Notifiable Data Breaches in Australia: A 2026 Cyber Consultant Guide to NDB Scheme Compliance
Understand Australia's NDB scheme obligations, the four-step breach response framework, and how a cyber consultant helps your business stay compliant in 2026.
Australia's Notifiable Data Breaches (NDB) scheme places mandatory obligations on thousands of organisations to notify regulators and affected individuals when a data breach is likely to cause serious harm. With the Office of the Australian Information Commissioner (OAIC) reporting a record 1,205 data breach notifications in 2025 — an 8% increase from the previous year — the question for Australian businesses is no longer whether a breach might occur, but whether they are prepared to respond correctly when it does.
Understanding the Notifiable Data Breaches Scheme
The NDB scheme was established under Part IIIC of the Privacy Act 1988 (Cth) and has been in force since February 2018. It requires entities covered by the Privacy Act to notify the OAIC and affected individuals when an "eligible data breach" occurs.
An eligible data breach arises when three criteria are met simultaneously. First, there must be unauthorised access to, unauthorised disclosure of, or loss of personal information held by the entity. Second, the incident must be likely to result in serious harm to one or more of the individuals whose information was involved. Third, the entity must be unable to prevent the likely risk of serious harm through remedial action taken after the breach is discovered.
The concept of "serious harm" is assessed objectively from the perspective of a reasonable person in the entity's position. It encompasses physical, psychological, emotional, financial, and reputational harm. The OAIC has published a quick reference guide to assist entities in making this assessment consistently and defensibly.
Which Organisations Are Covered?
The NDB scheme applies to all entities already subject to the Privacy Act 1988. Understanding whether your organisation is covered is the essential first step in building a compliant data breach response capability.
- Australian Government agencies — All federal government agencies are covered regardless of size
- Private sector businesses with annual turnover exceeding $3 million — This threshold captures the majority of medium and large Australian businesses
- Private sector health service providers — Covered regardless of turnover, including private hospitals, medical practices, allied health providers, and gyms that collect health information
- Credit reporting bodies and credit providers — Covered regardless of turnover due to the sensitivity of credit information
- Tax File Number (TFN) recipients — Any entity that handles TFN information is subject to the scheme
- Digital ID accredited entities — Under the Digital ID Act 2024, accredited entities must comply with the NDB scheme when providing accredited services, even if they would otherwise qualify as small businesses
Importantly, the Australian Government is developing a second tranche of privacy reforms that includes proposals to remove the general small business exemption entirely. If enacted, this would significantly expand the number of organisations subject to the NDB scheme. Businesses currently below the $3 million threshold should begin preparing now.
The Four-Step Data Breach Response Framework
The OAIC recommends a standardised four-step approach to responding to data breaches. A qualified cyber consultant can help your organisation implement and rehearse this framework before a breach occurs.
Step 1: Containment
The immediate priority when a breach is suspected is to stop further data outflow. This means isolating affected systems, revoking compromised credentials, and preventing additional unauthorised access. Critically, containment must be achieved without destroying forensic evidence that may be needed for the subsequent assessment and any regulatory or legal proceedings.
Step 2: Assessment
Once the breach is contained, the entity must conduct a reasonable and expeditious assessment to determine whether an eligible data breach has occurred. The Privacy Act requires this assessment to be completed within 30 calendar days of the entity first suspecting a breach. The assessment must gather facts about what information was involved, who may have accessed it, and what harm could result for affected individuals.
Step 3: Notification
If the assessment concludes that an eligible data breach has occurred, the entity must notify the OAIC using the official Notifiable Data Breach form available on the OAIC website. Affected individuals must also be notified as soon as practicable, with clear and actionable advice on steps they can take to protect themselves — such as changing passwords, monitoring financial accounts, or placing a credit alert.
Step 4: Review
After the immediate response is complete, a thorough post-incident review should identify the root cause of the breach, assess the effectiveness of the response, and implement preventive measures to reduce the likelihood of recurrence. This review should be documented and used to update the organisation's data breach response plan and security controls.
Common Mistakes in Data Breach Response
Many Australian organisations make avoidable errors when responding to data breaches. These mistakes can compound the harm to affected individuals, attract regulatory scrutiny, and increase the organisation's legal exposure.
