A data breach can create more than a technical problem. For Australian businesses, it can also raise notification, reporting, legal, contractual and customer communication obligations. Knowing what to do in the first hours and days can help reduce confusion, support compliance and protect trust with customers, employees and business partners.

This guide explains data breach notification obligations for Australian businesses in general terms, including the Notifiable Data Breaches scheme, when the Office of the Australian Information Commissioner may need to be notified, when affected individuals should be told, and how ReportCyber may fit into cyber incident reporting in Australia. It also explains why documentation, legal input and cyber insurance planning can be important parts of breach recovery.

This is general information only. Data breach obligations can depend on the type of organisation, the information involved, the harm that may result, contractual duties, industry regulation and the facts of the incident. Businesses should consider obtaining legal, cyber security and insurance advice for their circumstances.

What counts as a data breach?

A data breach generally occurs when personal, sensitive, confidential or business-critical information is accessed, disclosed, lost, altered or used without authorisation. For example, a breach may involve:

  • customer details being accessed through a compromised email account;
  • employee records being exposed through a cloud storage error;
  • payment, login or identity information being stolen by malware or phishing;
  • a lost device containing unencrypted business or customer data;
  • ransomware affecting systems that store personal information;
  • information being sent to the wrong recipient; or
  • a third-party supplier exposing data it holds on your behalf.

Not every cyber incident is a notifiable data breach. A failed phishing attempt, a blocked malware alert or a system outage may require investigation, but notification obligations usually depend on whether information was actually accessed, disclosed, lost or placed at risk, and whether serious harm is likely.

Immediate steps after discovering a breach

When a potential data breach is discovered, speed matters, but so does accuracy. Businesses should avoid making public statements before they understand the basic facts, while still acting quickly to contain harm.

Common first steps include:

  • Contain the incident: isolate affected systems, revoke compromised credentials, disable suspicious access and preserve evidence where possible.
  • Activate the response team: involve IT or cyber security specialists, senior decision-makers, legal advisers, communications staff and insurance contacts if applicable.
  • Identify the information involved: determine whether customer, employee, supplier, payment, health, financial or identity information may have been affected.
  • Assess the affected people: consider whose information is involved and how they may be harmed.
  • Check notification pathways: consider Privacy Act obligations, OAIC notification, ReportCyber, contractual notification clauses, payment card obligations and sector-specific rules.
  • Document decisions: record what was known, when it was known, what action was taken and why.

If the incident is also a broader cyber attack, such as ransomware or unauthorised system access, a practical recovery plan may be needed alongside notification decisions. For a broader response framework, see our cyber attack recovery roadmap.

Understanding the Notifiable Data Breaches scheme

The Notifiable Data Breaches scheme, often called the NDB scheme, sits under the Privacy Act 1988. It requires organisations covered by the Privacy Act to notify the OAIC and affected individuals when an eligible data breach occurs.

Many Australian businesses need to consider the NDB scheme, but not every small business is automatically covered by the Privacy Act. Coverage can depend on factors such as business size, the kind of services provided, whether health information is handled, whether personal information is bought or sold, and other specific circumstances. Even where the NDB scheme does not apply, a business may still have duties under contracts, industry rules, employment obligations, consumer expectations or common law risk management.

What is an eligible data breach?

In general terms, an eligible data breach involves three key elements:

  • there has been unauthorised access to, unauthorised disclosure of, or loss of personal information held by the organisation;
  • the breach is likely to result in serious harm to one or more individuals; and
  • the organisation has not been able to prevent the likely risk of serious harm through remedial action.

Serious harm can include more than financial loss. It may involve identity theft, scams, physical safety risks, emotional harm, reputational harm, discrimination, family violence risks, or other consequences depending on the information and the affected person's circumstances.

What information may increase the risk of serious harm?

The seriousness of a breach depends on the facts. Information that may require careful assessment includes:

  • identity documents, such as passport, driver licence or Medicare details;
  • financial account information or payment details;
  • login credentials, security questions or authentication information;
  • health information or other sensitive information;
  • information about children or vulnerable individuals;
  • employment, disciplinary or payroll information;
  • customer purchase history or location information; and
  • combinations of data that could make scams or identity misuse easier.

A spreadsheet containing names and email addresses may present one level of risk. The same spreadsheet combined with dates of birth, identity numbers, payment details or passwords may present a very different risk profile.

The 30-day assessment period

If a business suspects there may have been an eligible data breach, it should promptly assess the incident. Under the NDB scheme, organisations are expected to take reasonable steps to complete an assessment within 30 calendar days where there are reasonable grounds to suspect an eligible data breach.

The assessment should generally aim to answer:

  • what happened and when it occurred;
  • which systems, accounts, suppliers or devices were involved;
  • what personal information was accessed, disclosed or lost;
  • who may be affected;
  • whether the information was protected, such as by encryption or access controls;
  • whether the information has been misused or is likely to be misused;
  • whether remedial action can reduce or remove the likely risk of serious harm; and
  • whether notification to the OAIC and affected individuals is required.

