Australia flag

Australia

Data Breach in Australia: What to Do If Your Information Is Affected

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 14 primary sources cited on this page. How we verify our legal content

Data Breach in Australia: What to Do If Your Information Is Affected

Frequently Asked Questions

What is an eligible data breach in Australia?

It is either unauthorised access to, or unauthorised disclosure of, personal information held by an organisation or agency where a reasonable person would conclude the access or disclosure would be likely to result in serious harm, or loss of that information in circumstances where unauthorised access or disclosure is likely to occur and would be likely to result in serious harm. Loss is a separate limb of section 26WE(2), so records that simply go missing can qualify. Under section 26WF, if the entity takes remedial action in time so that a reasonable person would conclude serious harm is no longer likely, the breach is taken never to have been an eligible data breach.

How long does an organisation have to tell me about a data breach?

There is no fixed deadline for telling you. Where an organisation only suspects a breach, it has up to 30 calendar days under section 26WH(2) of the Privacy Act 1988 (Cth) to complete its assessment. Once it has reasonable grounds to believe there has been an eligible data breach, it must give a statement to the OAIC as soon as practicable after becoming aware (section 26WK(2)(b)) and notify affected individuals as soon as practicable after that statement is prepared (section 26WL(3)). Where the entity already has reasonable grounds to believe, no assessment period applies at all.

Should I pay for a credit monitoring service after a data breach?

Start with the free options: a credit ban with the credit reporting bodies, a free credit report, and IDCARE's free advice line. Many breach responses already include a period of free monitoring; a paid product should only be considered after you understand what the free protections do not already cover.

What is IDCARE and is it free?

IDCARE is Australia's national identity and cyber support service. It is free to use and can be reached on 1800 595 160 for expert, one-on-one advice specific to your situation.

How long does a credit ban last and can I extend it?

A ban lasts 21 days from when you first request it. You must ask for an extension before that ban period ends, and a credit reporting body must then extend it if it believes you have been, or are likely to be, a victim of fraud. There is no limit on the number of extensions and no charge to request one. If the ban has already expired, ask for a new ban rather than an extension; that is free too.

What should a data breach notification include?

The organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for what you should do in response.

What if the organisation can't contact me directly about the breach?

If notifying every individual whose information was involved is not practicable, it must notify everyone at risk of serious harm from the breach. Only where neither is practicable must it publish the notification on its website and take reasonable steps to bring it to affected individuals' attention, such as through social media, news coverage or advertising.

What should I do if I think I was affected but wasn't told?

Contact the organisation or agency directly and ask whether your information was involved. If it doesn't respond within a reasonable time, generally 30 days, or you're not satisfied with the answer, you can complain to the OAIC, provided the Privacy Act covers that organisation. Breaches at NSW public sector agencies go to the NSW Privacy Commissioner, and Queensland agencies and local governments to the Queensland Information Commissioner. A small business with annual turnover of AUD 3,000,000 or less is usually outside the Privacy Act altogether and has no notification obligation.

Can identity theft from a data breach affect my credit report?

Yes, identity theft is one of the examples of serious harm the OAIC points to, since stolen information can be used to open accounts or apply for credit in your name. This is exactly what a credit ban is designed to prevent while you assess the situation.

Updates

Corrected the notification section so the publish-on-website fallback applies only where the organisation cannot practicably notify either everyone whose information was involved or everyone at risk, added the coverage caveat to the key takeaway about complaining to the OAIC, replaced the flat statement that an OAIC complaint about a state or local agency goes nowhere with the OAIC's own position that some state authorities are bound by the Privacy Act, and noted the defendants the statutory tort does not reach.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. OAIC, Notifiable data breaches(oaic.gov.au).gov
  2. OAIC, When to report a data breach(oaic.gov.au).gov
  3. OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) scheme (30-day assessment under s 26WH; notify as soon as practicable under ss 26WK(2)(b), 26WL(3))(oaic.gov.au).gov
  4. OAIC, What is a notifiable data breach?(oaic.gov.au).gov
  5. OAIC, Identity fraud(oaic.gov.au).gov
  6. OAIC, Data breach support and resources(oaic.gov.au).gov
  7. OAIC, Fraud and your credit report(oaic.gov.au).gov
  8. OAIC, Make a data breach complaint(oaic.gov.au).gov
  9. Privacy Act 1988 (Cth), Compilation No. 104 (compilation date 4 June 2026), ss 6D, 20K, 20R, 26WE, 26WF, 26WH, 26WK, 26WL, 52 and Schedule 2(legislation.gov.au).gov
  10. OAIC, Statutory tort for serious invasions of privacy (commenced 10 June 2025)(oaic.gov.au).gov
  11. OAIC, State and territory privacy legislation (the Privacy Act does not cover local, state or territory agencies)(oaic.gov.au).gov
  12. Privacy and Personal Information Protection Act 1998 (NSW), Part 6A (mandatory notification of data breaches, ss 59M and 59N)(legislation.nsw.gov.au).gov
  13. Information Privacy Act 2009 (Qld), chapter 3A and s 219 (mandatory notification scheme; local governments from 1 July 2026)(legislation.qld.gov.au).gov
  14. Office of the Information Commissioner Queensland, What is Queensland's data breach scheme(oic.qld.gov.au).gov
Share: