Explainer · Rules & costs
Notifiable data breaches: when a small business has to report one
Which small businesses the Notifiable Data Breaches scheme covers, what makes a breach reportable, the 30-day assessment, and who you have to tell.

A client list emailed to the wrong address. A missing work laptop. A phished password. The first question after the scramble is whether any of it has to be reported.
The answer sits in the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988, run by the Office of the Australian Information Commissioner (OAIC) and applying to breaches since 22 February 2018. A covered organisation “must notify affected individuals and the OAIC about an eligible data breach”.
The scheme is busy. The OAIC’s latest published half-yearly report, for 1 July to 31 December 2024, records 595 notifications, up from 518 in the previous half. Of those attributed to malicious attack, human error or system fault, 404 (69%) were malicious or criminal attacks and 170 were human error, most often personal information emailed to the wrong person (71). Health service providers notified most, with 121 (20%). The OAIC says data for July to December 2025 is on data.gov.au, with its dashboard update still to come.
Are you covered?
Usually not. The OAIC says “Most small businesses are not covered by the Privacy Act 1988, but some are”, defining a small business as one with annual turnover of $3 million or less, counting “all income from all sources”. The OAIC publishes a Privacy Checklist for Small Business to help you work out whether you are covered. Because the NDB scheme applies only to entities with Privacy Act security obligations, a business outside the Act is generally outside the scheme.
But the Act covers some businesses regardless of turnover, including:
- health service providers (the OAIC lists medical practitioners, pharmacists, allied health, complementary therapists, child care centres and private schools)
- businesses that trade in personal information (generally, without consent)
- contractors under a Commonwealth contract
- residential tenancy database operators and credit reporting bodies
- reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006
- registered employee associations and protected action ballot agents
- Consumer Data Right accredited businesses
- businesses related to a covered business, prescribed by regulation, or that have opted in.
For some, such as Commonwealth contractors and AML/CTF reporting entities, coverage extends only to information held for those activities.
Two more groups catch small operators. Credit providers are covered for credit eligibility information whether or not they are otherwise covered; the Privacy Act’s definition, as the OAIC summarises it, includes businesses supplying goods or services where payment is deferred for seven days or more, citing telcos and utilities. And the scheme applies to tax file number (TFN) recipients where TFN information is breached. The employee records exemption “does not apply to TFN information contained within an employee record”. The OAIC’s guidance also refers to “small businesses that are required to secure tax file number information”. On our reading, a small employer holding staff TFN declarations has NDB obligations for that information, even if nothing else it holds is covered.
Outside the scheme? The OAIC still recommends protecting the personal information you hold, and says to consider other obligations, such as state or international laws, including the EU’s GDPR, which can apply, for example, to businesses offering goods or services in the EU. Others you might report to include police, the Australian Cyber Security Centre and your insurer. For where the law is heading, see Privacy Act changes: what applies now, what starts in December, what’s proposed.
What counts as an eligible data breach
The OAIC sets out three elements:
- A data breach: unauthorised access to, or disclosure of, personal information you hold, or its loss where access or disclosure is likely.
- Likely serious harm: judged as a reasonable person in your position would. “Likely” means “more probable than not (rather than possible)”. Harm may be physical, psychological, emotional, financial or reputational; health, identity-document and financial information can raise the risk.
- Not prevented by remedial action: if quick action means serious harm is no longer likely, the breach isn’t eligible.
Lost information that was “encrypted to a high standard”, or remotely deleted before anyone could access it, isn’t an eligible breach. But if an attacker holds both encrypted data and the key, the OAIC says not to assume it is secure.
The 30-day assessment
If you have reasonable grounds to believe a breach is eligible, you notify promptly. If you only suspect it, you must assess, taking all reasonable steps to finish within “30 calendar days” of becoming aware of the grounds.
The Commissioner expects businesses to “treat 30 days as a maximum time limit” and aim for much shorter. If you can’t finish, document the steps taken, the reasons for delay and why the assessment was still reasonable and expeditious. The OAIC suggests three stages (initiate, investigate, evaluate), documented. Don’t wait for the CEO or board (in a small business, on our reading, the owner): once someone with appropriate seniority knows, an assessment should start.
