The information on this website is general in nature and does not take into account your objectives, financial situation, or needs. Consider seeking personal advice from a licensed adviser before acting on any information.
A data breach can create more than a technical problem. For Australian businesses, it can also raise notification, reporting, legal, contractual and customer communication obligations. Knowing what to do in the first hours and days can help reduce confusion, support compliance and protect trust with customers, employees and business partners.
This guide explains data breach notification obligations for Australian businesses in general terms, including the Notifiable Data Breaches scheme, when the Office of the Australian Information Commissioner may need to be notified, when affected individuals should be told, and how ReportCyber may fit into cyber incident reporting in Australia. It also explains why documentation, legal input and cyber insurance planning can be important parts of breach recovery.
This is general information only. Data breach obligations can depend on the type of organisation, the information involved, the harm that may result, contractual duties, industry regulation and the facts of the incident. Businesses should consider obtaining legal, cyber security and insurance advice for their circumstances.
A data breach generally occurs when personal, sensitive, confidential or business-critical information is accessed, disclosed, lost, altered or used without authorisation. For example, a breach may involve:
Not every cyber incident is a notifiable data breach. A failed phishing attempt, a blocked malware alert or a system outage may require investigation, but notification obligations usually depend on whether information was actually accessed, disclosed, lost or placed at risk, and whether serious harm is likely.
When a potential data breach is discovered, speed matters, but so does accuracy. Businesses should avoid making public statements before they understand the basic facts, while still acting quickly to contain harm.
Common first steps include:
If the incident is also a broader cyber attack, such as ransomware or unauthorised system access, a practical recovery plan may be needed alongside notification decisions. For a broader response framework, see our cyber attack recovery roadmap.
The Notifiable Data Breaches scheme, often called the NDB scheme, sits under the Privacy Act 1988. It requires organisations covered by the Privacy Act to notify the OAIC and affected individuals when an eligible data breach occurs.
Many Australian businesses need to consider the NDB scheme, but not every small business is automatically covered by the Privacy Act. Coverage can depend on factors such as business size, the kind of services provided, whether health information is handled, whether personal information is bought or sold, and other specific circumstances. Even where the NDB scheme does not apply, a business may still have duties under contracts, industry rules, employment obligations, consumer expectations or common law risk management.
In general terms, an eligible data breach involves three key elements:
Serious harm can include more than financial loss. It may involve identity theft, scams, physical safety risks, emotional harm, reputational harm, discrimination, family violence risks, or other consequences depending on the information and the affected person's circumstances.
The seriousness of a breach depends on the facts. Information that may require careful assessment includes:
A spreadsheet containing names and email addresses may present one level of risk. The same spreadsheet combined with dates of birth, identity numbers, payment details or passwords may present a very different risk profile.
If a business suspects there may have been an eligible data breach, it should promptly assess the incident. Under the NDB scheme, organisations are expected to take reasonable steps to complete an assessment within 30 calendar days where there are reasonable grounds to suspect an eligible data breach.
The assessment should generally aim to answer:
The 30-day period is not a reason to delay action. If it becomes clear earlier that an eligible data breach has occurred, businesses should move to notification as soon as practicable. If serious harm can be prevented through effective remedial action, that may affect whether the breach is notifiable, but the reasoning should be carefully documented.
Where an eligible data breach has occurred and the NDB scheme applies, the business must notify the Office of the Australian Information Commissioner. The notification generally needs to include:
An OAIC data breach notification should be accurate, clear and practical. Businesses should avoid speculation, unsupported reassurance or blaming individuals before the facts are known. If the facts are still developing, the notification should reflect what is known at the time and may need to be updated as the investigation progresses.
If notification is required, affected individuals should be told as soon as practicable. The purpose is not only regulatory compliance; it is to help people take protective action.
Affected individual communication should usually explain:
Depending on the incident, recommended steps may include changing passwords, enabling multi-factor authentication, watching for scams, contacting banks, monitoring accounts, replacing identity documents or being cautious about unexpected calls, emails and messages. Businesses should tailor recommendations to the information involved rather than using generic warnings.
In some cases, a business may be able to notify only individuals who are at risk. In other cases, if it is not practicable to identify or contact each affected individual, the business may need to publish a statement and take reasonable steps to publicise it. The right approach depends on the breach, the records available and the legal requirements that apply.
