Australia
Data Breach in Australia: What to Do If Your Information Is Affected
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

If an Australian organisation or agency tells you your personal information was in a data breach, free protections come first: a credit ban, IDCARE's free identity and cyber support line, and your own free credit report, before considering any paid service.
This article addresses what an individual in Australia should do after being told, or suspecting, that their personal information was involved in a data breach covered by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth), current as at 10 September 2026. It is written for consumers responding to a breach, not for organisations managing their notification obligations; the OAIC's dedicated guidance for entities is linked where relevant. This article does not address data-breach notification laws in other countries.
What Counts as an "Eligible" Data Breach
A data breach happens whenever personal information an organisation or agency holds is accessed without authorisation, disclosed without authorisation, or lost. It becomes an eligible data breach, and triggers the notification obligations under the Privacy Act 1988 (Cth), if either of the two limbs in section 26WE(2) is satisfied.
Under the first limb, there is unauthorised access to, or unauthorised disclosure of, personal information the entity holds, and a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to.
Under the second limb, the information is lost in circumstances where unauthorised access or disclosure is likely to occur and, if it did occur, a reasonable person would conclude it would be likely to result in serious harm.
Loss is an independent route into the scheme, not an afterthought. A misplaced file, a misdirected mailout or a lost or stolen unencrypted device can be an eligible data breach even though nobody has been shown to have opened the information.
Remedial action is an exception, not a further element of the definition. Under section 26WF, if the entity acts before serious harm results and a reasonable person would then conclude serious harm is no longer likely, the breach is taken never to have been an eligible data breach at all.
Examples of serious harm the OAIC points to include identity theft affecting your finances and credit report, financial loss through fraud, a likely risk of physical harm, serious psychological harm, and serious harm to reputation.
The 30-Day Clock: How Fast the Entity Must Assess
Once an organisation or agency is aware of reasonable grounds to suspect an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment. Section 26WH(2) of the Privacy Act 1988 (Cth) requires it to take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of the grounds for suspicion. The OAIC expects entities to treat 30 days as a maximum, not a target, and to move faster wherever possible, since the risk of harm to individuals generally increases the longer a breach goes unaddressed. If an assessment cannot reasonably be completed within 30 days, the OAIC expects the entity to document why, and a failure to conduct a reasonable and expeditious assessment within that period is itself treated as an interference with privacy that the OAIC can act on.
The 30 days is a cap on assessment, not a deadline for telling you. It applies only while the entity suspects a breach and does not yet have reasonable grounds to believe there was one. Once it does have reasonable grounds to believe, section 26WH stops applying and the standard becomes as soon as practicable under sections 26WK(2)(b) and 26WL(3).
How You Will Be Told
If the entity has reasonable grounds to believe there has been an eligible data breach, it must prepare a statement and give a copy to the OAIC as soon as practicable after becoming aware, then notify individuals as soon as practicable after that statement is finished.
Section 26WL(2) sets three options in order. The entity notifies every individual whose information was involved; or, if that is not practicable, every individual who is at risk of serious harm from the breach; or, if neither is practicable, it publishes the statement instead. So being caught up in a breach does not guarantee you will be contacted personally.
Notification to you may come by email, text message or phone call, and should include the organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for the steps you should take in response. If neither of those individual notification options is practicable, it must instead publish a copy of the statement on its website and take reasonable steps to publicise it, for example through social media, news coverage or advertising, so that people who were not contacted directly still have a chance to see it.

Step One (Free): Place a Ban on Your Credit Report
If you have been, or are likely to be, the victim of fraud, including identity fraud, and a credit reporting body holds a report on you, you can ask that body to place a ban on your consumer credit report. The OAIC recommends applying to all three Australian credit reporting bodies, Equifax, Experian and illion, since any of them may hold a file on you. The ban lasts 21 days from your request, during which the credit reporting body must not use or disclose your report except with your written consent or where the law requires it; if a credit provider requests your report during the ban, the credit reporting body will flag the ban to them, alerting the provider to possible fraud. Requesting a ban, or extending it, is free, and there is no limit on how many times you can extend it if you remain concerned. You have to ask for the extension before the ban period ends; the credit reporting body must then extend it if it believes you have been, or are likely to be, a victim of fraud. It must notify you at least 5 business days before a ban is due to expire, including about your right to extend. If a ban has already lapsed, ask for a new ban, which is also free.
Step Two (Free): Get a Copy of Your Credit Report
You are entitled to a free copy of your credit report once every 3 months. Reviewing it lets you check for accounts, loans or credit checks you do not recognise, and shows you which organisations have recently accessed your file, so you know who to contact if something looks wrong.
Step Three (Free): Get Expert Help From IDCARE
IDCARE is Australia's national identity and cyber support service, and the OAIC directs individuals affected by identity fraud or a data breach to it for one-on-one advice from a specialist identity and cyber security counsellor. IDCARE can be reached on 1800 595 160. This support is free and is the appropriate first port of call for a step-by-step response plan tailored to what was actually exposed in the breach that affected you, rather than a generic checklist.

Step Four (Free): Log Out, Change Your Credentials and Check Your Accounts
Log yourself out of affected accounts on all devices, then log in from a device you trust and set a new, unique passphrase. Check your accounts for anything that looks out of place; scammers do not always act on stolen information immediately, so watching for unfamiliar transactions, emails or other contact over time matters as much as an immediate check. If you know or suspect your identity has been stolen, the OAIC also recommends reporting it to the Australian Cyber Security Centre through ReportCyber, contacting police for a report or reference number, and reporting scam-related fraud to the National Anti-Scam Centre through Scamwatch.
Watch for Follow-On Scams That Impersonate the Breached Organisation
A breach notification is itself bait. Scammers follow news of a breach and contact the same people, posing as the organisation that lost the data.
The OAIC advises against clicking links in emails, or giving personal information by phone or email, unless you are certain the organisation contacting you is genuine. Go back to the organisation through publicly available contact details, such as the number on its own website, rather than any number or link in the message you received.
A genuine organisation will not ask you to confirm a password, PIN or one-time code by email, text or phone. Urgency is the tell: a message that pushes you to act immediately through a supplied link deserves an independent check. Scam contact can be reported to the National Anti-Scam Centre through Scamwatch.
Free Protection Comes First, Not a Paid Product
Many data breach notifications, and many settlements arising from a breach, already include a period of free credit monitoring or identity protection for affected individuals. A credit ban, a free credit report and IDCARE's free advice line cover the practical steps most people need immediately. Treat any paid monitoring or identity-protection product as, at most, something to consider only after these free options, and only once you understand exactly what it adds that the free protections do not already cover.
Consider a Victims' Certificate If You Experienced Identity Crime
If identity crime caused ongoing problems in your personal or business affairs, for example debts or records wrongly attributed to you, a victims' certificate may help you resolve them. Certificates are available from the Commonwealth and from some states and territories, depending on the type of identity crime involved.

Which Organisations the NDB Scheme Actually Covers
The NDB scheme sits in the Commonwealth Privacy Act, so it reaches Australian Government agencies and the private sector organisations the Act covers. The OAIC states plainly that the Privacy Act does not cover local, state or territory government agencies, apart from the Norfolk Island administration. Two gaps explain most cases where a reader was never told anything.
The small business exemption
Under section 6D of the Privacy Act, a business is a small business if its annual turnover for the previous financial year was AUD 3,000,000 or less, and a small business operator is generally not covered by the Act at all. No coverage means no NDB obligation and nothing for the OAIC to act on.
The exemption does not apply if the operator provides a health service and holds health information, discloses personal information about someone else for a benefit, provides a benefit in order to collect personal information about someone else, is a contracted service provider under a Commonwealth contract, or is a credit reporting body. Removing the small business exemption has been proposed but has not been enacted.
State, territory and local government agencies
These have their own schemes and their own regulators. In New South Wales, public sector agencies notify the NSW Privacy Commissioner under Part 6A of the Privacy and Personal Information Protection Act 1998 (NSW), and affected individuals are notified under section 59N.
In Queensland, agencies notify the Office of the Information Commissioner Queensland under chapter 3A of the Information Privacy Act 2009 (Qld), and Queensland local governments came into that scheme on 1 July 2026. The ACT public sector is covered by the Information Privacy Act 2014 (ACT), administered by the ACT Privacy Commissioner since 1 July 2024. Other states and territories have their own privacy or information regulators.
Most state, territory and local government agencies are outside the OAIC's remit, though some state authorities and instrumentalities are bound by the Privacy Act, so start with the relevant state or territory regulator and check whether the particular body is covered.
