Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
A data breach can turn into a legal and reputational problem fast, especially when a business is not sure whether it needs to notify anyone, how quickly it needs to act, or what counts as an eligible breach.
Many founders make the same mistakes: they wait too long while they investigate, assume only large companies have notification duties, or send vague messages that do not actually meet the legal requirements. Others focus on the technical fix and forget about the privacy and contractual issues sitting behind it.
If your business handles customer details, staff or applicant information, payment information or account logins, this guide explains what Australian businesses need to know about data breach notification obligations. It covers when the rules apply, what a data breach means in practice, the steps to take when an incident happens, and the common errors that can cause further problems after the breach itself.
Overview
Australian businesses can have legal notification obligations after a data breach, but the exact position depends on whether the Privacy Act 1988 (Cth) applies to them, whether the incident is likely to cause serious harm, and what information was affected.
Even if your business is not strictly caught by the Notifiable Data Breaches scheme, a privacy or security incident may still trigger contractual obligations, sector-specific requirements and commercial issues that require a fast response.
- Check whether your business is covered by the Privacy Act and the Notifiable Data Breaches scheme.
- Work out what information was involved, whether it was lost, accessed without authorisation or disclosed without authorisation, and whether serious harm is likely.
- Contain the incident and consider whether remedial action can remove the likely risk of serious harm.
- If you suspect there may have been an eligible data breach, carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days.
- Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) if the incident is an eligible data breach and no exception applies.
- Review contracts, cybersecurity processes, staff access controls, privacy documents and incident response procedures once the immediate issue is contained.
What A Data Breach Means For Australian Businesses
A data breach generally involves personal information being lost, accessed without authorisation or disclosed without authorisation.
However, not every data breach needs to be reported under Australian privacy law. The more important legal question is whether the incident becomes an “eligible data breach” under the Notifiable Data Breaches scheme.
For many businesses, the key law is the Privacy Act 1988 (Cth). Part IIIC of the Privacy Act contains the Notifiable Data Breaches scheme, which requires covered entities to assess suspected eligible data breaches and notify the OAIC and affected individuals where the legal threshold is met.
What Counts As Personal Information?
Personal information is broader than many business owners expect. It is not limited to passport scans or Medicare numbers.
Under the Privacy Act, personal information generally includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on the circumstances, this may include:
- customer names, phone numbers and email addresses
- employee, contractor or applicant information
- addresses and dates of birth
- bank account or payment details
- account credentials linked to an identifiable individual
- health information
- ID documents and licence numbers
- location information or device identifiers where an individual can reasonably be identified
Employee records need some additional care. The Privacy Act contains an employee records exemption that can apply to certain acts or practices of private sector employers where they are directly related to a current or former employment relationship and an employee record. The exemption is not universal, however, and separate rules can still apply to information such as tax file numbers.
When Does A Data Breach Become An Eligible Data Breach?
An eligible data breach generally arises where:
- there is unauthorised access to or unauthorised disclosure of personal information held by an entity, or the information is lost in circumstances where unauthorised access or disclosure is likely
- the access, disclosure or loss is likely to result in serious harm to one or more individuals, and
- the entity has not been able to prevent the likely risk of serious harm through remedial action
Whether serious harm is likely depends on the circumstances. Relevant harm can include identity theft, financial loss, serious psychological harm, physical harm or serious reputational harm.
The type and sensitivity of the information, the people who may have obtained it, the security protections in place and the possible consequences for affected individuals can all matter.
For example, a stolen laptop containing customer information may create a very different risk if the device and files are strongly encrypted than if the information can be opened immediately without authentication.
Can Fixing The Problem Mean You Do Not Need To Notify?
Sometimes.
The Notifiable Data Breaches scheme specifically allows businesses to take remedial action. If that action is effective enough that serious harm is no longer likely, the incident may not amount to an eligible data breach requiring notification.
For example, information may accidentally be sent to the wrong recipient. If the business acts immediately, the recipient confirms the information has not been accessed or further disclosed and permanently deletes it, the likelihood of serious harm may be removed.
That does not mean the business should simply assume the problem has been fixed. The circumstances still need to be properly assessed and documented.
Does Every Australian Business Have To Comply?
No. The Privacy Act does not apply to every Australian business in the same way.
Generally, businesses with annual turnover of more than $3 million are covered. Many businesses with annual turnover of $3 million or less fall within the small business exemption, but there are important exceptions.
For example, certain small businesses may still be covered because they provide health services and hold health information, trade in personal information, are related to a larger organisation covered by the Privacy Act, handle particular regulated information, or fall within another category captured by the legislation.
This is where businesses can get caught out. Hearing that “small businesses are exempt” is not enough to determine whether the Privacy Act applies to a particular business.
Even where the Privacy Act does not apply, there may also be other obligations under contracts, state or territory legislation, industry-specific rules or other regulatory regimes.
Why This Matters Beyond Privacy Law
A data breach is rarely just a privacy issue.
It can affect:
- customer trust and retention
- client agreements containing security incident notification requirements
- supplier and technology agreements
- employment and workplace issues
- cyber insurance notification requirements
- board and investor reporting
- regulatory obligations outside the Privacy Act
- public statements that need to be accurate and not misleading
For startups and SMEs, one of the biggest risks is the gap between the technical response and the legal response.
A founder might restore systems, reset passwords and assume the problem is solved, while overlooking a client contract that requires security incidents to be reported within a particular timeframe or failing to keep enough records to explain why the business decided notification under the Privacy Act was not required.
When This Issue Comes Up
Data breach notification obligations often arise from ordinary business mistakes rather than dramatic cyberattacks.
Emailing Information To The Wrong Person
This is one of the most common scenarios.
A staff member sends a spreadsheet of customer information to the wrong recipient, attaches the wrong document to an email or copies someone into a message who should not have received the information.
Whether notification is required depends on factors including what was sent, who received it, whether it was accessed and whether the risk can be effectively contained.
If the recipient confirms deletion and the circumstances indicate that serious harm is no longer likely, remedial action may mean the incident does not become an eligible data breach. The business should still assess and record what happened rather than simply assuming the issue has disappeared.
Phishing And Compromised Logins
A founder or staff member clicks a phishing link and hands over their email credentials. An attacker then accesses inboxes, cloud files, invoices or customer records.
The initial compromised account can expose much more information than expected, which is why the investigation should look at what the attacker could actually access rather than only the account where the problem started.
Multi-factor authentication, role-based access, audit logs and effective offboarding processes can all reduce both the likelihood and potential impact of an incident.
Lost Devices And Removable Storage
Phones, laptops and USB drives can still create significant risks, particularly for businesses with mobile teams or staff working away from a central office.
If personal information is stored locally and the device is lost without appropriate security protections, the business may need to assess whether unauthorised access is likely and whether the incident creates a likely risk of serious harm.
Third-Party Software And Service Providers
Many Australian businesses rely on CRM systems, payroll platforms, ecommerce applications, outsourced IT providers and cloud hosting services.
If one of those providers experiences a security incident, your business may still need to consider its own obligations in relation to the personal information involved.
Where more than one organisation holds the same information, the legal position can become more complicated. Contracts should therefore clearly address matters such as:
- incident notification timing
- cooperation during investigations
- security standards and access controls
- subcontracting
- overseas handling of information
- responsibility for communicating with affected individuals
- liability and indemnity arrangements
Contract terms can help allocate responsibility between businesses, but they do not necessarily remove statutory privacy obligations that independently apply to either party.
Former Staff Access And Internal Misuse
Not every data breach comes from an external attacker.
A former employee with active login credentials, or a current staff member accessing records they have no legitimate reason to view, can also create a data breach.
Employment contracts, workplace policies and proper offboarding processes can help establish clear rules around confidential information and system access.