Who you tell and how
An eligible breach must be reported to the OAIC, and individuals at risk of serious harm told, “as soon as practicable”. Limited exceptions apply, for example where several businesses hold the same information. The OAIC asks businesses to use its online Notifiable Data Breach form.
The statement must include your identity and contact details, a description of the breach, the kinds of information involved, and steps individuals should take. Notices to individuals carry the same content and should be in plain English.
For telling individuals, there are three options, depending on what’s practicable:
- Option 1: notify everyone whose information was involved.
- Option 2: notify only those at risk of serious harm.
- Option 3: if neither works, publish the statement on your website and take reasonable steps to publicise it; the OAIC generally expects it to stay up at least six months.
Any reasonable method works, from phone to mail, and you can tell individuals before or alongside the OAIC. Where several businesses hold the same information, only one needs to notify, ideally the one closest to those affected.
Since 11 December 2024, a new Division 5 of Part IIIC lets the Minister permit otherwise-restricted information handling to reduce harm after an eligible breach.
Examples
Illustrative only, adapted from OAIC guidance.
- Lost phone, wiped in time. An employee leaves a work phone on public transport. IT wipes it remotely, confident its security meant nobody got in. Remedial action prevented likely serious harm: no eligible breach.
- Card skimmer on a web shop. Malicious code captures card details from buyers during a set period, plus basic account details for all customers. The retailer judges only the buyers at likely risk and notifies them (Option 2).
- Old client list sent to everyone. An accountant accidentally emails past clients’ TFNs and addresses to his whole contact list. With only outdated addresses, direct notice isn’t practicable, so he notifies the Commissioner and publicises a notice (Option 3).
Get ready before it happens
“All entities should have a data breach response plan,” the OAIC says. It should be written, easy for staff to find, and tested, for example against a hypothetical breach.
It should explain what a breach looks like in your business, who staff tell first, when to escalate, how you contain and assess, how you’ll contact affected people, which outsiders to call and how incidents are recorded. Keep a current contact list for each role, with a backup. On our reading, for a small business that may mean the owner, your IT provider, lawyer or accountant, and insurer.
If a cloud host or other provider holds your data, both of you may be treated as holding it, and the OAIC suggests contracts set out who assesses, contains and notifies. Its response sequence is four steps: contain, assess, notify if required, review.
Checklist
- Check your coverage. Run the OAIC’s Privacy Checklist for Small Business, then separately check whether you hold staff TFN information or give credit.
- Account for TFN records. Treat a breach of staff TFN information as covered by the scheme, and assess whether it is eligible.
- Write a response plan. Set out who staff tell first, how breaches are contained and assessed, and who contacts affected people.
- List your response contacts. Record details for people such as your IT provider, lawyer or accountant, and insurer, with a backup for each role.
- Start a dated assessment record. Start a dated record the day a breach is suspected and aim to finish the assessment well inside the limit.
- Encrypt and enable remote wipe. Set up laptops and phones so a lost device is less likely to become a notifiable breach.
- Draft a notice template. Prepare wording covering your contact details, what happened, the information involved and steps people should take.
- Settle breach duties with providers. Agree in contracts who assesses, contains and notifies when shared data is breached.
Tick items as you go. Your ticks stay in this browser.
Sources 11 sources
- OAIC – When to report a data breach
- OAIC – Report a data breach
- OAIC – About the Notifiable Data Breaches scheme
- OAIC – Quick reference guide for responding to data breaches
- OAIC – Data breach preparation and response
- OAIC – Data breach preparation and response, Part 1: Data breaches and the Australian Privacy Act
- OAIC – Data breach preparation and response, Part 2: Preparing a data breach response plan
- OAIC – Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) Scheme
- OAIC – Small business
- OAIC – Notifiable Data Breaches Report: July to December 2024
- OAIC – Notifiable Data Breach statistics dashboard