If You Weren't Notified But Think You Should Have Been
If you believe your personal information was involved in a data breach and you were not told, first contact the organisation or agency directly and ask for information, including whether your personal information was affected. Give it a reasonable period, generally 30 days, to respond. If it does not respond, or you are not satisfied with the response, you can lodge a written complaint with the OAIC, as long as the Privacy Act covers that organisation. If the breach was at a state, territory or local government agency, take the complaint to that jurisdiction's regulator instead, and if the business is a small business operator outside the Act, there may be no notification obligation to complain about in the first place. You can also complain to the OAIC if you think a data breach raises other privacy issues beyond a missed notification. See recordinglaw.com's guide to making a privacy complaint in Australia for the full complaint process, and the notifiable data breaches and Australian Privacy Principles pages for the underlying obligations, on recordinglaw.com's Australia data privacy laws hub.
Going to Court: The Statutory Tort for Serious Invasions of Privacy
Since 10 June 2025, Schedule 2 of the Privacy Act has given individuals a cause of action in tort for serious invasions of privacy. The OAIC describes it as an additional avenue to seek redress for privacy harms in the courts. It is not a general remedy for every data breach, and the limits are the point.
You would need to show that the defendant intruded on your seclusion or misused information relating to you, that a person in your position would have had a reasonable expectation of privacy, that the invasion was intentional or reckless, that it was serious, and that the public interest in your privacy outweighed any countervailing public interest. An ordinary negligent security failure will usually not meet the intentional or reckless requirement. Part 3 of Schedule 2 also exempts several defendants outright: Commonwealth agencies and state or territory authorities acting in good faith in the performance or exercise of their functions or powers, along with their staff members (clauses 16 and 16A), law enforcement bodies (clause 16B), intelligence agencies (clause 17), journalists dealing with journalistic material (clause 15) and people under 18 (clause 18). That leaves the tort a poor fit for a breach at a public sector agency.
The invasion is actionable without proof of damage, and a court may award damages or grant an injunction or an order requiring an apology.
There is a short time limit. If you were 18 or over when the invasion occurred, proceedings must start before the earlier of one year after the day you became aware of it and three years after it happened. A court can allow a later start in limited circumstances, but do not count on it.
The OAIC does not administer the tort, so this is a matter for independent legal advice. Separately, if the OAIC investigates a complaint and makes a determination, that determination can declare you entitled to compensation for loss or damage under section 52 of the Privacy Act. Neither route is a guarantee of any payment.
| If you were notified of a data breach | Action | Cost |
|---|---|---|
| Protect your credit | Request a ban with Equifax, Experian and illion | Free |
| Check your file | Get a free copy of your credit report | Free (once every 3 months) |
| Get expert advice | Call IDCARE on 1800 595 160 | Free |
| Secure your accounts | Log out everywhere, change passphrases, check for suspicious activity | Free |
| Avoid follow-on scams | Do not use links or numbers in the breach message; verify through the organisation's published contact details | Free |
| Report suspected identity theft | ReportCyber, police, Scamwatch | Free |
| Consider ongoing problems | Apply for a victims' certificate if identity crime caused lasting issues | Free to apply |
| Weren't notified but think you should have been | Ask the organisation, then complain to the OAIC if the Privacy Act covers it, or to the state or territory regulator if it does not | Free |
This article provides general legal information about the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) and the free protective steps available to individuals, current as at 10 September 2026. It is not legal advice and does not account for your individual circumstances. For advice about a specific breach, consult a legal practitioner admitted in the relevant Australian state or territory.
Frequently Asked Questions
What is an eligible data breach in Australia?
It is either unauthorised access to, or unauthorised disclosure of, personal information held by an organisation or agency where a reasonable person would conclude the access or disclosure would be likely to result in serious harm, or loss of that information in circumstances where unauthorised access or disclosure is likely to occur and would be likely to result in serious harm. Loss is a separate limb of section 26WE(2), so records that simply go missing can qualify. Under section 26WF, if the entity takes remedial action in time so that a reasonable person would conclude serious harm is no longer likely, the breach is taken never to have been an eligible data breach.
How long does an organisation have to tell me about a data breach?
There is no fixed deadline for telling you. Where an organisation only suspects a breach, it has up to 30 calendar days under section 26WH(2) of the Privacy Act 1988 (Cth) to complete its assessment. Once it has reasonable grounds to believe there has been an eligible data breach, it must give a statement to the OAIC as soon as practicable after becoming aware (section 26WK(2)(b)) and notify affected individuals as soon as practicable after that statement is prepared (section 26WL(3)). Where the entity already has reasonable grounds to believe, no assessment period applies at all.
Should I pay for a credit monitoring service after a data breach?
Start with the free options: a credit ban with the credit reporting bodies, a free credit report, and IDCARE's free advice line. Many breach responses already include a period of free monitoring; a paid product should only be considered after you understand what the free protections do not already cover.
What is IDCARE and is it free?
IDCARE is Australia's national identity and cyber support service. It is free to use and can be reached on 1800 595 160 for expert, one-on-one advice specific to your situation.
How long does a credit ban last and can I extend it?
A ban lasts 21 days from when you first request it. You must ask for an extension before that ban period ends, and a credit reporting body must then extend it if it believes you have been, or are likely to be, a victim of fraud. There is no limit on the number of extensions and no charge to request one. If the ban has already expired, ask for a new ban rather than an extension; that is free too.
What should a data breach notification include?
The organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for what you should do in response.
What if the organisation can't contact me directly about the breach?
If notifying every individual whose information was involved is not practicable, it must notify everyone at risk of serious harm from the breach. Only where neither is practicable must it publish the notification on its website and take reasonable steps to bring it to affected individuals' attention, such as through social media, news coverage or advertising.
What should I do if I think I was affected but wasn't told?
Contact the organisation or agency directly and ask whether your information was involved. If it doesn't respond within a reasonable time, generally 30 days, or you're not satisfied with the answer, you can complain to the OAIC, provided the Privacy Act covers that organisation. Breaches at NSW public sector agencies go to the NSW Privacy Commissioner, and Queensland agencies and local governments to the Queensland Information Commissioner. A small business with annual turnover of AUD 3,000,000 or less is usually outside the Privacy Act altogether and has no notification obligation.
Can identity theft from a data breach affect my credit report?
Yes, identity theft is one of the examples of serious harm the OAIC points to, since stolen information can be used to open accounts or apply for credit in your name. This is exactly what a credit ban is designed to prevent while you assess the situation.
Updates
Corrected the notification section so the publish-on-website fallback applies only where the organisation cannot practicably notify either everyone whose information was involved or everyone at risk, added the coverage caveat to the key takeaway about complaining to the OAIC, replaced the flat statement that an OAIC complaint about a state or local agency goes nowhere with the OAIC's own position that some state authorities are bound by the Privacy Act, and noted the defendants the statutory tort does not reach.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- OAIC, Notifiable data breaches(oaic.gov.au).gov
- OAIC, When to report a data breach(oaic.gov.au).gov
- OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) scheme (30-day assessment under s 26WH; notify as soon as practicable under ss 26WK(2)(b), 26WL(3))(oaic.gov.au).gov
- OAIC, What is a notifiable data breach?(oaic.gov.au).gov
- OAIC, Identity fraud(oaic.gov.au).gov
- OAIC, Data breach support and resources(oaic.gov.au).gov
- OAIC, Fraud and your credit report(oaic.gov.au).gov
- OAIC, Make a data breach complaint(oaic.gov.au).gov
- Privacy Act 1988 (Cth), Compilation No. 104 (compilation date 4 June 2026), ss 6D, 20K, 20R, 26WE, 26WF, 26WH, 26WK, 26WL, 52 and Schedule 2(legislation.gov.au).gov
- OAIC, Statutory tort for serious invasions of privacy (commenced 10 June 2025)(oaic.gov.au).gov
- OAIC, State and territory privacy legislation (the Privacy Act does not cover local, state or territory agencies)(oaic.gov.au).gov
- Privacy and Personal Information Protection Act 1998 (NSW), Part 6A (mandatory notification of data breaches, ss 59M and 59N)(legislation.nsw.gov.au).gov
- Information Privacy Act 2009 (Qld), chapter 3A and s 219 (mandatory notification scheme; local governments from 1 July 2026)(legislation.qld.gov.au).gov
- Office of the Information Commissioner Queensland, What is Queensland's data breach scheme(oic.qld.gov.au).gov