Technical controls matter as well. If every staff member can access large amounts of customer information regardless of their role, the business may be creating unnecessary exposure.
Mergers, Investment Due Diligence And Growth Stages
Privacy and cybersecurity issues also tend to surface when a business is raising capital, being acquired, onboarding enterprise clients or expanding into new products.
Investors and larger customers may ask detailed questions about privacy compliance, previous security incidents and incident response procedures.
A previous data breach that was poorly handled can affect confidence in the business, complicate due diligence or create issues around warranties and disclosures in transaction documents.
For a growing business, data breach preparation is therefore not only about reacting after something goes wrong. It also forms part of broader legal and operational readiness.
Practical Steps And Common Mistakes
When a data breach happens, a business should generally move quickly to contain the incident, assess what happened, consider remedial action, notify where legally required and document its decisions.
These stages may happen simultaneously rather than neatly one after another.
Step 1: Contain The Incident Straight Away
The first priority is usually to prevent the problem from becoming worse.
Depending on the incident, that may mean:
- locking compromised user accounts
- forcing password resets
- enabling or re-enabling multi-factor authentication
- removing malicious email forwarding rules
- revoking third-party access tokens
- isolating affected systems
- contacting relevant IT or security providers
- asking an unintended recipient to delete information
- preserving logs and other evidence for later review
One common mistake is wiping or rebuilding systems before enough evidence has been preserved.
If the business later cannot determine what happened, who may have accessed the information or what information was affected, assessing the legal position becomes much harder.
Step 2: Start The Assessment Quickly
Where a business covered by the NDB scheme has reasonable grounds to suspect that there may have been an eligible data breach, section 26WH of the Privacy Act requires a reasonable and expeditious assessment.
The business must take all reasonable steps to complete that assessment within 30 calendar days after becoming aware of the grounds that caused it to suspect an eligible data breach.
The 30 days should not be treated as an automatic investigation period. The OAIC expects organisations to complete assessments sooner where possible.
The assessment should consider:
- what happened and when
- what systems were affected
- what personal information was involved
- who may have accessed or received it
- how many individuals may be affected
- the sensitivity of the information
- whether encryption or other security controls protected it
- whether the information has been recovered
- whether remedial action has prevented serious harm
- what harm could realistically result
- whether contractual or other regulatory notifications are also required
It is also useful to put one person or a small response team in charge of the process. Unclear responsibility can easily lead to delays or inconsistent decisions.
Step 3: Decide Whether Notification Is Required
If the business has reasonable grounds to believe an eligible data breach has occurred, it generally needs to prepare the required statement, provide it to the OAIC and notify affected individuals as soon as practicable, unless an exception applies.
Under section 26WK of the Privacy Act, the statement must include:
- the identity and contact details of the entity
- a description of the eligible data breach
- the particular kind or kinds of information involved
- recommendations about the steps affected individuals should take in response
This is why a notification should usually do more than simply say there has been a “security incident”.
The communication should give affected individuals enough information to understand what happened and take reasonable protective action, such as changing passwords, contacting a financial institution or watching for identity fraud where appropriate.
Step 4: Check Contracts And Other Reporting Duties
Privacy law is only one part of the response.
Review your customer terms, supplier and technology agreements, cyber insurance policy and relevant governance documents.
These may contain separate notice periods, cooperation requirements or procedures for external communications.
It is particularly important to review security and privacy clauses before signing major customer or supplier contracts. Some contracts impose very short incident-notification periods, which can operate separately from the timing requirements under the Privacy Act.
Step 5: Update Your Documents And Processes
Once the immediate incident is under control, look at what allowed it to happen or made the response harder than it needed to be.
