What Notifiable Data Breaches (NDB) scheme means in practice
The NDB scheme applies to organisations covered by the Privacy Act, which includes Australian Government agencies, businesses with annual turnover above the small business threshold, and a range of others regardless of turnover, such as private health service providers, credit reporting bodies and businesses that trade in personal information.
An eligible data breach has three elements: there is unauthorised access to, unauthorised disclosure of, or loss of personal information; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that harm through remedial action. That last element matters — a laptop lost but fully encrypted and remotely wiped may not be notifiable, which is a direct argument for the controls that make remediation possible.
The process runs to a clock. If an organisation suspects an eligible breach it must carry out a reasonable and expeditious assessment, generally within 30 days, and notify as soon as practicable once it forms the view that the breach is eligible. Notification goes to the OAIC and to affected individuals, and must describe the breach, the information involved, and what those individuals should do in response.
The operational implication is that incident response has to answer questions about data, not just systems. Which mailboxes were accessed, over what period, containing whose personal information, is a very different investigation from confirming that an account was compromised. Audit log retention, mailbox auditing, data loss prevention and sensible data classification determine whether that question can be answered at all.
Australian privacy law has been under active reform, and penalties for serious or repeated interference with privacy have increased substantially. Organisations should confirm current obligations and thresholds against the OAIC's published guidance rather than relying on older summaries.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Information Security Manual (ISM)The Information Security Manual is the Australian Signals Directorate's cyber security framework for government systems.
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
