Notifiable Data Breaches scheme training gives staff a simple job: recognise a potential privacy incident and report it immediately. This 2026 guide shows how to train Australian teams without asking every employee to become a privacy lawyer.
Why this matters
The Notifiable Data Breaches scheme applies to organisations and agencies covered by the Privacy Act. The OAIC says affected individuals and the OAIC must be notified when a data breach is likely to result in serious harm to an individual whose personal information is involved.
Staff do not decide whether a breach meets that legal threshold. They create the first signal that lets the response team contain, assess and act. A lost device, recipient error, suspicious login, phishing click or unexpected disclosure can all require urgent escalation.
Cyber Aware training provides completion-tracked lessons and can schedule training on a steady cadence. Pair that capability with a clear internal incident route, named response owners and tabletop practice.
What you will need
Prepare these items before assigning training:
- One plain-language incident-reporting route, monitored during business hours and with an after-hours process.
- A current list of privacy, security, legal and communications decision-makers.
- A one-page guide defining what staff must report.
- Examples of the personal information the organisation handles.
- A response playbook for containment, evidence preservation, assessment and communication.
- A way to record training completion, incident reports and lessons learned.
Do not hide the reporting route in a long policy. Put it in the training, employee portal, onboarding pack and staff communication channels.
Step 1: teach the difference between a mistake and a reportable event
Staff often avoid reporting because they assume an error must be serious before it is worth raising. Train the opposite rule: report any suspected unauthorised access, disclosure, loss or change involving personal information as soon as it is noticed.
Examples include emailing a client document to the wrong person, misplacing a device, finding a publicly accessible file, clicking a suspicious link, receiving a strange MFA prompt or disclosing account information to an unverified caller.
Expected outcome: a fast report reaches the right team. Common mistake: asking the employee to investigate or prove harm before reporting.
Step 2: show people what personal information looks like
Use examples from the organisation: names, contact details, addresses, account details, identity documents, employee records, health information, customer tickets, photos and location information. Explain that information can become personal information when combined with other data.
The OAIC notes that personal information includes information or an opinion about an identified individual or an individual who is reasonably identifiable. The amount and sensitivity of the information changes the likely impact of an incident.
Expected outcome: staff recognise that a spreadsheet, screenshot or chat export can carry privacy risk. Common mistake: treating information as harmless because it has no obvious medical or financial field.
Step 3: train the first 15 minutes
Give every person a short sequence:
- Stop the unsafe action and do not send further messages or share more data.
- Preserve the email, URL, file name, timestamp or recipient details.
- Contact the designated privacy or security channel immediately.
- Follow instructions about disconnecting a device, changing a password or contacting a recipient.
- Do not delete evidence, promise outcomes to customers or discuss the event publicly.
This sequence reduces delay and protects evidence. It also prevents well-intended actions, such as deleting an email, from making assessment harder.
Expected outcome: the response team receives useful details while they are fresh. Common mistake: a staff member tries to recall a misdirected email and then deletes it from Sent Items.
Step 4: make phishing part of NDB readiness
Phishing can lead to credential theft, inbox access and unauthorised disclosure of personal information. ASD's ACSC recorded phishing or social engineering in 60% of reported incidents in FY2024–25, so it belongs in every privacy-response program.
Use phishing simulations to practise the decision to report. Cyber Aware tracks clicks and reports, and can automatically assign a relevant lesson to people who click. Make clear that reporting a real suspicious message is always the right action, even if it turns out harmless.
Expected outcome: staff identify and escalate suspicious messages earlier. Common mistake: treating simulation failures as a disciplinary process rather than a training signal.
Step 5: train managers to escalate, not filter
Managers are often the first people told about an incident. Their job is to help the staff member report quickly and protect the person from blame, not to decide whether the incident is significant enough.
Give managers a separate 15-minute session with examples of misdirected emails, customer complaints, missing records and third-party incidents. Require them to escalate any suspected privacy event through the same channel within 30 minutes.
Expected outcome: management does not become a bottleneck. Common mistake: a manager waits for a weekly meeting or asks staff to fix the problem quietly.
Step 6: rehearse the response team
The response team needs practice beyond a written plan. Run a 60-minute tabletop exercise twice a year: one accidental disclosure and one cyber-enabled scenario such as an account takeover.
Walk through containment, what information is affected, whether serious harm is likely, which parties must be contacted and who approves communication. The OAIC states that an entity must conduct a prompt and reasonable assessment when it suspects an eligible data breach.
Expected outcome: decision-makers know their roles and dependencies. Common mistake: testing only the security team while excluding privacy, legal and customer-facing leaders.
Step 7: enrol every workforce group
Assign baseline NDB awareness training to employees, contractors, casual staff and managers within their first 7 days. Provide role-based lessons to customer support, HR, payroll, finance, IT and data owners.
Track completion and overdue assignments, then reconcile the training register against active accounts and contractor records. A training register missing contractors is weak evidence of readiness.
Expected outcome: all people with access to personal information receive an appropriate baseline. Common mistake: treating temporary staff as outside the program despite access to the same systems.
Step 8: review incidents and improve controls
After every privacy incident or near miss, capture what happened, which control failed and what needs to change. Possible changes include a clearer identity check, tighter sharing permissions, a system setting, a revised workflow or targeted training.
Use human risk reporting to see overdue lessons, quiz outcomes and phishing results together. Keep personal performance data restricted to people with a legitimate need to act on it.
Expected outcome: repeat errors decline because the program changes after evidence. Common mistake: adding another generic annual module while leaving the broken process untouched.
Troubleshooting
Staff are unsure what counts as a privacy incident
Use a short list of examples and the rule that suspected events should be reported. The response team decides severity; staff decide to escalate.
Reports arrive without enough detail
Add a simple incident form with fields for time, system, information involved, recipient or sender, and actions already taken. Accept an incomplete first report rather than delaying it.
People fear blame
Train managers to thank reporters and focus on containment. A blame-heavy response suppresses the early reports needed to limit harm.
Contractors cannot access training
Create an approved alternate enrolment route and a completion record. Do not accept verbal confirmation as the only evidence.
Tabletop exercises stall
Use a realistic but bounded scenario and a named facilitator. The goal is to test decisions and handoffs, not to produce a perfect legal conclusion in the room.
Tools and resources
- Cyber Aware training
- Phishing simulations
- Human risk reporting
- Cyber security gap assessment
- OAIC Notifiable Data Breaches scheme
FAQ
What is the Notifiable Data Breaches scheme?
The NDB scheme requires organisations and agencies covered by the Privacy Act to notify affected individuals and the OAIC when an eligible data breach is likely to result in serious harm.
Should staff decide whether to notify the OAIC?
No. Staff should report a suspected incident immediately. The designated response team assesses the event, contains it and determines notification obligations.
What should staff do after sending data to the wrong person?
They should stop further sharing, preserve the details, report it immediately through the internal route and follow the response team's instructions. They should not try to resolve it quietly or delete evidence.
Is phishing relevant to NDB training?
Yes. Phishing can give an attacker access to personal information or systems that hold it. Training should cover recognising, reporting and escalating suspicious messages.
How often should NDB training run?
Provide baseline training at onboarding, refresh it at least annually and use short role-based reinforcement after process or system changes. Response-team tabletop exercises should run regularly.
What evidence should an organisation keep?
Keep completion records, training content, incident reports, response exercises, control changes and records of exception handling. Retention should follow the organisation's policy and legal obligations.
One last thing
A well-trained employee does not need to know the legal definition of serious harm. They need to report a suspicious event in minutes, with enough detail for the people who do.