The 30-day period is not a reason to delay action. If it becomes clear earlier that an eligible data breach has occurred, businesses should move to notification as soon as practicable. If serious harm can be prevented through effective remedial action, that may affect whether the breach is notifiable, but the reasoning should be carefully documented.

OAIC data breach notification

Where an eligible data breach has occurred and the NDB scheme applies, the business must notify the Office of the Australian Information Commissioner. The notification generally needs to include:

  • the identity and contact details of the organisation;
  • a description of the data breach;
  • the kinds of information involved; and
  • recommendations about steps affected individuals should take in response.

An OAIC data breach notification should be accurate, clear and practical. Businesses should avoid speculation, unsupported reassurance or blaming individuals before the facts are known. If the facts are still developing, the notification should reflect what is known at the time and may need to be updated as the investigation progresses.

Notifying affected individuals

If notification is required, affected individuals should be told as soon as practicable. The purpose is not only regulatory compliance; it is to help people take protective action.

Affected individual communication should usually explain:

  • what happened, in plain language;
  • what types of information were involved;
  • when the breach occurred or was discovered, where known;
  • what the business has done to contain the incident;
  • what the individual can do to reduce risk;
  • where the individual can get assistance or ask questions; and
  • whether further updates will be provided.

Depending on the incident, recommended steps may include changing passwords, enabling multi-factor authentication, watching for scams, contacting banks, monitoring accounts, replacing identity documents or being cautious about unexpected calls, emails and messages. Businesses should tailor recommendations to the information involved rather than using generic warnings.

Who needs to be notified?

In some cases, a business may be able to notify only individuals who are at risk. In other cases, if it is not practicable to identify or contact each affected individual, the business may need to publish a statement and take reasonable steps to publicise it. The right approach depends on the breach, the records available and the legal requirements that apply.

Businesses should also consider accessibility. A notification that is legally accurate but difficult to understand may not help affected people protect themselves. Clear language, a dedicated contact point and consistent internal messaging can reduce confusion.

ReportCyber and cyber incident reporting in Australia

ReportCyber is the Australian Government's online reporting channel for cybercrime and cyber security incidents. It is commonly used to report incidents such as ransomware, business email compromise, online fraud, unauthorised access, phishing and other cybercrime affecting Australian businesses or individuals.

Reporting through ReportCyber is different from notifying the OAIC under the NDB scheme. One does not automatically replace the other. A ransomware attack that involves personal information may require both cybercrime reporting and privacy breach assessment. A scam payment incident may require reporting to banks and cybercrime channels, even if no personal information has been exposed. A privacy breach caused by human error may require OAIC assessment, even if there was no cybercriminal activity.

Businesses may also need to notify other parties depending on the incident, such as:

  • banks or payment providers;
  • payment card scheme contacts or merchant service providers;
  • cloud, software or managed service providers;
  • contracting parties whose data or systems are affected;
  • professional indemnity, cyber or management liability insurers;
  • industry regulators, where applicable;
  • police, where there is fraud, extortion or criminal conduct; and
  • employees, unions or workplace representatives where employment information is involved.

The correct reporting pathway can depend on the type of business and the type of incident. When in doubt, businesses should seek advice before assuming that one report satisfies all obligations.

Assessing legal, contractual and industry obligations

The NDB scheme is important, but it is not the only possible source of obligations after a data breach. Australian businesses should review whether they have additional duties under:

  • customer, supplier or government contracts;
  • privacy policies and collection notices;
  • employment agreements and workplace obligations;
  • payment processing and merchant service arrangements;
  • industry codes or professional standards;
  • licensing conditions or regulator expectations;
  • confidentiality agreements; and
  • insurance policy conditions, including claims notification requirements.

For example, a service provider may be contractually required to notify a client within a specified timeframe if the client's data is affected. A business handling payment information may have merchant or payment card obligations. A health, financial, education or professional services business may need to consider additional expectations around sensitive information.

These obligations can overlap. A clear breach response plan should assign responsibility for checking legal, contractual, regulatory and insurance notification requirements early in the response process.

Why documentation matters after a data breach

Good records can be critical after a data breach. Documentation supports decision-making, helps demonstrate that the business acted reasonably, assists insurers and advisers, and provides a reference point if regulators, customers or contractual partners ask questions later.

Useful incident records may include:

  • the date and time the incident was detected;
  • who discovered it and how it was escalated;
  • systems, accounts, devices and suppliers involved;
  • containment steps taken and when;
  • forensic findings or technical logs;
  • types of information affected;
  • the assessment of likely serious harm;
  • legal and insurance advice received;
  • notifications made to the OAIC, affected individuals, ReportCyber or other parties;
  • customer communications and scripts;
  • remedial action taken; and
  • lessons learned and future prevention measures.

