Australia
Australia's Notifiable Data Breaches Scheme Explained
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 8 primary sources cited on this page. How we verify our legal content

Australia's Notifiable Data Breaches (NDB) scheme sits in Part IIIC of the Privacy Act 1988 (Cth) and requires regulated entities to notify the OAIC and affected individuals when a data breach is likely to result in serious harm. The scheme has applied to breaches occurring on or after 22 February 2018.
For the full federal framework, see our overview of Australian data privacy laws.
Where the NDB scheme comes from and who it covers
The NDB scheme is contained in Part IIIC of the Privacy Act 1988 (Cth) and has applied to eligible data breaches occurring on or after 22 February 2018. It binds the same regulated population as the rest of the Act, described as APP entities. That group covers Australian Government agencies and private sector or not-for-profit organisations with an annual turnover of more than AUD 3 million. It also captures certain entities regardless of turnover, including private sector health service providers, credit reporting bodies, credit providers and recipients of tax file number information. The scheme attaches to personal information that the entity holds, so an organisation that outsources storage can still carry the obligation. The OAIC, headed by the Australian Information Commissioner, administers and enforces Part IIIC.
Section 6D(4) lists what stops a business being a small business operator. Paragraph (a) is the turnover limb itself. The remaining paragraphs bite whatever the turnover: a business is outside the exemption if it provides a health service to another individual and holds any health information except in an employee record, discloses personal information about another individual to anyone else for a benefit, service or advantage, provides a benefit, service or advantage in order to collect personal information about another individual from anyone else, is a contracted service provider for a Commonwealth contract, or is a credit reporting body. The two middle limbs are what the OAIC calls trading in personal information, and they reach data brokers, list sellers and lead generators of any size.
Those two limbs come with carve-backs. Subsections 6D(7) and 6D(8) preserve small business operator status where the disclosure or the collection is made with the individual's consent, or as required or authorised by or under legislation. Separately, section 6D(9) sits outside subsection (4) altogether: a body corporate related to a body corporate that carries on a business that is not a small business is not a small business operator.
Section 6E separately deems some small business operators to be organisations for particular activities. That covers reporting entities and their authorised agents under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, protected action ballot agents under the Fair Work Act 2009, employee associations registered under the Fair Work (Registered Organisations) Act 2009, and holders of an accreditation under section 56CA(1) of the Competition and Consumer Act 2010. A small business operator can also opt in to coverage under section 6EA.
Two further classes are caught by rules that sit outside the APP entity definition. The OAIC states that accredited data recipients and designated gateways under the Consumer Data Right must comply with the NDB scheme for eligible data breaches involving CDR data relating to a CDR consumer. That is a duty attaching to the data, and many of those entities are APP entities in their own right. The OAIC also states that under the Digital ID Act 2024 accredited entities that are not APP entities must comply when providing accredited services, other than State or Territory agencies covered by a comparable data breach notification scheme.
Watch out: the small business exemption is not a blanket exemption for everyone under AUD 3 million, and health and credit are not the whole of the carve-out. A sub-threshold business that buys or sells personal information, or that delivers services to the Commonwealth under a contract, is caught by the NDB scheme in relation to the personal information it holds for those activities.
What counts as an eligible data breach
Section 26WE defines an eligible data breach. Subsection 26WE(2) sets out two limbs. Under the first, there is unauthorised access to or unauthorised disclosure of personal information held by the entity, and a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Under the second, the information is lost in circumstances where unauthorised access or disclosure is likely to occur and, assuming it did occur, a reasonable person would conclude it would be likely to result in serious harm. Subsection 26WE(3) makes that subject to section 26WF, which is where remedial action sits, so a breach that meets one of the limbs is still not eligible if the entity acts in time to remove the likely risk of serious harm. The OAIC frames the same test as three criteria drawn from three provisions: section 26WE(2), section 26WG on whether serious harm is likely, and section 26WF on remedial action. Common scenarios include a hacked database, a lost or stolen device holding customer records, or personal information sent to the wrong recipient.

