Australia's Notifiable Data Breaches Scheme: What Small Businesses Must Do
A plain-English guide to Australia's Notifiable Data Breaches (NDB) scheme: what counts as an eligible data breach, the 30-day assessment rule, when and how to notify the OAIC and affected individuals, and the penalties for getting it wrong.
Last updated: 2026-06-22
If your business is covered by the Australian Privacy Act and you suffer a data breach that is likely to seriously harm someone, you have legal obligations — to assess it quickly, and in many cases to notify both the regulator and the people affected. This is the Notifiable Data Breaches (NDB) scheme, and it has applied since February 2018.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Consult a qualified lawyer or privacy professional for guidance specific to your situation. Information is current as of the date below and is based on Part IIIC of the Privacy Act 1988 (Cth) and OAIC guidance.
Who the NDB Scheme Applies To
The NDB scheme applies to APP entities — the same organisations bound by the Australian Privacy Principles. If you are exempt from the Privacy Act (most commonly under the small business exemption), the NDB scheme generally does not apply to you either. If you are covered — because you exceed $3 million in turnover, hold health information, are an AML/CTF reporting entity from 1 July 2026, or fall under another exception — read on.
What Is an "Eligible Data Breach"?
Not every breach triggers notification. The obligation applies only to an eligible data breach, which has three elements:
- There is unauthorised access to, unauthorised disclosure of, or loss of personal information your business holds;
- This is likely to result in serious harm to one or more individuals; and
- You have not been able to prevent that serious harm through remedial action.
"Serious harm" is assessed objectively — what a reasonable person would conclude given the circumstances. Relevant factors include the sensitivity of the information, whether it was protected (for example, encrypted), the kinds of people who could access it, and the nature of the harm (financial, physical, psychological, reputational, or identity theft). A lost laptop with strongly encrypted data may not be an eligible breach; a spreadsheet of customer names, dates of birth, and bank details emailed to the wrong person almost certainly is.
If remedial action means serious harm is no longer likely, the breach is not "eligible" and notification is not required — which is why fast containment matters.
The 30-Day Assessment Rule
Here is the part businesses most often get wrong, so be precise:
- Where you have reasonable grounds to suspect there may have been an eligible data breach (but aren't yet sure), you must carry out a reasonable and expeditious assessment — and take all reasonable steps to complete it within 30 calendar days.
- Where you have reasonable grounds to believe an eligible data breach has occurred, you must notify as soon as practicable.
So the 30 days applies to your assessment, not to the notification. Once you reach a reasonable belief that an eligible breach has happened, the clock is "as soon as practicable" — don't sit on it.
How to Notify
When notification is required, you must:
- Prepare a statement for the OAIC containing: your identity and contact details, a description of the breach, the kinds of information involved, and the steps you recommend individuals take in response. This is lodged with the OAIC (an online form is provided).
- Notify affected individuals of the contents of that statement — either everyone at risk, only those likely to suffer serious harm, or (if neither is practicable) by publishing the statement and taking reasonable steps to publicise it.
Notify "as soon as practicable" after preparing the statement.
A Simple Response Plan
Most small-business breaches are mishandled because there is no plan, not because the law is unclear. Have these steps ready:
- Contain — stop the exposure (revoke access, recall the email, reset credentials).
- Assess — what information, whose, how sensitive, what harm is likely? Start the 30-day clock.
- Remediate — if you can remove the risk of serious harm, document how.
- Notify — if serious harm remains likely, notify the OAIC and affected individuals as soon as practicable.
- Review — fix the root cause so it doesn't recur.
A current data inventory makes the assessment step dramatically faster, because you already know what data you hold and where. For the mechanics of drafting notifications, see our general guide to data breach notification.
Penalties
Failing to comply with the NDB scheme is an interference with privacy under the Privacy Act, which means it can attract the Act's civil penalties. For a serious interference, the maximum penalty for a body corporate is the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. The OAIC can also issue infringement and compliance notices for lower-level breaches. Beyond the legal exposure, the reputational damage of a mishandled breach usually dwarfs the fine.
For the full picture of how the NDB scheme fits within your obligations, see the Australian Privacy Act guide.
References
- About the Notifiable Data Breaches scheme: OAIC
- Identifying eligible data breaches: OAIC
- Privacy Act 1988 (Cth), Part IIIC: Federal Register of Legislation
Last reviewed: June 2026. Verify all statutory references against the current text of the Act and consult qualified legal counsel before making compliance decisions for your business.
Breaches Often Trigger Access Requests
After a breach, affected individuals frequently ask what data you hold on them. Our DSAR Compliance Guide gives you a step-by-step process for handling access requests under the Australian Privacy Act and other laws — so you can respond accurately and on time, even under pressure.
Related Articles
- Does the Australian Privacy Act's $3M Small Business Exemption Apply to You?
- The Privacy Act Employee Records Exemption (and Its Limits)
- Australian Privacy Access Requests (APP 12): How to Respond
- Data Mapping for Small Businesses: Where Does Your Data Live?
- Data Breach Prevention: A Practical Guide for Small Businesses