Depending on the business, this might mean:
- updating your privacy policy so it reflects how personal information is actually collected, used, disclosed and stored
- reviewing privacy collection notices given when information is collected
- improving privacy and data-security clauses in supplier and technology contracts
- reviewing arrangements with third parties that process or store personal information
- tightening staff policies around devices, passwords and confidential information
- limiting system access according to what each person actually needs
- introducing clearer onboarding and offboarding procedures
- adopting an Information Security Policy
- putting a Data Breach Response Plan in place with clear roles, escalation procedures and decision points
For businesses covered by the Australian Privacy Principles, APP 11 also requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
The important point is that privacy compliance should not exist only on a website. Your legal documents and operational practices need to work together.
Common Mistakes Australian Businesses Make
The same issues tend to appear repeatedly after a data breach:
- assuming the business is too small for privacy law to apply
- failing to keep a written record of the assessment and decision
- treating the 30-day assessment period as permission to wait 30 days
- waiting for a complete forensic investigation before making decisions that can already be made
- failing to consider remedial action
- overlooking incidents caused by vendors or contractors
- sending inconsistent information to customers, employees and clients
- misunderstanding how the employee records exemption operates
- using a privacy policy copied from another business that does not reflect actual practices
- forgetting contractual notification deadlines
- focusing entirely on the technical problem and ignoring the legal response
Ideally, these issues should be addressed before a breach occurs.
If your business is launching a new product, hiring staff, collecting more customer information or introducing new software, your privacy documents, supplier arrangements, internal access controls and incident response process should grow with the business rather than being dealt with only after something goes wrong.
FAQs
Do All Australian Small Businesses Have To Report A Data Breach?
No.
Not every small business is covered by the Privacy Act or the Notifiable Data Breaches scheme. However, the small business exemption has a number of important exceptions, so turnover alone does not always answer the question.
Businesses outside the NDB scheme may also have contractual, sector-specific or other regulatory obligations following an incident.
How Fast Do We Need To Assess A Suspected Breach?
If your business is covered by the NDB scheme and has reasonable grounds to suspect there may have been an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days.
The OAIC treats 30 days as the maximum assessment period and expects businesses to finish sooner wherever possible.
What If The Information Was Encrypted?
Encryption can be an important factor when determining whether serious harm is likely.
If strong encryption or another security measure means the information cannot realistically be accessed, that may reduce the likelihood of serious harm and affect whether notification is required.
However, encryption should not automatically be treated as proof that there is no risk. The effectiveness of the protection and the circumstances of the incident still need to be assessed.
Do We Need To Notify Customers Every Time There Is A Cyber Incident?
No.
Not every cyber incident is a data breach, and not every data breach is an eligible data breach.
Under the NDB scheme, notification generally becomes mandatory where there has been unauthorised access, disclosure or qualifying loss of personal information, serious harm is likely and remedial action has not removed that likely risk.
What Documents Should A Business Review After A Data Breach?
Depending on the business and incident, documents worth reviewing may include your privacy policy, privacy collection notices, customer terms, supplier and software agreements, employment agreements, workplace policies, confidentiality terms, cyber insurance wording, Information Security Policy and Data Breach Response Plan.
Key Takeaways
- A data breach can trigger legal notification duties in Australia where it meets the requirements for an eligible data breach under the Privacy Act.
- Not every breach needs to be notified, and effective remedial action can sometimes prevent an incident from becoming an eligible data breach.
- If a covered entity suspects an eligible data breach, it must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days.
- Once there are reasonable grounds to believe an eligible data breach has occurred, notification must generally happen as soon as practicable.
- Small businesses should not automatically assume they are exempt, because the Privacy Act contains a number of exceptions and other legal or contractual obligations may still apply.
- A good response combines legal, technical and communications steps rather than focusing only on fixing the system.
- Privacy policies, supplier contracts, access controls, Information Security Policies and Data Breach Response Plans can all help a business prepare before an incident happens.
If your business is dealing with a data breach and needs help understanding its notification obligations, reviewing its privacy compliance or putting the right documents in place, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.
Connect the privacy document to the real data flow
What should the business map before updating its policy?
Collection points, purposes, vendors, disclosures, retention and incident handling must match what the policy and notices actually say.