The serious harm test and the section 26WG factors
The trigger for notification is whether a breach is likely to result in serious harm to an individual. The Act does not exhaustively define serious harm, but the OAIC explains it as covering serious physical, psychological, emotional, financial or reputational harm. Section 26WG sets out a non-exhaustive list of matters relevant to assessing the likelihood of serious harm. These include the kind or kinds of information involved and its sensitivity, whether the information was protected by security measures and the likelihood those measures could be overcome, the persons or kinds of persons who have obtained or could obtain the information, the nature of the harm that could result, and any other relevant matters. Whether a security technology was designed to make the information unintelligible or meaningless is also relevant. Sensitive information such as health records generally carries a higher risk of serious harm than information that is already public.
The 30-day assessment obligation
An entity does not always know straight away whether a breach is eligible. Section 26WH addresses that uncertainty. Where an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach but is not yet aware of reasonable grounds to believe one has occurred, it must carry out a reasonable and expeditious assessment of whether the relevant circumstances amount to an eligible data breach. The entity must take all reasonable steps to ensure the assessment is completed within 30 calendar days after the day it became aware of those grounds for suspicion. The OAIC treats the 30 days as a maximum rather than a default timeframe, and expects entities to move faster where they can. Documenting the steps taken and the reasoning is important, because the assessment obligation is enforceable in its own right.
Watch out: the 30-day clock is for the assessment of whether a breach is eligible. Once an entity has reasonable grounds to believe an eligible data breach has occurred, the separate notification duty applies and runs on an "as soon as practicable" basis, not a fresh 30 days.
Preparing the statement and notifying the OAIC and individuals
When an entity has reasonable grounds to believe there has been an eligible data breach, section 26WK requires it to prepare a statement as soon as practicable and give a copy to the Commissioner. In practice this is done through the OAIC's online Notifiable Data Breach form. Section 26WK sets out what the statement must contain: the identity and contact details of the entity, a description of the eligible data breach, the kind or kinds of information concerned, and recommendations about the steps individuals should take in response. Section 26WL then governs notifying individuals. Subsection 26WL(2) is a cascade the entity must work through in order. If it is practicable to notify each of the individuals to whom the relevant information relates, the entity must take reasonable steps to notify all of them. If that is not practicable but it is practicable to notify each individual at risk from the breach, it must take reasonable steps to notify that narrower group. Only if neither paragraph applies may the entity fall back on publishing a copy of the statement on its website and taking reasonable steps to publicise the contents. Subsection 26WL(3) sets the clock, and it runs from the completion of the preparation of the statement, which is a different starting point from the section 26WK(2) duty, whose clock runs from the entity becoming aware of reasonable grounds to believe.

| Step | Provision | Timing |
|---|---|---|
| Assess a suspected eligible breach | s 26WH | All reasonable steps within 30 calendar days |
| Prepare statement and give it to the Commissioner | s 26WK | As soon as practicable after becoming aware of reasonable grounds to believe |
| Notify affected individuals (cascade in s 26WL(2)) | s 26WL | As soon as practicable after completing the statement |
Exceptions, including remedial action
Part IIIC contains several exceptions. The most significant is the remedial action provision in section 26WF. If an entity takes remedial action before any serious harm is caused, and as a result a reasonable person would conclude the access, disclosure or loss is not likely to result in serious harm, then there is no eligible data breach and notification is not required. Examples the OAIC gives include recovering and deleting an email sent to the wrong person before it is opened, or relying on encryption of a high standard that prevents the unauthorised person from accessing the information. The OAIC groups the remaining exceptions into four classes. Eligible data breaches of other entities: where one entity complies, sections 26WH, 26WK and 26WL do not apply to the other entities caught by the same access, disclosure or loss (sections 26WJ and 26WM). Enforcement related activities: an enforcement body need not notify individuals where its chief executive officer believes on reasonable grounds that doing so would prejudice an enforcement related activity, but it must still give a statement to the Commissioner, minus the recommendations for individuals (section 26WN). Inconsistency with secrecy provisions: under section 26WP, the duty to give the statement to the Commissioner and the section 26WL notification duty do not apply to the extent they would be inconsistent with a Commonwealth secrecy provision. Section 26WT applies the same limitation to a Commissioner direction to notify under section 26WR. And declaration by the Commissioner: the Commissioner can declare that sections 26WK and 26WL do not apply, or can extend the section 26WL(3) period (section 26WQ).
Section 26WD sits apart from those four. Where an unauthorised access to information, an unauthorised disclosure of information or a loss of information has been, or is required to be, notified under section 75 of the My Health Records Act 2012, Part IIIC does not apply to it at all. That matters most to the private sector health service providers the small business rules already single out.
Neither Part IIIC nor the OAIC guidance sets a general rule of narrow construction or an onus of proof for these exceptions. An entity relying on one should still document the basis for doing so.
Enforcement and penalties
The Commissioner can direct an entity to prepare a statement and notify, including under section 26WR where the Commissioner is aware of an eligible data breach the entity has not reported. Section 26WU, added in 2022, lets the Commissioner require a person or entity to give information, produce documents or answer questions about an actual or suspected eligible data breach or about compliance with the Part IIIC notification duties. Division 5 of Part IIIC, added in December 2024, is a separate power and it belongs to the Minister rather than the Commissioner. Under section 26X(1) the Minister may make an eligible data breach declaration authorising limited collection, use and disclosure of personal information to help respond to a breach.
Section 13(4A) deems a contravention of section 26WH(2), 26WK(2), 26WL(3) or 26WR(10) to be an act that is an interference with the privacy of an individual, so a failure to assess or notify is enforceable in its own right. Since the Privacy and Other Legislation Amendment Act 2024 commenced on 11 December 2024, the civil penalties have sat in tiers rather than in a single provision.
Section 13G now applies only where the interference with privacy is serious. For a body corporate the maximum is the greatest of AUD 50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover over the breach turnover period. For a person other than a body corporate it is AUD 2.5 million. Section 13H applies to any interference with privacy, with no seriousness element at all, and section 13H(3) sets the penalty for a person at not more than 2,000 penalty units. That figure is not the ceiling for a company. Section 80U(1) makes every civil penalty provision of the Privacy Act enforceable under Part 4 of the Regulatory Powers (Standard Provisions) Act 2014, and section 82(5)(a) of that Act caps a body corporate at five times the amount the civil penalty provision specifies. Section 13G(4) switches that multiplier off for section 13G alone, which is direct proof it applies to the rest. A body corporate therefore faces up to 10,000 penalty units under section 13H, which is AUD 3,640,000 at the AUD 364 penalty unit in force from 1 July 2026, against 2,000 units or AUD 728,000 for a person other than a body corporate. Under section 13J, a court hearing a section 13G case that is not satisfied the interference was serious may make a pecuniary penalty order for contravening section 13H instead.
Section 13K carries a lower tier for listed Australian Privacy Principle breaches and for a statement that does not comply with section 26WK(3). Section 13K(4) specifies 200 penalty units, so the court maximum is 200 units for a person and, under the same section 82(5)(a) multiplier, 1,000 units or AUD 364,000 for a body corporate. It is also the tier infringement notices and compliance notices attach to. Section 80UB(1A) fixes an infringement notice for a single section 13K contravention at 200 penalty units where the entity is a listed corporation within the meaning of the Corporations Act 2001. For every other entity the amount falls back to section 104(2) of the Regulatory Powers Act, which works out to 60 penalty units for a body corporate and 12 for an individual. Section 80UC is the compliance notice power for the same provision.
For an ordinary notification failure by an organisation, the realistic exposure is the section 13H corporate maximum of 10,000 penalty units, AUD 3,640,000, rather than the AUD 50 million headline.
The reach of these powers became concrete on 8 October 2025, when the Federal Court ordered Australian Clinical Labs to pay AUD 5.8 million, the first civil penalties under the Privacy Act. That total included AUD 4.2 million for failing to take reasonable steps to protect personal information under Australian Privacy Principle 11.1, AUD 800,000 for failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred under section 26WH(2), and AUD 800,000 for failing to prepare and give a statement about the eligible data breach to the Australian Information Commissioner as soon as practicable under section 26WK(2).
A second Commonwealth reporting duty runs alongside the NDB scheme. Part 3 of the Cyber Security Act 2024 has applied since 30 May 2025. Section 26(2)(a) catches a business carrying on business in Australia whose annual turnover for the previous financial year exceeds the turnover threshold, provided it is not a Commonwealth or State body and is not a responsible entity for a critical infrastructure asset. Section 26(2)(b) separately catches a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies. Either way, the entity must report a ransomware payment within 72 hours of making it or of becoming aware that another entity made one on its behalf. The threshold is set at AUD 3 million by section 6 of the Cyber Security (Ransomware Payment Reporting) Rules 2025, not by the Act itself. That report goes to the designated Commonwealth body, not the OAIC, and it does not replace an NDB notification.

Frequently Asked Questions
Which law contains Australia's Notifiable Data Breaches scheme?
The NDB scheme is set out in Part IIIC of the Privacy Act 1988 (Cth) and is administered by the OAIC. It has applied to eligible data breaches occurring on or after 22 February 2018.
Who has to comply with the NDB scheme?
APP entities must comply. That covers Australian Government agencies and organisations with annual turnover over AUD 3 million. Section 6D(4) also pulls in smaller businesses that provide a health service and hold health information, that disclose personal information for a benefit, service or advantage, that provide a benefit, service or advantage in order to collect personal information, that are contracted service providers for a Commonwealth contract, or that are credit reporting bodies. Section 6E deems further small business operators to be organisations, including AML/CTF reporting entities, protected action ballot agents, registered employee associations and Consumer Data Right accredited operators, though section 6E(1D) reaches only that operator's personal information which is not CDR data. Credit providers and tax file number recipients are covered for the information their obligations attach to, and the OAIC adds CDR accredited data recipients and designated gateways for CDR data, plus Digital ID Act 2024 accredited entities that are not APP entities when providing accredited services.
What is an eligible data breach?
Under section 26WE(2) it is either unauthorised access to or disclosure of personal information that a reasonable person would conclude is likely to result in serious harm to an individual, or loss of personal information in circumstances where such access or disclosure is likely to occur and would then be likely to cause serious harm. Section 26WE(3) makes that subject to section 26WF, so the breach is not eligible if remedial action removes the likely risk of serious harm.
What is the serious harm test?
The test asks whether a reasonable person would conclude the breach is likely to result in serious harm to an individual. Section 26WG lists relevant factors, including the kind and sensitivity of the information and who has obtained it.
How long do you have to assess a suspected data breach in Australia?
Section 26WH requires a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 calendar days of becoming aware of grounds to suspect an eligible data breach. The OAIC treats 30 days as a maximum.
When must you notify the OAIC and affected individuals?
Under section 26WK(2) the entity must prepare a statement and give it to the Commissioner as soon as practicable after it becomes aware that there are reasonable grounds to believe an eligible data breach has occurred. Under section 26WL(3) it must then notify individuals as soon as practicable after it completes the preparation of that statement, working through the section 26WL(2) cascade in order.
What must a data breach statement include?
Section 26WK requires the entity's identity and contact details, a description of the eligible data breach, the kind or kinds of information concerned, and recommendations about the steps individuals should take in response.
Are there exceptions to notifying a data breach?
Yes. Under section 26WF, if remedial action is taken before any serious harm occurs so that a reasonable person would conclude serious harm is no longer likely, the breach is not eligible and notification is not required. The OAIC's other exception classes are eligible data breaches of other entities (sections 26WJ and 26WM), enforcement related activities (section 26WN), inconsistency with a Commonwealth secrecy provision (section 26WP, with section 26WT applying the same limitation to a Commissioner direction under section 26WR), and a declaration by the Commissioner (section 26WQ). Separately, section 26WD disapplies Part IIIC altogether where the access, disclosure or loss has been or must be notified under section 75 of the My Health Records Act 2012.
What are the penalties for failing to notify a data breach in Australia?
