Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
A data breach can turn into a legal and reputational problem fast, especially when a business is not sure whether it needs to notify anyone, how quickly it needs to act, or what counts as an eligible breach.
Many founders make the same mistakes: they wait too long while they investigate, assume only large companies have notification duties, or send vague messages that do not actually meet the legal standard. Others focus on the tech fix and forget the privacy and contract issues sitting behind it.
If your business handles customer details, employee records, payment information or account logins, this guide explains what Australian businesses need to know about data breach notification obligations. It covers when the rules apply, what “data breach” means in practice, the steps to take when an incident happens, and the common errors that cause extra damage after the breach itself.
Overview
Australian businesses can have legal notification obligations after a data breach, but the exact position depends on whether the Privacy Act applies to them, whether the incident is likely to cause serious harm, and what information was affected. Even if your business is not strictly caught by the Notifiable Data Breaches scheme, a privacy incident can still trigger contractual, regulatory and commercial problems that need a fast response.
- Check whether your business is covered by the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme.
- Work out what data was involved, whether it was accessed, disclosed or lost, and whether serious harm is likely.
- Assess quickly and document your decision making, including what you know, what you do not know yet, and who is responsible.
- Notify affected individuals and the Office of the Australian Information Commissioner if the breach is an eligible data breach.
- Review contracts, cybersecurity processes, staff access controls, privacy policies and incident response steps after the immediate issue is contained.
What Data Breech Means For Australian Businesses
A data breach usually means personal information has been lost, accessed without authorisation, or disclosed to the wrong person. In Australian privacy law, the more important question is whether the incident becomes an “eligible data breach” that triggers notification obligations.
For many businesses, the key law is the Privacy Act 1988 (Cth). That Act includes the Notifiable Data Breaches scheme, which requires certain organisations to assess suspected breaches and notify where serious harm is likely. The Office of the Australian Information Commissioner, often called the OAIC, oversees this area.
What counts as personal information?
Personal information is broader than many business owners expect. It is not limited to passport scans or Medicare numbers. It can include any information or opinion about an identified individual, or someone who is reasonably identifiable.
That may include:
- customer names, phone numbers and email addresses
- employee HR records and payroll details
- addresses and dates of birth
- bank account or payment card details
- account usernames and passwords
- health information
- ID documents and licence numbers
- location data or device identifiers, depending on context
When does a data breech become an eligible data breach?
An eligible data breach generally arises where:
- there is unauthorised access to, or unauthorised disclosure of, personal information held by an organisation, or information is lost in circumstances where unauthorised access or disclosure is likely
- serious harm to one or more individuals is likely
- the organisation has not been able to prevent the likely risk of serious harm through remedial action
Serious harm can include financial loss, identity theft, emotional or psychological harm, physical harm, reputational damage, or other serious consequences. Whether serious harm is likely depends on the facts. A laptop stolen from a car may be treated differently if the files were strongly encrypted than if they were saved in plain text and accessible with no password.
Does every Australian business have to comply?
No. The Privacy Act does not apply to every business in the same way. Many small businesses are exempt, but there are important exceptions. Some businesses with turnover under $3 million are still caught, including some health service providers, businesses that trade in personal information, and businesses covered for other specific reasons.
This is where founders often get caught. They hear that “small businesses are exempt” and assume there is nothing to do. That can be wrong for two reasons. First, the exemption may not apply to their business. Second, even where the Privacy Act does not strictly apply, customers, enterprise clients, investors and platforms may still expect proper incident handling, fast notice, and contractual compliance.
Why this matters beyond privacy law
A data breech is rarely just a privacy issue. It can affect:
- customer trust and churn
- service agreements with clients that require prompt security notifications
- supplier agreements and software contracts with incident reporting clauses
- employment issues if staff actions caused or worsened the problem
- insurance notifications under cyber or business policies
- board and investor reporting
- public statements that need to be accurate and not misleading
For startups and SMEs, the main risk is often the gap between technical response and legal response. A founder might restore systems, reset passwords and move on, but miss a client contract requiring notice within 24 hours, or fail to preserve enough records to justify why the business decided the event was not notifiable.