Documentation should be factual and controlled. Internal messages that speculate about fault, exaggerate facts or make unsupported assumptions can create confusion. Businesses should consider preserving evidence and seeking advice before deleting files, rebuilding systems or resetting logs in a way that may compromise an investigation.

Common mistakes in data breach notification

Notification errors can increase regulatory, reputational and commercial risk. Common mistakes include:

  • Waiting too long to assess the incident: delays can increase harm and undermine confidence.
  • Assuming a small business has no obligations: some small businesses are covered by the Privacy Act, and many have contractual or industry duties.
  • Not checking supplier involvement: a breach at a cloud provider, IT contractor or software platform may still affect your customers or your legal responsibilities.
  • Sending vague customer notices: affected people need practical steps, not just a general apology.
  • Overpromising: saying that there is no risk before an investigation is complete can be misleading.
  • Forgetting insurer notification conditions: some policies require prompt notice and insurer consent before certain costs are incurred.
  • Not recording the assessment: even if notification is not required, the reasons for that decision should be documented.

The role of cyber insurance in notification and recovery

Cyber insurance does not remove legal obligations after a data breach, and cover always depends on the policy wording, exclusions, limits, sub-limits and the insurer's claims process. However, a suitable cyber insurance policy may help a business access financial support and specialist services during a breach response.

Depending on the policy, cyber insurance coverage may include or help arrange support for:

  • incident response and cyber forensics;
  • legal advice about privacy and notification obligations;
  • OAIC and affected individual notification support;
  • customer call centre or credit monitoring costs, where covered;
  • public relations and crisis communications;
  • data restoration and system recovery;
  • business interruption losses caused by a covered cyber incident;
  • third-party liability claims; and
  • regulatory investigation costs or penalties where insurable and covered by the policy.

Businesses should not assume every breach response cost is covered. Policy terms vary significantly, and some policies contain strict conditions about when the insurer must be notified, which vendors may be used, what prior security controls were required, and how claims evidence should be preserved. If you want to understand where cyber insurance may fit into your breach response planning, Cyber Insurance Online provides general information about cyber insurance for Australian businesses.

If a breach may lead to an insurance claim, notify the insurer or broker promptly and follow the policy's claims process. For more detail on insurer interaction, see our guide to cyber insurance claims for small business owners.

Building a practical breach notification plan

A breach notification plan should be prepared before an incident occurs. During a live breach, decisions often need to be made quickly, and the business may be under pressure from customers, staff, suppliers, attackers, media or regulators.

A practical plan should identify:

  • who has authority to activate the incident response process;
  • who will lead technical containment and investigation;
  • who will assess legal and privacy obligations;
  • who will contact insurers, brokers or external advisers;
  • who will approve customer and staff communications;
  • where incident logs and evidence will be stored;
  • which systems contain personal or sensitive information;
  • which suppliers hold data on the business's behalf;
  • which contracts contain notification deadlines;
  • how OAIC, ReportCyber and other reporting decisions will be made; and
  • how the business will review and improve controls after the incident.

The plan should be tested with realistic scenarios, such as a compromised email account, ransomware attack, lost laptop, cloud misconfiguration or supplier breach. Testing helps identify gaps before they become urgent.

Prevention still matters

Notification planning is essential, but preventing breaches remains the better outcome. Businesses can reduce the chance and impact of data breaches by strengthening basic cyber hygiene.

Important controls include:

  • multi-factor authentication for email, remote access and administrator accounts;
  • regular patching and secure configuration of systems;
  • least-privilege access to sensitive data;
  • encrypted devices and secure backups;
  • staff training on phishing, payment redirection and data handling;
  • supplier due diligence and contract review;
  • logging and monitoring for suspicious activity;
  • documented data retention and deletion practices; and
  • regular review of incident response and insurance arrangements.

The less personal information a business stores, and the better it protects that information, the easier it may be to contain an incident and reduce the likelihood of serious harm.

Key takeaways for Australian businesses

After a data breach, Australian businesses should act quickly, but not carelessly. The immediate priorities are to contain the incident, understand what information is affected, assess whether serious harm is likely, and work out which notification and reporting pathways apply.

The NDB scheme may require notification to the OAIC and affected individuals where an eligible data breach occurs. ReportCyber may be relevant where the incident involves cybercrime or malicious cyber activity. Contracts, industry rules, payment arrangements, employment issues and insurance policies may add further obligations.

A strong response depends on preparation: knowing where sensitive data is held, having an incident response plan, documenting decisions, understanding policy conditions and engaging appropriate advisers. Cyber insurance may support breach response costs and expert assistance where the policy responds, but it should be treated as one part of a broader cyber risk management strategy, not a substitute for prevention or legal compliance.

Author: Paige Estritori
Published: Thursday 31st July, 2025
Last updated: Monday 17th August, 2026

Share this article: