Skip to content

When a breach becomes a legal obligation: the NDB scheme explained

Australia's Notifiable Data Breaches scheme starts a clock the moment you suspect personal information was exposed. What triggers it, and what you must do.
Published
Reading time
4 min
Topic
Compliance & Privacy
On this page

Most conversations about a security incident focus on getting systems working again. There is a second track running in parallel that businesses discover late and regret: the legal obligation to tell people what happened.

In Australia that obligation comes from the Notifiable Data Breaches scheme, administered by the Office of the Australian Information Commissioner. This is a plain-English orientation, not legal advice, and for anything serious you should take proper advice early.

Who it applies to

The scheme applies to organisations covered by the Privacy Act. That includes most businesses with an annual turnover above three million dollars, and, importantly, a long list of smaller ones regardless of turnover: health service providers, businesses trading in personal information, credit reporting bodies, TFN recipients, and some contractors delivering Australian Government contracts.

“Health service provider” is broader than people assume. It captures allied health, gyms with health assessments, and others who would never describe themselves as being in healthcare.

The practical point: do not assume you are exempt because you are small. Check.

What actually triggers it

Three things have to line up. There must be unauthorised access to, disclosure of, or loss of personal information; it must be likely to result in serious harm to the individuals affected; and you must be unable to prevent that harm through remedial action.

That middle test is where judgement lives. Serious harm covers identity theft, financial loss, threats to physical safety, and significant psychological or reputational damage. A spreadsheet of business email addresses is one thing. A list of names, dates of birth and Medicare numbers is another entirely.

The third limb matters and is often missed. If you can genuinely fix the exposure before harm occurs, for example a misdirected email that the recipient confirms they deleted unopened, the obligation may not be triggered at all. That is a real off-ramp, but it needs to be documented honestly rather than used as an excuse.

The clock

Once you are aware, or have reasonable grounds to suspect, that an eligible breach has occurred, you have 30 days to assess it. If it is eligible, you must notify the OAIC and the affected individuals as soon as practicable.

Thirty days is the outer limit for deciding, not a grace period for acting. Regulators have been consistently unimpressed by organisations that used the full window on straightforward cases.

What notification involves

A statement to the OAIC and to affected individuals covering who you are, what happened, what kinds of information were involved, and what those individuals should do in response.

That last part is the one to take seriously. “We take security seriously” helps nobody. Telling someone specifically that their driver licence number was exposed, and what to do about it, is what actually reduces harm and what regulators look for.

Where businesses get caught

Not knowing what data they hold. You cannot assess harm from an exposure if you do not know what was in the system. This is the single biggest cause of slow, painful assessments.

Not knowing when the attacker got in. Scope depends on dwell time. Without logs you are guessing, and guessing tends to force a wider and more expensive notification than the facts would have required.

Treating it as an IT matter. This is a legal and communications exercise that happens to have a technical cause.

Forgetting suppliers. If a provider holding your data is breached, the obligation can still be yours. Worth checking who would tell you, and how fast. See supplier risk.

What to do before anything happens

Know what personal information you hold and where. Keep logs long enough to reconstruct an intrusion, since 30 days of retention against a 90 day dwell time is not enough. Write down who makes the notification call and who approves the wording. And read your supplier contracts for a breach notification clause with an actual timeframe in it.

The honest summary

The NDB scheme rewards preparation and punishes improvisation. The businesses that handle it well are not the ones with the best technology, they are the ones that knew what data they held and had already decided who makes the call.


Want help mapping what personal information you hold and getting your logging to the point where you could actually answer the questions? Get in touch.

Want help putting this into practice?

Tell us what you are trying to solve and we will tell you what it would take.

Get in touch