When the NDB scheme applies
The scheme applies to APP entities under the Privacy Act 1988 — most Australian organisations with annual turnover above $3 million, plus all health service providers, credit reporting bodies and TFN recipients. Privacy Act reform is progressively expanding scope; treat the $3 million small-business exemption as living on borrowed time.
What counts as an "eligible data breach"
Three elements must coexist: unauthorised access to, disclosure of, or loss of personal information; a real risk of serious harm to one or more individuals; and remedial action has not prevented that risk. "Serious harm" includes financial, physical, psychological, emotional and reputational harm — the OAIC interprets it broadly.
The 30-day assessment clock
From the moment you become aware of a suspected breach you have up to 30 calendar days to complete a reasonable and expeditious assessment. The clock starts on awareness, not on confirmation. Treating the 30 days as a deadline rather than a maximum is one of the most common findings in OAIC's published determinations — entities are expected to move faster where practicable.
The first 72 hours
NDB-aligned 72-hour response
- 0–4 hours. Containment, evidence preservation, legal privilege over the response, immediate exec brief.
- 4–24 hours. Forensic scoping, identify personal information classes affected, stand up CIRT and comms.
- 24–72 hours. Eligible-breach assessment in flight, regulator engagement strategy, draft OAIC + individual notifications, APRA CPS 234 / SOCI obligations cross-checked.
- Day 3 onwards. Continue assessment (max 30 days), formal notifications, individual support arrangements, post-incident review and defensible decision record.
How NDB interacts with APRA, SOCI and ASIC
- APRA CPS 234 — material information security incidents must be notified to APRA within 72 hours, independent of the NDB clock.
- SOCI Act — responsible entities for critical infrastructure must report cyber incidents within 12 hours (critical) or 72 hours (other) to ASD.
- ASIC — listed entities must consider continuous disclosure obligations where the breach is materially price-sensitive.
- State health regulators — separate notification regimes may apply to clinical data breaches.
Treat these as parallel obligations, not sequential. A single incident commonly triggers three or four notifications on different clocks.
FOR INCIDENT LEADERS
Generate a Crisis Response Plan defensible to OAIC and your board.
FORTE/CYBERx produces a one-page executive crisis runbook — first-60-minute actions, RACI, regulator notification drafts and comms templates — anchored to the NDB scheme, CPS 234 and SOCI obligations.
Start a free missionPenalties under the reformed Privacy Act
Maximum civil penalties for serious or repeated interferences with privacy have risen to the greater of $50 million, three times the benefit derived, or 30 per cent of adjusted turnover. The OAIC has signalled it will use the new powers. The cost of late, incomplete or absent notification has materially increased.
The defensible decision record
For every eligible-breach assessment, document context, the options considered (notify / do not notify / notify subset), the evidence relied on, the legal advice, the decision and the rationale. This record is the single most useful artefact in any subsequent OAIC engagement.
FAQ
What is the Notifiable Data Breaches scheme?
The Notifiable Data Breaches (NDB) scheme, in force since February 2018 under Part IIIC of the Privacy Act 1988, requires APP entities to notify the OAIC and affected individuals when an "eligible data breach" occurs — that is, unauthorised access to or disclosure of personal information that is likely to result in serious harm.
How long do I have to assess and notify?
You have up to 30 calendar days from the moment you become aware of suspected unauthorised access or loss to assess whether an eligible data breach has occurred. Once you have reasonable grounds to believe one has occurred, you must notify the OAIC and affected individuals as soon as practicable. Many entities aim for materially faster — within days, not weeks.
What must the notification statement contain?
A statement to the OAIC must include the entity's identity and contact details, a description of the breach, the kinds of information involved and the recommended steps for affected individuals. The same information must be communicated to affected individuals — directly where practicable, otherwise via a public statement.
Are there exemptions?
Yes. If remedial action prevents the breach from being likely to result in serious harm — for example, encrypted data with intact keys, or quickly contained internal disclosure — notification may not be required. The reasoning must still be documented for the OAIC if challenged.