Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Australian regulation

    Notifiable Data Breaches (NDB) scheme

    The Notifiable Data Breaches scheme, under the Privacy Act 1988, requires covered organisations to notify affected individuals and the Office of the Australian Information Commissioner about eligible data breaches — unauthorised access, disclosure or loss of personal information likely to result in serious harm — as soon as practicable.

    What Notifiable Data Breaches (NDB) scheme means in practice

    The NDB scheme applies to organisations covered by the Privacy Act, which includes Australian Government agencies, businesses with annual turnover above the small business threshold, and a range of others regardless of turnover, such as private health service providers, credit reporting bodies and businesses that trade in personal information.

    An eligible data breach has three elements: there is unauthorised access to, unauthorised disclosure of, or loss of personal information; this is likely to result in serious harm to one or more individuals; and the organisation has not been able to prevent that harm through remedial action. That last element matters — a laptop lost but fully encrypted and remotely wiped may not be notifiable, which is a direct argument for the controls that make remediation possible.

    The process runs to a clock. If an organisation suspects an eligible breach it must carry out a reasonable and expeditious assessment, generally within 30 days, and notify as soon as practicable once it forms the view that the breach is eligible. Notification goes to the OAIC and to affected individuals, and must describe the breach, the information involved, and what those individuals should do in response.

    The operational implication is that incident response has to answer questions about data, not just systems. Which mailboxes were accessed, over what period, containing whose personal information, is a very different investigation from confirming that an account was compromised. Audit log retention, mailbox auditing, data loss prevention and sensible data classification determine whether that question can be answered at all.

    Australian privacy law has been under active reform, and penalties for serious or repeated interference with privacy have increased substantially. Organisations should confirm current obligations and thresholds against the OAIC's published guidance rather than relying on older summaries.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.