Act notification requirements, an entity that has reasonable grounds to believe an eligible data breach has occurred must prepare the required statement and give it to the Information Commissioner as soon as practicable.
The OAIC's guidance on responding to eligible data breaches similarly explains that individuals at risk of serious harm and the OAIC should be notified as soon as practicable where notification is required.
|
Stage |
What The Timeframe Means |
|
Suspected eligible breach |
Assess reasonably and expeditiously and take all reasonable steps to complete the assessment within 30 days |
|
Eligible breach established |
Notify the OAIC and relevant individuals as soon as practicable, subject to applicable exceptions |

So an organisation should not wait until day 30 if the assessment establishes an eligible breach earlier.
What Should You Do After A Suspected Data Breach?
The OAIC's 2026 data breach response guidance uses a practical four-stage model: contain, assess, notify and review.
1. Contain The Breach
Take reasonable action to stop the incident from continuing or becoming worse.
Depending on the circumstances, that might involve restricting compromised account access, recovering incorrectly sent information, securing exposed records or stopping further disclosure.
At the same time, preserve the information your organisation needs to investigate what happened and escalate the incident through the appropriate privacy, security, legal or management process.
Containment is an immediate response step. It does not replace the need to assess whether the NDB Scheme applies.
2. Assess What Happened
The assessment should establish enough facts to make a defensible decision.
Questions may include:
- What personal information was involved?
- Whose information was affected?
- Was the information actually accessed or disclosed?
- Who may have obtained it?
- How sensitive was it?
- What protections were in place?
- What harm could realistically result?
- Can remedial action prevent that harm?
If the organisation only has reasonable grounds to suspect an eligible breach, the 30-day assessment requirement discussed above becomes particularly important.
3. Notify The OAIC And Relevant Individuals If Required
Where an eligible data breach is established, and no relevant exception applies, the organisation must notify the OAIC and individuals at risk of serious harm.
The OAIC's data breach reporting requirements explain that the statement should include:
- the entity's identity and contact details;
- a description of the data breach;
- the kinds of information involved; and
- recommendations about steps individuals should take in response.
Organisations can also report an eligible data breach to the OAIC through the regulator's NDB reporting process.
Notifications to individuals should be practical and understandable. The OAIC's breach response guidance recommends communicating in plain English rather than relying on complex technical language.
4. Review The Incident
The work should not finish once notifications have been sent.
Good post-incident practice includes documenting what happened, recording the assessment and notification decision, identifying weaknesses, reviewing third-party arrangements where relevant and updating processes that failed.

Staff also need to know how to recognise an incident and where to escalate it. ACT's Privacy & AI Governance training covers Privacy Act obligations, NDB rules, incident response, and NDB reporting protocols for Australian professionals.
Notifiable Data Breach Examples
Whether a breach is notifiable depends on the facts. These examples illustrate the questions an organisation may need to ask rather than providing automatic legal conclusions.
|
Scenario |
Could It Be Notifiable? |
Main Question |
|
HR emails sensitive employee records to the wrong external recipient |
Potentially |
Was the information accessed, and is serious harm likely? |
|
A customer database is accessed during a cyberattack |
Potentially |
What information was accessed and what harm could follow? |
|
A laptop containing personal information is lost |
It depends |
Could an unauthorised person access the information despite any security controls? |
|
A document is misdirected but recovered or securely deleted before it can be accessed |
Possibly not |
Did remedial action remove the likely risk of serious harm? |
|
A cloud or SaaS provider exposes customer information |
Potentially |
Which entities hold the information and does the incident meet the eligible-breach test? |

Third-party incidents deserve particular attention. The OAIC's guidance on data breaches involving more than one entity explains that where multiple entities jointly hold the affected information, they may coordinate the assessment and notification process.
The entity with the most direct relationship with affected individuals may often be best placed to communicate with them.
That does not mean outsourcing a service automatically outsources privacy responsibility. The organisations involved still need to determine how their obligations apply to the incident.
What Happens If A Notifiable Data Breach Is Not Reported?
Failing to comply with applicable NDB obligations can become a regulatory issue under the Privacy Act.
The Privacy Act 1988 provides that contraventions of specified NDB assessment and notification requirements can amount to an interference with the privacy of an individual.
Depending on the circumstances, the OAIC has investigative and enforcement powers available under the Act. Its privacy regulatory action policy explains that regulatory decisions take account of matters such as the seriousness of the conduct and whether issues appear systemic.
It would therefore be misleading to attach one headline penalty figure to every failure to notify. The consequences depend on the actual contravention, circumstances and regulatory response.
For businesses, the more useful approach is to make sure incidents are recognised, escalated and assessed promptly rather than relying on assumptions about whether notification will be necessary.
How Can Organisations Prepare Before A Data Breach Happens?
A breach is much easier to manage when responsibilities have been decided before an incident occurs.
Practical preparation can include:
- maintaining a documented data breach response plan;
- assigning clear responsibility for breach assessment and escalation;
- ensuring staff know how and where to report suspected incidents;
- keeping response-team contact details current;
- setting expectations with cloud, payroll and other service providers about incident escalation; and
- reviewing or testing the response process periodically.
The OAIC's guidance on preparing for and responding to data breaches provides practical regulator resources for organisations managing these issues.
Breach readiness is only one part of privacy governance, so employers reviewing their wider processes can use ACT's Privacy Act compliance checklist to assess collection, security, training, retention and other controls.
For professionals who need structured training across Privacy Act obligations, APP governance and NDB incident response, ACT's Privacy & AI Governance course provides an Australian-focused learning pathway.
Responding At The Right Time Matters
Not every Australian data breach is automatically notifiable. What matters is whether the incident meets the eligible data breach threshold under the NDB Scheme.
The 30-day rule is also narrower than it is sometimes presented: it concerns the assessment of a suspected eligible breach, not a general 30-day window in which an organisation can delay reporting.
For organisations handling personal information, the practical sequence is straightforward: recognise the incident, escalate it, assess it promptly, take effective remedial action where possible and notify when the NDB requirements are met.
