A data breach can activate reporting obligations almost instantly. For small business owners the first question is usually whether the Notifiable Data Breaches (NDB) scheme applies to them at all — and if it does, what they are required to do next. The scheme commenced on 22 February 2018, when the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) inserted Part IIIC into the Privacy Act 1988 (Cth). It requires covered entities to report eligible data breaches to the Office of the Australian Information Commissioner (OAIC) and to affected individuals.
Working through this process correctly produces two things: a documented assessment that either confirms or rules out an eligible data breach, and — where required — a formal notification to affected individuals and the OAIC. What the scheme does not do is guarantee immunity from regulatory scrutiny simply because you notified. Many businesses assume that reporting closes the matter; the OAIC can still investigate whether appropriate security measures were in place before the breach.
Prerequisites — check these before a breach happens
- Confirm whether you are an APP entity. The Australian Privacy Principles (APPs) apply to private-sector organisations with an annual turnover of more than AUD $3 million. If you are below that threshold and do not fall into one of the exceptions below, you are generally exempt from the NDB scheme.
- Check the exceptions that override the turnover threshold. You are an APP entity regardless of turnover if you are a private-sector health service provider (including pharmacies, allied health practices, gyms and weight-loss clinics), a credit reporting body, a credit provider, or a business that trades in personal information — for example, buying and selling email lists.
- Determine whether you hold tax file number (TFN) information. Even if your business is otherwise exempt from the APPs, the Privacy (Tax File Number) Rule 2015 treats any entity that holds TFN records — such as employee payroll records — as a TFN recipient. TFN recipients must comply with the NDB scheme in relation to that information, regardless of turnover.
- Know what counts as personal information. The NDB scheme protects information about an identified individual or an individual who can reasonably be identified — name, date of birth, address, email, occupation, health information and similar.
- Have an incident response contact identified. When a suspected breach occurs you need to assign responsibility immediately; deciding who is accountable after the event wastes part of the 30-day assessment window.
The exception that most often trips people up is the TFN one. A sole trader with two employees and a turnover well below $3 million who stores TFN details in a payroll spreadsheet is a TFN recipient and must follow the NDB process if that spreadsheet is compromised.
How the NDB process works
Step 1 — Identify and contain the suspected breach
A data breach occurs when personal information is accessed, disclosed or lost without authorisation. This is not limited to criminal hacking. Common causes include:
- losing a laptop, hard drive, or paper file containing personal information
- an employee accessing records they are not authorised to view
- an email sent to the wrong person, or using CC instead of BCC for a distribution list
- accidentally forwarding data to an unauthorised third party
- an IT system misconfiguration that exposes stored records
As soon as you become aware of a potential breach, take immediate containment steps: revoke access, isolate affected systems, recover devices where possible, and document exactly what you did and when. These actions feed directly into the assessment and may form part of the remedial action that avoids notification altogether.
Step 2 — Decide whether a formal assessment is needed
Not every incident triggers a reporting obligation. An eligible data breach under s 26WE of the Privacy Act 1988 (Cth) requires all three of the following:
- there has been unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an APP entity (or TFN recipient in relation to TFN information);
- a reasonable person would conclude that the access, disclosure or loss is likely to result in serious harm to one or more affected individuals — harm includes physical, psychological, emotional, financial or reputational consequences; and
- the entity has not been able to prevent the likely risk of serious harm through remedial action.
The third element is important for small businesses. If, for example, you accidentally emailed a client the wrong data file, contacted the client promptly, and received confirmed proof of deletion before any further disclosure occurred, the incident may not meet the threshold because you remediated the risk. Keep written evidence of that chain of events.
If you cannot confidently rule out an eligible data breach after an initial review, move immediately to a formal assessment.
Step 3 — Conduct the 30-day assessment
Under s 26WH of the Privacy Act 1988 (Cth), you must take all reasonable steps to complete the assessment within 30 calendar days of first becoming aware of the grounds for suspecting a breach. The OAIC treats 30 days as a ceiling, not a comfortable deadline — complete the assessment as quickly as the circumstances allow.
