Australia's Notifiable Data Breaches scheme requires organisations covered by the Privacy Act to tell affected people and the regulator when a data breach is likely to cause serious harm. This is general information, and a breach is the time to get legal advice.

Who it applies to

The scheme covers organisations with annual turnover above three million dollars, and some smaller ones, including health service providers and businesses that trade in personal information. If you are unsure whether you are covered, find out now.

What counts as a breach

A breach is unauthorised access to, or disclosure of, personal information, or its loss. That includes a hacked mailbox, a lost laptop, and an email with customer details sent to the wrong person.

When it must be reported

A breach is notifiable when it is likely to result in serious harm to any of the people affected and you haven't been able to prevent that harm. Harm includes financial loss, identity theft and damage to reputation or safety.

The timeframes

If you suspect a breach, you must assess it promptly, and within 30 days. Once you believe it is notifiable, you must notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable.

What the notice contains

It sets out who you are, what happened, what kinds of information were involved, and what people should do to protect themselves.

The first steps

Contain it: reset accounts, recover the device, recall the email. Work out what information was exposed and whose. Keep a record of what you did and when. Tell your insurer early, because many policies require it.

Being ready

Know where personal information sits in your business, who can reach it, and how long you keep it. Logging and a written response plan are what let you answer the regulator's questions with facts.

Want the first hour of an incident planned? Incident response

All resources