Notifiable Data Breaches: When You're Legally Required to Tell the Regulator (and Your Customers)

19/08/2026 02:52 PM
Notifiable Data Breaches: When You're Legally Required to Tell the Regulator (and Your Customers)

Notifiable Data Breaches: When You're Legally Required to Tell the Regulator (and Your Customers)

If your business experiences a data breach involving personal information, and that breach is likely to result in serious harm to the individuals affected, you may be legally required to notify both the Office of the Australian Information Commissioner (OAIC) and the affected individuals themselves. Many small and medium businesses assume this scheme only applies to large corporations handling sensitive data — in reality, the obligation applies broadly to any business covered by the Privacy Act, and the definition of a notifiable breach is wider than most owners expect.

Who This Actually Applies To

The Notifiable Data Breaches (NDB) scheme applies to organisations covered by the Australian Privacy Principles under the Privacy Act — which generally includes businesses with an annual turnover above a specified threshold, along with certain businesses regardless of turnover (health service providers, businesses trading in personal information, and some others). Many growing SMEs cross this threshold without necessarily realising the privacy obligations that come with it, particularly service businesses that hold client contact details, financial information, or health-related data.

What Counts as a Notifiable Breach

Not every security incident triggers notification obligations. The threshold is specifically an "eligible data breach" — broadly, one where:

  • There's unauthorised access to, unauthorised disclosure of, or loss of personal information held by the business, and
  • This is likely to result in serious harm to one or more individuals whose information is involved, and
  • The business hasn't been able to prevent the likely risk of serious harm through remedial action taken before serious harm occurs

"Serious harm" isn't limited to financial loss — it can include harm such as identity theft risk, reputational damage, or other significant harm to the individual, depending on the nature of the information involved and the circumstances of the breach.

Common Situations That Can Trigger This

  • A lost or stolen laptop or device containing unencrypted client or employee personal information.
  • A phishing or hacking incident giving unauthorised access to a customer database.
  • Accidentally sending an email containing personal information to the wrong recipient, particularly where the information is sensitive in nature.
  • A cyber incident affecting a third-party service provider that holds personal information on your business's behalf, where your business may still have notification obligations depending on the arrangement.
  • An employee inappropriately accessing or disclosing customer information without authorisation.
  • What Notification Actually Requires

    If an eligible data breach has occurred (or is reasonably suspected), the business generally needs to:

    1. Carry out a reasonable and expeditious assessment, generally within a defined timeframe, to determine whether the breach meets the eligible data breach threshold.
    2. Notify the OAIC, providing details of the breach, the kind of information involved, and recommendations for individuals affected.
    3. Notify affected individuals, or if that's not practicable, publish a notification prominently and take reasonable steps to publicise it, so affected individuals have a genuine opportunity to become aware of the breach and its implications.

    Where Businesses Commonly Get This Wrong

  • Assuming a breach is "too small" to require notification, without properly assessing whether serious harm is genuinely likely, rather than making an informal judgment call without documenting the assessment.
  • Delaying assessment while trying to fully understand the technical cause of a breach, when the assessment and notification clock is tied to becoming aware of a suspected breach, not to having a complete technical picture.
  • Not having an incident response plan in place at all, meaning the first time a business considers its notification obligations is during the incident itself, under pressure, rather than following a plan established in advance.
  • Overlooking third-party and outsourced data holders, not realising that a breach at a service provider handling your customers' data on your behalf can still create notification obligations for your business.
  • What to Have in Place Before an Incident Occurs

  • Confirm whether your business is covered by the Privacy Act's notification obligations, based on turnover and the nature of the personal information handled.
  • Develop a documented data breach response plan, including who's responsible for assessment, decision-making, and notification if an incident occurs.
  • Maintain an inventory of where personal information is held, including with third-party service providers, so you know what's actually at risk if any part of that ecosystem is compromised.
  • Review cyber insurance coverage, since many policies specifically address data breach response costs, including notification and regulatory liaison support.
  • Train staff on recognising and immediately escalating potential breaches, since delayed internal escalation directly affects how quickly the business can assess and respond to an actual eligible breach.
  • Preparation Matters More Than Perfect Prevention

    No business can guarantee it will never experience a data breach. What genuinely matters is having a clear, documented process for assessing and responding when one occurs — since acting quickly and appropriately is exactly what the notification scheme is designed to encourage, and having a plan in place before an incident occurs makes an already stressful situation considerably more manageable.


    RBizz can connect you with privacy and cyber security specialists to review your data breach preparedness — get in touch to check your current position.

    Contact Us


    RBizz Team