Businesses should also consider accessibility. A notification that is legally accurate but difficult to understand may not help affected people protect themselves. Clear language, a dedicated contact point and consistent internal messaging can reduce confusion.
ReportCyber is the Australian Government's online reporting channel for cybercrime and cyber security incidents. It is commonly used to report incidents such as ransomware, business email compromise, online fraud, unauthorised access, phishing and other cybercrime affecting Australian businesses or individuals.
Reporting through ReportCyber is different from notifying the OAIC under the NDB scheme. One does not automatically replace the other. A ransomware attack that involves personal information may require both cybercrime reporting and privacy breach assessment. A scam payment incident may require reporting to banks and cybercrime channels, even if no personal information has been exposed. A privacy breach caused by human error may require OAIC assessment, even if there was no cybercriminal activity.
Businesses may also need to notify other parties depending on the incident, such as:
The correct reporting pathway can depend on the type of business and the type of incident. When in doubt, businesses should seek advice before assuming that one report satisfies all obligations.
The NDB scheme is important, but it is not the only possible source of obligations after a data breach. Australian businesses should review whether they have additional duties under:
For example, a service provider may be contractually required to notify a client within a specified timeframe if the client's data is affected. A business handling payment information may have merchant or payment card obligations. A health, financial, education or professional services business may need to consider additional expectations around sensitive information.
These obligations can overlap. A clear breach response plan should assign responsibility for checking legal, contractual, regulatory and insurance notification requirements early in the response process.
Good records can be critical after a data breach. Documentation supports decision-making, helps demonstrate that the business acted reasonably, assists insurers and advisers, and provides a reference point if regulators, customers or contractual partners ask questions later.
Useful incident records may include:
Documentation should be factual and controlled. Internal messages that speculate about fault, exaggerate facts or make unsupported assumptions can create confusion. Businesses should consider preserving evidence and seeking advice before deleting files, rebuilding systems or resetting logs in a way that may compromise an investigation.
Notification errors can increase regulatory, reputational and commercial risk. Common mistakes include:
Cyber insurance does not remove legal obligations after a data breach, and cover always depends on the policy wording, exclusions, limits, sub-limits and the insurer's claims process. However, a suitable cyber insurance policy may help a business access financial support and specialist services during a breach response.
Depending on the policy, cyber insurance coverage may include or help arrange support for:
Businesses should not assume every breach response cost is covered. Policy terms vary significantly, and some policies contain strict conditions about when the insurer must be notified, which vendors may be used, what prior security controls were required, and how claims evidence should be preserved. If you want to understand where cyber insurance may fit into your breach response planning, Cyber Insurance Online provides general information about cyber insurance for Australian businesses.
If a breach may lead to an insurance claim, notify the insurer or broker promptly and follow the policy's claims process. For more detail on insurer interaction, see our guide to cyber insurance claims for small business owners.
A breach notification plan should be prepared before an incident occurs. During a live breach, decisions often need to be made quickly, and the business may be under pressure from customers, staff, suppliers, attackers, media or regulators.
A practical plan should identify:
The plan should be tested with realistic scenarios, such as a compromised email account, ransomware attack, lost laptop, cloud misconfiguration or supplier breach. Testing helps identify gaps before they become urgent.
Notification planning is essential, but preventing breaches remains the better outcome. Businesses can reduce the chance and impact of data breaches by strengthening basic cyber hygiene.
Important controls include:
The less personal information a business stores, and the better it protects that information, the easier it may be to contain an incident and reduce the likelihood of serious harm.
After a data breach, Australian businesses should act quickly, but not carelessly. The immediate priorities are to contain the incident, understand what information is affected, assess whether serious harm is likely, and work out which notification and reporting pathways apply.
The NDB scheme may require notification to the OAIC and affected individuals where an eligible data breach occurs. ReportCyber may be relevant where the incident involves cybercrime or malicious cyber activity. Contracts, industry rules, payment arrangements, employment issues and insurance policies may add further obligations.
A strong response depends on preparation: knowing where sensitive data is held, having an incident response plan, documenting decisions, understanding policy conditions and engaging appropriate advisers. Cyber insurance may support breach response costs and expert assistance where the policy responds, but it should be treated as one part of a broader cyber risk management strategy, not a substitute for prevention or legal compliance.
Published: Thursday, 31st Jul 2025
Author: Paige Estritori
Rate this article
0 Comments
No comments yet. Be the first to share your thoughts.