WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Privacy Act 1988 — Notifiable Data Breaches scheme

NDB scheme (Part IIIC)

Australia · February 22, 2018

Australia's scheme turns on an 'eligible data breach': unauthorised access, disclosure, or loss of personal information that a reasonable person would conclude is likely to result in serious harm. There is no fixed notification deadline — s. 26WK requires the statement to the Australian Information Commissioner as soon as practicable after the entity becomes aware there are reasonable grounds to believe an eligible data breach has occurred — but there IS a fixed assessment deadline, which is where most of the compliance risk sits: where an entity only suspects an eligible breach, it must take all reasonable steps to complete a reasonable and expeditious assessment within 30 days. Individuals at risk are notified with the same statement. Note the entity-level scope limit: the Privacy Act's small-business exemption (turnover of AUD 3 million or less, subject to exceptions) means some businesses fall outside the scheme entirely — an unusual carve-out among the regimes here, and one under active reform pressure.

Privacy Act 1988 (Cth), Part IIIC, ss. 26WE-26WR (esp. s. 26WK); Australian Privacy Principle 11Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.