Section 13(4A) makes a failure to assess or notify an interference with the privacy of an individual. Since 11 December 2024 the penalties have been tiered. Section 13G covers a serious interference, with a maximum for a body corporate of the greatest of AUD 50 million, three times the benefit obtained, or 30 percent of adjusted turnover over the breach turnover period, and AUD 2.5 million for anyone else. Section 13H covers any interference, with no seriousness element. Section 13H(3) sets 2,000 penalty units for a person, and section 82(5)(a) of the Regulatory Powers Act multiplies that by five for a body corporate, so a company faces up to 10,000 penalty units, AUD 3,640,000 at the AUD 364 penalty unit in force from 1 July 2026. Section 13J lets a court impose that penalty in a section 13G case. Section 13K sits lower again, at 200 penalty units for a person and 1,000 for a body corporate, and is the tier infringement notices attach to: 200 penalty units for a listed corporation under section 80UB(1A), and 60 penalty units for any other body corporate under section 104(2) of the Regulatory Powers Act. For an ordinary notification failure by an organisation, the section 13H corporate maximum is the realistic exposure. In October 2025 Australian Clinical Labs was ordered to pay AUD 5.8 million, the first civil penalties under the Privacy Act.
Updates
Corrected who the scheme covers, adding the businesses that trade in personal information, Commonwealth contracted service providers, the section 6E deemed organisations and the Consumer Data Right and Digital ID accredited entities that the old health, credit and tax file number list left out; rewrote the penalties section for the tiered regime in force since 11 December 2024, including the section 13H cap of 2,000 penalty units (AUD 728,000) that applies to an ordinary notification failure; added the section 26WD My Health Records and secrecy-provision exceptions; and corrected the description of section 26WE, the section 26WL notification cascade and its timing, the Part IIIC section range, and the wording of the two AUD 800,000 Australian Clinical Labs penalties. Corrected the civil penalty figures: the section 13H and section 13K maximums the page gave were the amounts for an individual, and section 82(5)(a) of the Regulatory Powers (Standard Provisions) Act 2014 makes a body corporate liable for five times those amounts, so an organisation faces up to AUD 3,640,000 under section 13H and AUD 364,000 under section 13K. Also separated the section 80UB infringement notice amount from the section 13K court penalty, restored the statutory qualifications on the section 6D(4) small business limbs, limited the section 6E(1D) Consumer Data Right rule to information that is not CDR data, attributed the secrecy exception to section 26WP with section 26WT applying to a Commissioner direction, named the Minister as the maker of an eligible data breach declaration, and attributed the AUD 3 million ransomware reporting threshold to the Cyber Security (Ransomware Payment Reporting) Rules 2025.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Privacy Act 1988
s 26WEEligible data breachIn force
Scope (1) This section applies if: (a) both: (i) an APP entity holds personal information relating to one or more individuals; and (ii) the APP entity is required under section 15 not to do an act, or engage in a practice, that breaches Australian Privacy Principle 11.1 in relation to the personal information; or (b) both: (i) a credit reporting body holds credit reporting information relating to one or more individuals; and (ii) the credit reporting body is required to comply with section 20Q in relation to the credit reporting information; or (c) both: (i) a credit provider holds credit eligibility information relating to one or more individuals; and (ii) the credit provider is required to comply with subsection 21S(1) in relation to the credit eligibility information; or (d) both: (i) a file number recipient holds tax file number information relating to one or more individuals; and (ii) the file number recipient is required under section 18 not to do an act, or engage in a practice, that breaches a section 17 rule that relates to the tax file number information.
Official text (excerpt) · last checked 2026-08-14 · Read the full text in our law library · Verify at legislation.gov.au
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Privacy Act 1988 (Cth), Part IIIC (Notification of eligible data breaches), ss 26WA-26XH, and ss 6D, 6E, 13(4A), 13G-13K (Compilation No. 104, C2026C00227, 4 June 2026)(legislation.gov.au).gov
- OAIC, About the Notifiable Data Breaches scheme(oaic.gov.au).gov
- OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) Scheme(oaic.gov.au).gov
- OAIC, What is a notifiable data breach?(oaic.gov.au).gov
- OAIC, Report a data breach (Notifiable Data Breach form)(oaic.gov.au).gov
- OAIC, Australian Clinical Labs ordered to pay penalties (first civil penalty under the Privacy Act), 9 October 2025(oaic.gov.au).gov
- Regulatory Powers (Standard Provisions) Act 2014 (Cth), s 82(5) (body corporate maximum) and s 104 (infringement notice amounts), Federal Register of Legislation(legislation.gov.au).gov
- Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424), penalty unit AUD 364 from 1 July 2026, Federal Register of Legislation(legislation.gov.au).gov