When This Issue Comes Up
Data breach notification obligations usually come up in ordinary business moments, not dramatic movie-style hacks. Most incidents start with a rushed team member, a weak process, or a system that was never properly locked down.
Emailing information to the wrong person
This is one of the most common small business incidents. A staff member sends a spreadsheet of customer data to the wrong recipient, attaches the wrong file to an email, or copies in someone who should not receive the information.
Whether notification is required depends on what was sent, who received it, whether they opened it, and whether the risk can be contained. If the recipient confirms deletion and the circumstances show serious harm is not likely, the incident may not become an eligible data breach. You still need to assess it properly rather than guess.
Phishing and compromised logins
A founder or staff member clicks a phishing link and hands over email credentials. An attacker then accesses inboxes, cloud files, invoices or customer records. This can expose far more information than the first compromised account suggests.
Before you spend money on setup for any digital tool, it is worth checking whether multi-factor authentication, role-based access, audit logs and offboarding processes are in place. Those practical settings often decide whether an incident becomes a contained scare or a notifiable breach.
Lost devices and removable storage
Phones, laptops and USBs still create problems, especially for businesses with mobile sales teams, healthcare workers, consultants and tradies using field devices. If personal information is stored locally and not properly encrypted, losing the device can trigger a serious assessment exercise very quickly.
Third-party software and service providers
Many Australian businesses rely on CRM systems, payroll platforms, ecommerce apps, outsourced IT providers and cloud hosting. If a vendor suffers a security incident, your business may still have obligations to customers or employees whose information you hold through that platform.
This is why privacy and data clauses matter before you sign a contract. You want clear terms around:
- incident notification timing
- cooperation during investigations
- security standards and access controls
- subcontracting and offshore storage
- responsibility for customer communications
- indemnities and liability limits
Former staff access and internal misuse
Not every data breech is external. A former employee with active logins, or a current staff member accessing records they do not need, can create a serious issue. Small businesses often miss this because they trust their team and do not build formal access rules.
Employment contracts, workplace policies and offboarding checklists all matter here. If your systems allow broad internal access with no clear need-to-know restrictions, the legal and operational risk rises.
Mergers, investment due diligence and growth stages
This issue also surfaces when a business is raising capital, selling, onboarding enterprise clients, or expanding into new products. Investors and larger customers often ask detailed questions about privacy compliance, security incidents and incident response capability.
A past data breech that was handled poorly can slow down a deal, reduce confidence in management, or create warranty issues in transaction documents. For growth-stage businesses, notification obligations are not just about compliance after a problem. They also affect value, credibility and contract negotiations.
Practical Steps And Common Mistakes
When a data breach happens, your business should contain the incident, assess whether serious harm is likely, make required notifications if needed, and keep clear records of what you did and why. Speed matters, but so does accuracy.
Step 1: Contain the incident straight away
The first job is to stop the problem getting worse. That may mean disabling compromised accounts, revoking access, isolating systems, resetting passwords, contacting your IT provider, or recovering information sent to the wrong recipient.
Containment actions often include:
- locking user accounts and forcing password resets
- enabling or re-enabling multi-factor authentication
- removing malicious forwarding rules from email
- cutting off third-party access tokens
- asking an unintended recipient to delete information
- preserving logs and evidence for later review
One common mistake is wiping or rebuilding systems before enough evidence is preserved. If you cannot later work out what happened, who was affected, or whether data was exfiltrated, your legal assessment becomes much harder.
Step 2: Start an assessment quickly
If you suspect an eligible data breach may have occurred, Australian privacy law expects a reasonable and expeditious assessment. Businesses should not let incidents drift while waiting for perfect information.
Your internal assessment should identify:
- what happened and when
- what systems and data sets were involved
- what type of personal information was affected
- how many individuals may be impacted
- whether the information was encrypted or otherwise protected
- whether the information has been recovered or access prevented
- the likely harm that could result
- whether contractual notices also need to go out
Put one person or a small response team in charge. In small businesses, confusion about ownership is a major reason notifications are delayed or inconsistent.
Step 3: Decide whether notification is required
If the incident is an eligible data breach, the business generally needs to notify the OAIC and affected individuals as soon as practicable. The notice needs to do more than say there was a “security issue”. It should describe the incident, the kinds of information involved, and recommended steps individuals should take in response.
