Your online form builder, survey platform, or CRM provider sends an email: they have suffered a security incident and some data may have been compromised. The message is short on specifics. You do not yet know which of your customers are affected or what information was exposed. Within minutes, a journalist has sent a request for comment.
This scenario is not hypothetical. Australian businesses regularly discover that a vendor they rely on — a SaaS tool, a cloud storage provider, a data processor — has been breached. The instinct is to wait for more information from the vendor before doing anything. That instinct can get your business into serious legal trouble.
What is actually at stake
Under Australian privacy law, the fact that someone else suffered the breach is not a defence. If your business is an APP entity — that is, an entity covered by the Privacy Act 1988 (Cth) — then you hold the personal information that your vendor handles on your behalf. The Office of the Australian Information Commissioner (OAIC) is explicit: an entity that outsources the storage or processing of personal information to a third party, but retains the right to deal with that information, continues to hold it for the purposes of the Act. The breach is legally yours to assess and, if required, to report.
The practical consequence is a ticking clock. Part IIIC of the Privacy Act 1988 (Cth) — the Notifiable Data Breaches (NDB) scheme — requires your business to complete a reasonable assessment of whether an eligible data breach has occurred within 30 calendar days of first becoming aware of the suspected breach. If the breach is eligible, you must then notify affected individuals and the OAIC as soon as practicable. There is no grace period for waiting on your vendor's investigation.
The stakes beyond the clock include regulatory scrutiny, reputational damage, and — if your customers include EU residents — the additional obligations of the GDPR, which requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach (Article 33).
What to do when you receive the notification
Step 1: Confirm scope before you assume the worst or the best
Do not act on the vendor's summary alone. Contact your account team and ask specific questions in writing:
- Which of your data sets or form responses were stored in the affected system?
- What categories of personal information were involved (names, email addresses, government identifiers, financial details, health information)?
- What was the approximate date range of the affected records?
- Has the vulnerability been contained, and if so, when?
Get the answers in writing. You need this information to run your own assessment — and the record of your enquiries matters if the OAIC ever reviews your response.
At the same time, assign a response lead internally. This should be someone with authority to make decisions quickly: typically a senior manager, a privacy officer if you have one, or a director. Do not run the response by committee.
Step 2: Assess whether the breach is eligible under the NDB scheme
An eligible data breach has three elements, all of which must be present:
- there has been unauthorised access to or disclosure of personal information that your business holds (or a loss of information in circumstances where unauthorised access is likely);
- the breach is likely to result in serious harm to one or more of the individuals whose information was involved; and
- your business has not been able to prevent that likely harm through remedial action.
The serious harm test is where most businesses get this wrong. "Serious harm" is not limited to financial loss. Under the OAIC's guidance, it can include identity theft, reputational damage, and physical harm. The assessment turns on the sensitivity and type of information involved: a list of first names and work email addresses is less likely to cross the threshold than a dataset combining names, dates of birth, and Medicare numbers.
If the information was encrypted and the encryption has not been broken, that can reduce (though not automatically eliminate) the likelihood of serious harm.
Factors to weigh in your assessment:
- the nature and sensitivity of the personal information (health records, government identifiers, and financial details attract higher risk)
- the number of individuals affected
- who is likely to have obtained the information and their likely purpose
- whether the information is already publicly available
- the technical measures in place (encryption, access controls)
You must complete this assessment within 30 days of first suspecting the breach. Do not wait until the vendor has finished their own investigation if that will take you past the deadline.
Step 3: Contain what you can on your side
While the vendor addresses their systems, take steps on your own infrastructure:
- Revoke or rotate any API keys, access tokens, or credentials that the vendor held.
- Review whether the same data set is held elsewhere in your systems and confirm those stores are secure.
- If the breach involved passwords or credentials your customers used with your service, force a password reset.
- Preserve logs and records of the incident, including the vendor's notification email, your correspondence with them, and your internal assessment notes. Do not delete anything.
These steps matter both practically and legally. Under Australian Privacy Principle 11, your business is independently required to take reasonable steps to protect the personal information it holds from misuse, interference, loss, and unauthorised access or disclosure.
Step 4: Notify — if required, promptly and in the right order
If your assessment concludes that an eligible data breach has occurred, notify the affected individuals and the OAIC. The two notifications do not have to be simultaneous, but both are required and neither can be indefinitely delayed.
Your notification to affected individuals must include:
- your business name and contact details
- a description of the breach
- the kind of personal information involved
- your recommendations for steps individuals should take (for example, monitoring their accounts, changing passwords, or placing alerts with their bank)
Your statement to the OAIC is made through the OAIC's online notification portal and covers the same ground.
If your customers include EU residents and your business is subject to the GDPR, you also have a separate 72-hour window to notify the relevant supervisory authority (Article 33 GDPR). That clock runs from when your business became aware of the breach — not from when the vendor told you — so the two timelines can overlap in ways that demand urgent action.
Step 5: Review your vendor contracts and your internal framework
Once the immediate response is handled, this incident is the trigger for a broader review. Most businesses have weak contractual positions with their SaaS vendors because they accepted standard terms without negotiation.
Review your existing contracts with data processors and consider negotiating for:
- a right to be notified of a suspected breach within a defined timeframe (24–48 hours is reasonable to request)
- an obligation on the vendor to cooperate with your assessment, including providing specific information about the data affected
- a right to audit the vendor's security practices
- clarity about who makes the formal NDB determination — your business must retain that right; it cannot be outsourced to the vendor
If you do not have a formal data breach response plan, create one now. The OAIC's guidance recommends a four-step framework — contain, assess, notify, review — and suggests assigning a standing response team with clear roles before an incident occurs, not during it.
How Artificer Legal can help you respond
If your business has received a breach notification from a vendor, engaging a lawyer early is not a precaution — it is a practical necessity. The 30-day assessment window is short. The legal questions are specific: does this breach meet the eligible data breach threshold, who are the affected individuals, does the GDPR apply, and what do your vendor contracts actually require?
An Artificer Legal practitioner working with you on a vendor breach would:
- Review the vendor's notification and your contracts to identify your legal obligations and the vendor's express commitments
- Lead or assist the formal assessment of whether the breach is an eligible data breach under Part IIIC of the Privacy Act 1988 (Cth)
- Draft and review your notifications to affected individuals and your statement to the OAIC to ensure they meet the mandatory requirements and are not unnecessarily broad
- Advise on your GDPR exposure if EU residents are involved
- Identify any APP 11 compliance gaps in your own systems that the incident has exposed
- Negotiate improved data breach and notification provisions into your vendor contracts on a go-forward basis
The thing worth remembering
The most consequential mistake businesses make after a third-party breach is treating it as the vendor's problem to fix. Under Australian privacy law, if you hold the data, you own the response — regardless of whose systems were compromised. The 30-day clock starts running when your business first suspects a breach, not when the vendor confirms one.
When a vendor notification lands in your inbox, the first question to answer is not "what did they do wrong?" It is "what personal information of our customers was in their systems, and what do we now have to do about it?" A well-prepared business has a response plan, a response team, and vendor contracts that require timely disclosure. An unprepared one learns the rules under time pressure, with a regulator watching.
Key points this article covers: the NDB scheme imposes response obligations on APP entities even when a third-party vendor caused the breach; the 30-day assessment window starts from the date your business first suspects a breach; serious harm is assessed on the type and sensitivity of information, not just financial loss; EU-based customer data may also trigger a 72-hour GDPR notification obligation; and your vendor contracts should specify breach notification timelines and preserve your right to make the eligible data breach determination yourself.