- Delaying the assessment — The 30-day assessment window begins from the date the entity first suspects a breach, not from when it is confirmed. Organisations that delay initiating the assessment risk breaching the Privacy Act independently of the underlying breach
- Destroying forensic evidence during containment — Wiping affected systems before preserving logs and forensic data can prevent accurate assessment and may hinder law enforcement investigations
- Underestimating the scope of affected information — Organisations often initially underestimate how much data was exposed. A thorough assessment with appropriate technical expertise is essential to avoid incomplete notifications
- Notifying too late or not at all — Failing to notify the OAIC and affected individuals when required is a serious breach of the Privacy Act and can result in significant civil penalties
- Providing inadequate notification content — Notifications to affected individuals must include the entity's identity and contact details, a description of the breach, the kinds of information involved, and recommended protective steps. Vague or incomplete notifications do not satisfy the legal requirement
- Having no documented response plan — Organisations without a tested data breach response plan consistently perform worse in real incidents, taking longer to contain breaches and making more errors in the notification process
Australian Regulatory Context
The NDB scheme sits within a broader and evolving Australian privacy and cybersecurity regulatory framework. Organisations subject to the scheme must also navigate related obligations under the Cyber Security Act 2024, which introduced mandatory ransomware payment reporting for businesses with annual turnover exceeding $3 million, and the Security of Critical Infrastructure Act 2018 (SOCI Act), which imposes additional cyber incident reporting obligations on operators of critical infrastructure assets.
The OAIC has broad investigative and enforcement powers under the Privacy Act. Following the Privacy and Other Legislation Amendment Act 2024, civil penalties for serious or repeated privacy interferences were significantly increased. The OAIC can also conduct own-motion investigations and accept complaints from affected individuals, making proactive compliance essential.
The Australian Signals Directorate (ASD) publishes the Essential Eight Maturity Model, which provides a prioritised set of mitigation strategies that, when implemented, significantly reduce the likelihood of a data breach occurring. Cyber consultants with IRAP (Information Security Registered Assessors Program) accreditation can assess your organisation's Essential Eight maturity and identify gaps that increase breach risk.
For organisations in the financial services sector, APRA's Prudential Standard CPS 234 (Information Security) and CPS 230 (Operational Risk Management) impose additional obligations around information security capability, incident management, and third-party risk that complement the NDB scheme requirements.
Building a Data Breach Response Plan: Checklist
A documented, tested data breach response plan is the foundation of NDB scheme compliance. Use this checklist to assess your organisation's readiness:
- Have you identified all categories of personal information your organisation holds and mapped where it is stored?
- Does your response plan clearly define who is responsible for leading the breach response, including legal, IT, communications, and executive roles?
- Is there a documented process for assessing whether a suspected breach meets the "eligible data breach" threshold within 30 days?
- Do you have template notification letters ready for both the OAIC and affected individuals?
- Have you conducted a tabletop exercise or simulated breach scenario in the past 12 months to test your plan?
- Are your third-party vendors and suppliers contractually required to notify you of breaches involving your data within a defined timeframe?
- Do you have cyber insurance that covers breach response costs, including forensic investigation, legal advice, and notification expenses?
- Is your data breach response plan reviewed and updated at least annually, or after any significant change to your IT environment?
How MyMoney® Can Help
Navigating the NDB scheme and building a robust data breach response capability requires specialist expertise that most Australian businesses do not have in-house. A qualified cyber consultant can assess your current privacy and security posture, develop a tailored data breach response plan, and help you implement the technical and governance controls needed to reduce breach risk and respond effectively when incidents occur.
MyMoney® connects Australian businesses with verified cyber security consultants who specialise in privacy compliance, NDB scheme obligations, and data breach response planning. Whether you need a gap assessment, a response plan, or ongoing virtual CISO support, our platform makes it easy to find the right expert.
Don't wait for a breach to discover your organisation is unprepared. Post a Brief today and receive proposals from qualified cyber consultants, or Browse Cyber Consultants on the MyMoney® Marketplace to find specialists in data breach response and privacy compliance.
This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).