The content and timing of your notification matters. A rushed message can create panic or understate the problem. A vague message can fail to meet legal expectations. A delayed message can expose people to avoidable harm, especially if they need to reset passwords, contact their bank or watch for identity fraud.
Step 4: Check contracts and other reporting duties
Privacy law is only one part of the picture. Review your customer terms, platform terms, software agreements, cyber insurance and internal governance documents. You may have separate notice periods, cooperation duties, or approval processes for external communications.
Before you sign major client contracts, this is one of the most useful things to negotiate clearly. Security and privacy clauses drafted for larger enterprises often put very short deadlines on SMEs without giving them enough room to investigate first.
Step 5: Update your documents and processes
After the immediate response, fix the gaps that allowed the incident to happen or made it harder to manage. For many businesses, that means reviewing both legal documents and operational controls.
That can include:
- updating your privacy policy so it accurately reflects collection, use, disclosure and storage practices
- reviewing website terms and ecommerce flows if you collect customer data online
- tightening staff policies on device use, passwords and confidential information
- improving service agreements with IT providers and data processors
- creating a simple incident response plan with clear decision makers
- checking whether your trade mark, brand and customer communications strategy are ready if a public response is needed
Not every item will apply to every business, but the point is practical: a breach often exposes that privacy compliance was treated as a policy document, rather than part of day-to-day business operations.
Common mistakes Australian businesses make
The same issues come up again and again after a data breach:
- assuming the business is too small to have any legal exposure
- failing to keep a written record of the assessment
- waiting for a complete forensic report before making basic decisions
- not checking whether a vendor or contractor caused the incident
- sending inconsistent messages to customers, staff and clients
- forgetting employee records, which can raise separate issues even though the Privacy Act has specific treatment for some employment records
- using a privacy policy copied from another business that does not reflect actual practices
- ignoring contract notice deadlines
Another common mistake is treating privacy as separate from business structure and growth planning. If you are setting up a new venture, changing your business structure, selling online, hiring staff, or rolling out a new app, privacy settings and document drafting should happen before launch, not after an incident. Registration, branding, trade mark strategy, customer terms, employment contracts and privacy documents often need to line up.
FAQs
Do all Australian small businesses have to report a data breech?
No. Not all small businesses are covered by the Privacy Act and the Notifiable Data Breaches scheme. But some are, and even businesses outside the scheme may still have contractual, commercial or other regulatory obligations, so it is risky to assume no action is needed.
How fast do we need to assess a suspected breach?
You should act quickly and carry out a reasonable and expeditious assessment. The law does not reward delay while a business waits for every detail. Early containment and a documented assessment are both important.
What if the information was encrypted?
Encryption can be a major factor in deciding whether serious harm is likely. If the data was strongly protected and the attacker could not realistically access it, notification may not be required. You still need to assess the facts carefully.
Do we need to notify customers every time there is a cyber incident?
No. Notification is not required for every incident. The key question is whether the incident amounts to an eligible data breach, including whether serious harm is likely. Some incidents can be contained before that threshold is reached.
What documents should a business review after a data breech?
Common documents to review include your privacy policy, customer terms, supplier agreements and software contracts, employment agreements, workplace policies, confidentiality terms, cyber insurance wording and any internal incident response plan.
Key Takeaways
- A data breech can trigger legal notification duties in Australia if it is an eligible data breach under the Privacy Act and serious harm is likely.
- Not every incident is notifiable, but every suspected breach should be assessed quickly, documented properly and contained straight away.
- Small businesses should not assume they are exempt, because the Privacy Act exceptions can be technical and contracts may impose separate obligations.
- Good response management includes legal, technical and communications steps, not just fixing the system problem.
- Privacy policies, supplier contracts, staff access controls and incident response procedures all matter before and after a breach.
If your business is dealing with data breach and wants help with privacy compliance, breach notification assessments, supplier contracts, and privacy policies, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.
Connect the privacy document to the real data flow
What should the business map before updating its policy?
Collection points, purposes, vendors, disclosures, retention and incident handling must match what the policy and notices actually say.






