What counts as a notifiable data breach in Australia?

A notifiable data breach in Australia is unauthorised access to personal information likely to cause serious harm. What counts, what does not and the deadlines in 2026.

A notifiable data breach in Australia is an eligible data breach under the Notifiable Data Breaches scheme: unauthorised access to, unauthorised disclosure of, or loss of personal information that a reasonable person would conclude is likely to result in serious harm — and which remedial action cannot fix in time. When that test is met, the Privacy Act 1988 requires you to notify the Office of the Australian Information Commissioner and every affected individual as soon as practicable.

Key takeaways

What counts as a notifiable data breach?

The scheme turns on four questions. Work through them in order:

QuestionThe test
What was exposed?Personal information: names, addresses, health records, tax file numbers, payment details, ID documents
What happened?Unauthorised access, unauthorised disclosure, or loss
Is harm likely?A reasonable person would conclude serious harm — identity theft, financial loss, safety risks — is likely
Can you fix it?Remedial action has not removed the likely risk of serious harm before it lands

If all four resolve against you, you notify. If any one resolves in your favour, the breach is not eligible — but you still assess and document the reasoning, because the OAIC expects to see that assessment if it ever asks.

Who has to comply

The scheme binds organisations covered by the Privacy Act. In practice that means Australian Government agencies and private-sector organisations with annual turnover of more than $3 million, along with categories covered regardless of turnover — health service providers, organisations that buy or sell personal information, credit reporting bodies and others. If you sit under the $3 million line, do not assume you are exempt: the exceptions are narrower than most owners think, and enterprise clients routinely impose equivalent obligations by contract anyway.

What does not count

Each of these still deserves a written assessment. The judgment call is exactly what an assessor, a client or the OAIC will probe later, and the file is your defence.

Examples that count in 2026

Notice what four of these share: a person did something ordinary, and the harm followed from it. Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches and again found a human element in roughly 60% of them (full report PDF) — your people, not your firewall, decide most of these cases.

How quickly must you assess and notify?

You must assess a suspected eligible breach as soon as practicable, and OAIC guidance expects that assessment completed within 30 days of becoming aware. If it is eligible, notify both the OAIC and affected individuals as soon as practicable — there is no grace period for getting the wording perfect.

The notification must state your identity, describe the breach, list the kinds of information involved and recommend the steps individuals should take. Practical advice beats legal hedging: tell people exactly which accounts to change passwords on and to expect follow-up phishing that exploits the breach itself.

What this means for prevention

The cheapest eligible breach is the one that never happens, and the controls that prevent the examples above are unglamorous: enforced MFA, least-privilege mailbox access, and staff who report suspicious mail within minutes. Speed of reporting matters as much as click rate — a mailbox compromise reported the same day is a far smaller exposure than one that sits undetected for a month, and Cyber Aware's human risk reporting tracks both numbers per learner.

If you are not sure whether to notify

Assess anyway, in writing, against the four questions. If the answer stays genuinely unclear, the OAIC's report a data breach guidance sets out the process, and voluntary notification is always available — an early report is treated far better than a late discovery. For businesses that have never written an assessment, a security gap assessment puts the surrounding controls — access, training records, incident plan — on paper first, which makes the breach assessment itself straightforward instead of improvised.

FAQ

What counts as a notifiable data breach in Australia? Unauthorised access, disclosure or loss of personal information that is likely to result in serious harm and cannot be prevented by remedial action. Notify the OAIC and affected individuals as soon as practicable.

Do small businesses have to report data breaches? Organisations with turnover over $3 million do. Below that line some categories are still covered — health providers, for instance — and client contracts often impose equivalent duties regardless.

How quickly must a breach be notified? As soon as practicable after the assessment concludes it is eligible, with the assessment itself expected within 30 days of awareness.

Is a lost laptop a notifiable breach? Usually not, if the drive is fully encrypted and keys are secure. Without encryption it likely is — assess against the four questions.

What happens if a business does not report an eligible breach? The OAIC can investigate and apply substantial civil penalties for serious or repeated interference with privacy, and the reputational cost of concealment compounds both.

Does an incident that is not notifiable need to be documented? Yes. The assessment reasoning is your evidence that you met the obligations, and it is the first thing asked for later.

One last thing

The OAIC's breach statistics show the same pattern every reporting period: malicious attacks cause most notifiable breaches, and phishing is the most common way in. Your breach-notification plan and your phishing programme are the same document wearing different covers — write them once, together.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.