Do I have to report a data breach? (Australia)

Also searched as: Notifiable data breach Australia · Notifiable data breaches scheme · Notifiable data breach timeframe · Notifiable data breach form · Notifiable data breach scheme Privacy Act

Updated 3 October 2026

Short answer

If the Privacy Act covers your business, and the breach is likely to result in serious harm to someone whose personal information was involved, yes. You must notify the people affected and the Office of the Australian Information Commissioner (OAIC). If you only suspect a breach, you must assess it promptly and take reasonable steps to finish that assessment within 30 days. Many businesses with an annual turnover of $3 million or less aren't covered, but some are regardless of size, including those that provide health services or trade in personal information.

What's the problem

Something went wrong: a database was open, a key leaked, the site was hacked, a file was sent to the wrong person. Customer information may have been seen by someone it shouldn't have been. You need to know whether you're legally required to tell anyone, and how fast.

Why it happens

Breaches in small apps usually come from the same short list: an open database or storage bucket, missing access checks between users, leaked keys, outdated software, or a stolen password. The legal duty depends on two separate questions: whether the Privacy Act covers you, and whether this breach is likely to cause serious harm.

How to fix it

  1. Contain it. Close the database, rotate the keys, take the site offline: whatever stops further access.
  2. Assess it. What information was involved, whose, how many people, and how likely it is to cause any of them serious harm. Write down what you found and when.
  3. Work out whether you're covered. Check your turnover and the exceptions to the small business exemption, or ask a lawyer.
  4. If it's an eligible breach, notify. Prepare a statement for the OAIC (it has an online form) and tell the affected individuals what happened, what information was involved, and what they should do.
  5. Fix the cause, so the same breach can't happen again.
  6. Keep records of the breach, your assessment and your decisions, even if you decide notification isn't required.

Australian law

  • Who's covered. The Privacy Act 1988 (Cth) applies to organisations other than small business operators. Under section 6D(1), a business is a small business if its annual turnover for the previous financial year is $3,000,000 or less. Under section 6D(4), some small businesses are covered anyway, including those that provide a health service and hold health information, and those that disclose personal information for a benefit, service or advantage.
  • What's an eligible data breach. Under section 26WE(2), broadly: unauthorised access to or disclosure of personal information, or its loss in circumstances where that's likely, where a reasonable person would conclude it would be likely to result in serious harm to any of the individuals it relates to.
  • Suspected breaches. Under section 26WH(2), you must carry out a reasonable and expeditious assessment, and take all reasonable steps to complete it within 30 days.
  • Notifying. Under section 26WK(2), you must prepare a statement and give it to the Commissioner as soon as practicable after becoming aware. You must also notify the affected individuals.

The OAIC publishes detailed guidance and the notification form on its website.

General information, not legal advice.

When to call Preventionlabs

Whether and how to notify is a legal question about your business, and we're not lawyers. Your own compliance isn't something we handle. Start with the OAIC's guidance, and get legal advice if you're unsure. What we do is the software side: if the breach came from an app that was never properly protected, a resurrection gets it running and protected to MVP level, with access control, data exposure and the rest tested and fixed. That doesn't change what you have to report, but it lowers the chance of a next time.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. OAIC: About the Notifiable Data Breaches schemeAustralian privacy regulatorUnder the Notifiable Data Breaches (NDB) scheme any organisation or agency the Privacy Act 1988 covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to an individual whose personal information is involved.
  2. Privacy Act 1988 (Cth): Section 6D(1): what is a small businesslegislation, compilation No. 104A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less.
  3. Privacy Act 1988 (Cth): Section 6D(4): small business operators who are still coveredlegislation, compilation No. 104provides a health service to another individual and holds any health information except in an employee record; or (c) discloses personal information about another individual to anyone else for a benefit, service or advantage
  4. Privacy Act 1988 (Cth): Section 26WE(2): eligible data breachlegislation, compilation No. 104a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates
  5. Privacy Act 1988 (Cth): Section 26WH(2): assessing a suspected breachlegislation, compilation No. 104take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware as mentioned in paragraph (1)(a).
  6. Privacy Act 1988 (Cth): Section 26WK(2): statement to the Commissionerlegislation, compilation No. 104do so as soon as practicable after the entity becomes so aware.
← All of Is it safe?