
Notifiable Data Breaches: When You're Legally Required to Tell the Regulator (and Your Customers)
Who This Actually Applies To
The Notifiable Data Breaches (NDB) scheme applies to organisations covered by the Australian Privacy Principles under the Privacy Act — which generally includes businesses with an annual turnover above a specified threshold, along with certain businesses regardless of turnover (health service providers, businesses trading in personal information, and some others). Many growing SMEs cross this threshold without necessarily realising the privacy obligations that come with it, particularly service businesses that hold client contact details, financial information, or health-related data.
What Counts as a Notifiable Breach
Not every security incident triggers notification obligations. The threshold is specifically an "eligible data breach" — broadly, one where:
- There's unauthorised access to, unauthorised disclosure of, or loss of personal information held by the business, and
- This is likely to result in serious harm to one or more individuals whose information is involved, and
- The business hasn't been able to prevent the likely risk of serious harm through remedial action taken before serious harm occurs
"Serious harm" isn't limited to financial loss — it can include harm such as identity theft risk, reputational damage, or other significant harm to the individual, depending on the nature of the information involved and the circumstances of the breach.
Common Situations That Can Trigger This
What Notification Actually Requires
If an eligible data breach has occurred (or is reasonably suspected), the business generally needs to:
- Carry out a reasonable and expeditious assessment, generally within a defined timeframe, to determine whether the breach meets the eligible data breach threshold.
- Notify the OAIC, providing details of the breach, the kind of information involved, and recommendations for individuals affected.
- Notify affected individuals, or if that's not practicable, publish a notification prominently and take reasonable steps to publicise it, so affected individuals have a genuine opportunity to become aware of the breach and its implications.
Where Businesses Commonly Get This Wrong
What to Have in Place Before an Incident Occurs
Preparation Matters More Than Perfect Prevention
No business can guarantee it will never experience a data breach. What genuinely matters is having a clear, documented process for assessing and responding when one occurs — since acting quickly and appropriately is exactly what the notification scheme is designed to encourage, and having a plan in place before an incident occurs makes an already stressful situation considerably more manageable.
RBizz can connect you with privacy and cyber security specialists to review your data breach preparedness — get in touch to check your current position.


