The assessment should:
- identify who had access to the information and what they did with it
- establish what categories of personal information were involved and how sensitive they are
- determine when and where the incident occurred and why
- evaluate the realistic harm that could flow to affected individuals
- decide whether the incident meets all three elements of an eligible data breach
If you cannot finish within 30 days, you must keep written records showing the steps taken to date, the reasons for the delay, and why the overall timeline has been reasonable and efficient.
Step 4 — Notify affected individuals
Once you have reasonable grounds to believe an eligible data breach has occurred, you are required to notify affected individuals as soon as practicable. Under s 26WL of the Privacy Act 1988 (Cth), there are three options — choose the one that is practical given your circumstances:
- Notify all individuals whose information was involved. Use this when you cannot determine which specific people face serious harm, or when the breach is wide enough that notifying everyone is the only safe approach.
- Notify only those individuals at risk of serious harm. Use this when the breach is limited in scope and you can identify who is genuinely at risk. If you cannot make that identification reliably, revert to the first option.
- Publish a statement and actively publicise it. This applies only where direct notification is not practicable — for example, you no longer hold current contact details for the individuals. If you have a website, the statement must appear on it. You must also take reasonable steps to publicise it, such as posting on social media or issuing a press release.
Whichever option you use, the notification must include: your business contact details; a description of the eligible data breach; the kinds of personal information involved; and the steps you recommend individuals take to protect themselves — such as cancelling credit cards, changing passwords or placing a credit alert.
Step 5 — Notify the OAIC
You must also report the eligible data breach to the OAIC. Notification to affected individuals and to the OAIC should happen at the same time where possible. Use the OAIC's online NDB notification form, which is hosted on the business.gov.au smart forms portal (form code OAIC-NDB). Include the same information you provided to affected individuals.
Common points where businesses get held up
- Waiting to be certain before starting the assessment. The 30-day clock starts when you become aware of grounds to suspect a breach, not when you confirm one. Starting late is itself a compliance risk.
- Confusing containment with remediation. Recovering a device or revoking access reduces exposure but does not automatically mean no eligible data breach occurred. You still need to assess whether serious harm was already likely before you acted.
- Underestimating the TFN exception. Many small-business owners believe the $3 million threshold exempts them entirely, not realising that holding employee TFN records brings them within scope for that information.
- Informal notifications. A phone call to an affected customer is not a compliant notification. The content requirements under s 26WL are specific; a written notification that omits recommended steps or fails to describe the breach accurately does not satisfy the obligation.
How Artificer Legal can assist with NDB compliance
If you are unsure whether an incident crosses the eligible data breach threshold, or you need to move quickly through the assessment and notification process, an Artificer Legal practitioner can assist by:
- reviewing the facts of the incident against the three-part eligible data breach test under s 26WE to give you a defensible position before you decide whether to notify
- drafting the assessment documentation, including the written record required if the 30-day window cannot be met
- preparing compliant notifications to affected individuals that satisfy the content requirements under s 26WL
- completing and lodging the OAIC notification form on your behalf
- advising on any follow-on obligations — for example, if the breach also involves credit-related information regulated by the credit reporting provisions of the Privacy Act 1988 (Cth)
- reviewing your data handling practices and internal incident response procedures to reduce the likelihood of a future breach or assessment delay
What determines whether you get this right
The single factor most likely to determine the outcome of an NDB process is how quickly you begin the formal assessment from the moment awareness arises. Businesses that treat the 30-day window as a grace period frequently find themselves without sufficient documentation to justify the timeline, running out of time before they have established whether harm was likely, or — worst of all — discovering that the breach was eligible only after the notification deadline has passed.
The NDB scheme requires covered entities to know whether the Australian Privacy Principles apply to them and to understand the special position of TFN recipients. Once a suspected breach occurs, the obligation is to assess it promptly, contain the harm, and notify both affected individuals and the OAIC through the correct channels. The scheme's three notification options give businesses flexibility in how they reach affected individuals, but not in whether they do so once an eligible data breach is confirmed.