Data Security & Breach Notification
Privacy Act 1988 — Notifiable Data Breaches scheme
Australia · February 22, 2018
Australia's scheme turns on an 'eligible data breach': unauthorised access, disclosure, or loss of personal information that a reasonable person would conclude is likely to result in serious harm. There is no fixed notification deadline — s. 26WK requires the statement to the Australian Information Commissioner as soon as practicable after the entity becomes aware there are reasonable grounds to believe an eligible data breach has occurred — but there IS a fixed assessment deadline, which is where most of the compliance risk sits: where an entity only suspects an eligible breach, it must take all reasonable steps to complete a reasonable and expeditious assessment within 30 days. Individuals at risk are notified with the same statement. Note the entity-level scope limit: the Privacy Act's small-business exemption (turnover of AUD 3 million or less, subject to exceptions) means some businesses fall outside the scheme entirely — an unusual carve-out among the regimes here, and one under active reform pressure.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.