The Notifiable Data Breaches scheme, in Part IIIC of the Privacy Act 1988, requires covered Australian organisations to notify the Office of the Australian Information Commissioner and affected individuals when an eligible data breach occurs. The Privacy Act allows up to 30 days to assess a suspected breach. The obligation sits with the business holding the data, not with its IT provider.
This guide is general information, not legal advice, and privacy law in Australia is actively changing. Check the current position with the OAIC or a privacy lawyer before relying on it for a live incident. Reviewed August 2026.
The three-part test
A breach is only notifiable if all three of these are true. Plenty of security incidents fail the test and don't require notification — which is why the assessment step matters rather than notifying reflexively.
1. There's been unauthorised access, unauthorised disclosure, or loss
Someone got into a system or a mailbox they shouldn't have, information went to the wrong recipient, or a device or record was lost. Loss counts even when nobody has necessarily looked at it.
2. It's likely to result in serious harm to someone
Serious harm can be financial, physical, psychological, reputational or a mix. What matters is the sensitivity of the information, who has it now, and whether it was protected — encrypted data on a lost laptop is a very different situation to a plain spreadsheet.
3. You haven't been able to prevent that harm through remedial action
If you act fast enough that serious harm is no longer likely — you recover the device before anyone accesses it, or you recall the email successfully — the breach may not be notifiable. This is why the first hours matter.
Four steps, in order
The first hour matters more than the next week, and the most common mistake is destroying evidence while trying to clean up.
1. Contain it
Stop the access continuing. Reset credentials, disable the account, isolate the machine. Do not delete anything — that destroys the evidence you'll need to work out what actually happened.
2. Assess it
Work out what information was involved, whose it was, and whether serious harm is likely. The Privacy Act allows up to 30 days for this assessment, and it should be documented as you go.
3. Notify if it's eligible
If it meets the test, you notify the OAIC using their form and you notify the affected individuals, telling them what happened and what they should do about it.
4. Review and fix
Work out how it happened and close the gap. Regulators look far more favourably on an organisation that fixed the underlying cause than one that just filed the paperwork.
Do not delete anything, and don't wipe and rebuild the machine. It's the instinctive reaction and it removes the only record of what actually happened — which you need for your assessment, your insurer, and possibly the regulator. Isolate it instead and call for help.
Who is actually covered
This trips up more Gold Coast businesses than any other part of the scheme. The Privacy Act exempts many small businesses under $3 million annual turnover — but the exceptions are broad, and some of them are common locally:
- Health service providers of any size — including allied health, dental, physiotherapy and psychology practices. Turnover is irrelevant here.
- Businesses that trade in personal information
- Credit reporting bodies and businesses handling credit eligibility information
- Contractors delivering services under an Australian Government contract
- Businesses that have opted in to Privacy Act coverage
- Any business over the $3 million annual turnover threshold
If you're a health provider, assume you're covered. If you're anywhere near the turnover threshold or you handle sensitive information about clients, get advice on your specific position rather than assuming the exemption protects you.
What your IT provider can and can't do
There's a clear line here and it's worth understanding before you need it.
What we do: contain the incident, establish technically what happened and what data was involved, preserve evidence, and give you a factual written account you can use for your assessment and your insurer. Where you engage us for incident response, that includes forensic investigation and recovery.
What we don't do: make the notification decision or notify on your behalf. The obligation under the Privacy Act sits with the organisation holding the personal information. An IT provider offering to take that off your hands has misunderstood the law, and relying on them would leave you exposed.
The best time to think about this is before it happens. A security health check tells you what you hold and what would actually be exposed — which is most of the assessment work done in advance.
Questions Gold Coast businesses ask us
What is the Notifiable Data Breaches scheme?
The Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act 1988 and requires organisations covered by the Act to notify the Office of the Australian Information Commissioner and affected individuals when an eligible data breach occurs. An eligible data breach is unauthorised access, unauthorised disclosure or loss of personal information that is likely to result in serious harm, where remedial action has not prevented that harm.
How long do we have to report a data breach in Australia?
Where you suspect an eligible data breach may have occurred, the Privacy Act allows up to 30 days to carry out a reasonable and expeditious assessment. If it is confirmed as eligible, notification to the OAIC and affected individuals must be made as soon as practicable — 30 days is the outer limit for deciding, not a grace period for acting.
Does the NDB scheme apply to a small business?
Not automatically. The Privacy Act's small business exemption applies to many businesses under $3 million annual turnover, but there are significant exceptions — health service providers of any size, businesses trading in personal information, credit reporting bodies, contractors delivering Australian Government contracts, and others. Health providers are the exception that catches the most Gold Coast businesses by surprise. Get advice on your specific position rather than assuming the exemption applies.
What does bcom ICT do if there's a breach at our business?
We help you contain it, work out technically what happened and what data was involved, preserve evidence, and give you a factual written account you can use for your assessment and notification. What we do not do is make the notification decision for you or notify on your behalf — that obligation sits with your business, not your IT provider, and any provider offering to take it off your hands is misunderstanding the law.
Are you obliged to tell us if you have a breach?
Yes. If bcom ICT suffered a breach affecting systems or data belonging to a client, we would notify the affected clients as part of our documented incident response process. That obligation is part of our alignment to ISO/IEC 27001 practices and it works in both directions.
What if we're not sure whether it's serious enough to notify?
Document what you know, take advice, and don't let the clock run out while deciding. The OAIC has published guidance on assessing serious harm, and for anything genuinely borderline a privacy lawyer is worth the fee. Under-notifying carries regulatory risk; over-notifying carries reputational cost. Neither is a decision to make in a hurry or alone.
Think you're in the middle of one right now?
Call 07 3041 8993. Don't delete anything and don't rebuild the machine — isolate it and talk to us first.