Australia flag

Australia

Australia's Notifiable Data Breaches Scheme Explained

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

Australia's Notifiable Data Breaches Scheme Explained

Frequently Asked Questions

Which law contains Australia's Notifiable Data Breaches scheme?

The NDB scheme is set out in Part IIIC of the Privacy Act 1988 (Cth) and is administered by the OAIC. It has applied to eligible data breaches occurring on or after 22 February 2018.

Who has to comply with the NDB scheme?

APP entities must comply. That covers Australian Government agencies and organisations with annual turnover over AUD 3 million. Section 6D(4) also pulls in smaller businesses that provide a health service and hold health information, that disclose personal information for a benefit, service or advantage, that provide a benefit, service or advantage in order to collect personal information, that are contracted service providers for a Commonwealth contract, or that are credit reporting bodies. Section 6E deems further small business operators to be organisations, including AML/CTF reporting entities, protected action ballot agents, registered employee associations and Consumer Data Right accredited operators, though section 6E(1D) reaches only that operator's personal information which is not CDR data. Credit providers and tax file number recipients are covered for the information their obligations attach to, and the OAIC adds CDR accredited data recipients and designated gateways for CDR data, plus Digital ID Act 2024 accredited entities that are not APP entities when providing accredited services.

What is an eligible data breach?

Under section 26WE(2) it is either unauthorised access to or disclosure of personal information that a reasonable person would conclude is likely to result in serious harm to an individual, or loss of personal information in circumstances where such access or disclosure is likely to occur and would then be likely to cause serious harm. Section 26WE(3) makes that subject to section 26WF, so the breach is not eligible if remedial action removes the likely risk of serious harm.

What is the serious harm test?

The test asks whether a reasonable person would conclude the breach is likely to result in serious harm to an individual. Section 26WG lists relevant factors, including the kind and sensitivity of the information and who has obtained it.

How long do you have to assess a suspected data breach in Australia?

Section 26WH requires a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 calendar days of becoming aware of grounds to suspect an eligible data breach. The OAIC treats 30 days as a maximum.

When must you notify the OAIC and affected individuals?

Under section 26WK(2) the entity must prepare a statement and give it to the Commissioner as soon as practicable after it becomes aware that there are reasonable grounds to believe an eligible data breach has occurred. Under section 26WL(3) it must then notify individuals as soon as practicable after it completes the preparation of that statement, working through the section 26WL(2) cascade in order.

What must a data breach statement include?

Section 26WK requires the entity's identity and contact details, a description of the eligible data breach, the kind or kinds of information concerned, and recommendations about the steps individuals should take in response.

Are there exceptions to notifying a data breach?

Yes. Under section 26WF, if remedial action is taken before any serious harm occurs so that a reasonable person would conclude serious harm is no longer likely, the breach is not eligible and notification is not required. The OAIC's other exception classes are eligible data breaches of other entities (sections 26WJ and 26WM), enforcement related activities (section 26WN), inconsistency with a Commonwealth secrecy provision (section 26WP, with section 26WT applying the same limitation to a Commissioner direction under section 26WR), and a declaration by the Commissioner (section 26WQ). Separately, section 26WD disapplies Part IIIC altogether where the access, disclosure or loss has been or must be notified under section 75 of the My Health Records Act 2012.

What are the penalties for failing to notify a data breach in Australia?

Section 13(4A) makes a failure to assess or notify an interference with the privacy of an individual. Since 11 December 2024 the penalties have been tiered. Section 13G covers a serious interference, with a maximum for a body corporate of the greatest of AUD 50 million, three times the benefit obtained, or 30 percent of adjusted turnover over the breach turnover period, and AUD 2.5 million for anyone else. Section 13H covers any interference, with no seriousness element. Section 13H(3) sets 2,000 penalty units for a person, and section 82(5)(a) of the Regulatory Powers Act multiplies that by five for a body corporate, so a company faces up to 10,000 penalty units, AUD 3,640,000 at the AUD 364 penalty unit in force from 1 July 2026. Section 13J lets a court impose that penalty in a section 13G case. Section 13K sits lower again, at 200 penalty units for a person and 1,000 for a body corporate, and is the tier infringement notices attach to: 200 penalty units for a listed corporation under section 80UB(1A), and 60 penalty units for any other body corporate under section 104(2) of the Regulatory Powers Act. For an ordinary notification failure by an organisation, the section 13H corporate maximum is the realistic exposure. In October 2025 Australian Clinical Labs was ordered to pay AUD 5.8 million, the first civil penalties under the Privacy Act.

Updates

Corrected who the scheme covers, adding the businesses that trade in personal information, Commonwealth contracted service providers, the section 6E deemed organisations and the Consumer Data Right and Digital ID accredited entities that the old health, credit and tax file number list left out; rewrote the penalties section for the tiered regime in force since 11 December 2024, including the section 13H cap of 2,000 penalty units (AUD 728,000) that applies to an ordinary notification failure; added the section 26WD My Health Records and secrecy-provision exceptions; and corrected the description of section 26WE, the section 26WL notification cascade and its timing, the Part IIIC section range, and the wording of the two AUD 800,000 Australian Clinical Labs penalties. Corrected the civil penalty figures: the section 13H and section 13K maximums the page gave were the amounts for an individual, and section 82(5)(a) of the Regulatory Powers (Standard Provisions) Act 2014 makes a body corporate liable for five times those amounts, so an organisation faces up to AUD 3,640,000 under section 13H and AUD 364,000 under section 13K. Also separated the section 80UB infringement notice amount from the section 13K court penalty, restored the statutory qualifications on the section 6D(4) small business limbs, limited the section 6E(1D) Consumer Data Right rule to information that is not CDR data, attributed the secrecy exception to section 26WP with section 26WT applying to a Commissioner direction, named the Minister as the maker of an eligible data breach declaration, and attributed the AUD 3 million ransomware reporting threshold to the Cyber Security (Ransomware Payment Reporting) Rules 2025.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Independently fact-checked against the cited primary sources

Sources and References

  1. Privacy Act 1988 (Cth), Part IIIC (Notification of eligible data breaches), ss 26WA-26XH, and ss 6D, 6E, 13(4A), 13G-13K (Compilation No. 104, C2026C00227, 4 June 2026)(legislation.gov.au).gov
  2. OAIC, About the Notifiable Data Breaches scheme(oaic.gov.au).gov
  3. OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) Scheme(oaic.gov.au).gov
  4. OAIC, What is a notifiable data breach?(oaic.gov.au).gov
  5. OAIC, Report a data breach (Notifiable Data Breach form)(oaic.gov.au).gov
  6. OAIC, Australian Clinical Labs ordered to pay penalties (first civil penalty under the Privacy Act), 9 October 2025(oaic.gov.au).gov
  7. Regulatory Powers (Standard Provisions) Act 2014 (Cth), s 82(5) (body corporate maximum) and s 104 (infringement notice amounts), Federal Register of Legislation(legislation.gov.au).gov
  8. Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424), penalty unit AUD 364 from 1 July 2026, Federal Register of Legislation(legislation.gov.au).gov
Share: