What to Do After a Privacy Breach in Australia

Alex Solo
byAlex Solo11 min read

If your business has breached privacy, the first few hours matter. Many founders make the same mistakes, they delete evidence too early, assume the issue is too small to report, or send a rushed apology before they know what information was exposed. Others focus only on the technical fix and forget the legal and customer communication side.

A privacy incident can affect your customers, staff, suppliers and reputation at the same time. It can also trigger obligations under Australian privacy law, your contracts, internal policies and insurance terms. The right response is not just about stopping the leak. It is about working out what happened, containing the risk, deciding whether notification is required, and documenting each decision properly.

This guide explains what breached privacy means for Australian businesses, when these issues usually come up, what practical steps to take straight away, and the common mistakes that can make a bad situation worse.

Overview

A privacy breach is not limited to a hacker stealing customer data. It can also be an employee emailing personal information to the wrong person, losing a laptop, publishing private details by mistake, or giving access to a system without proper controls. Australian businesses should respond fast, but they also need a calm process so they can make sound legal and commercial decisions.

The key question is whether personal information has been lost, accessed, used or disclosed without authorisation, and whether the harm is serious enough to trigger notification obligations.

  • Contain the incident immediately and preserve evidence
  • Work out what personal information was involved and whose information was affected
  • Assess whether serious harm is likely and whether the Notifiable Data Breaches scheme may apply
  • Review contracts, privacy policies, internal procedures and cyber insurance notice requirements
  • Prepare clear communications for affected people, regulators and commercial partners where needed
  • Record what happened, what decisions were made, and how you will reduce the risk of it happening again

What Breached Privacy Means For Australian Businesses

For an Australian business, breached privacy usually means personal information has been handled in a way that was not authorised, was not secure, or was not consistent with your legal obligations and stated practices.

Personal information is broad. It can include names, email addresses, phone numbers, addresses, dates of birth, payment details, employee records held in some contexts, identification documents, health information, and online identifiers where they can identify a person.

Privacy breaches are often broader than business owners expect

Many people hear the word “breach” and think of a cyber attack. That is only one category. A breached privacy issue can also happen through ordinary day-to-day mistakes.

  • A staff member sends a spreadsheet of customer details to the wrong recipient
  • An online form collects more information than your business needs and stores it insecurely
  • A contractor is given access to a CRM without proper permissions
  • Paper files are left in a public area or disposed of without secure destruction
  • A database backup is exposed through poor cloud settings
  • A former employee still has access to inboxes or systems after leaving

This matters because your response should be based on the actual risk, not on whether the incident feels “technical” or “serious” at first glance.

Which Australian privacy rules may matter

The main federal privacy framework for many businesses is the Privacy Act 1988, including the Australian Privacy Principles and the Notifiable Data Breaches scheme. Not every small business is automatically covered in every situation, but many are caught because of the type of information they handle, the services they provide, or their turnover and business model.

Even where the Privacy Act does not clearly apply, privacy obligations can still arise through:

  • Customer contracts and supplier agreements
  • Confidentiality clauses
  • Platform and software provider terms
  • Industry standards
  • Your privacy policy, collection notices and public statements
  • General obligations to take reasonable care with sensitive business operations

This is where founders often get caught. They assume that if they are a small business, they can treat the incident informally. In practice, the commercial and reputational consequences can be just as real.

If your business is subject to the Privacy Act, the Notifiable Data Breaches scheme can require notification where there has been unauthorised access to, unauthorised disclosure of, or loss of personal information, and this is likely to result in serious harm to individuals.

Serious harm depends on the context. You need to consider the kind of information involved, whether it is protected, who may now have it, and what harm could flow. Financial fraud, identity theft, humiliation, reputational damage and physical safety risks may all be relevant.

The test is not whether harm has already happened. The issue is whether serious harm is likely. That is why a proper early assessment matters.

When This Issue Comes Up

Privacy breaches usually surface during ordinary business activity, not dramatic headline events. They often appear when a business is growing quickly, changing systems, using contractors, or moving faster than its internal controls.

Common founder moments that lead to a privacy incident

A lot of breaches happen during transition points, especially before you sign a new software contract or before you spend money on setup for a new process without checking how data will move.

  • Migrating to a new CRM, booking system or ecommerce platform
  • Hiring staff quickly and skipping access control steps
  • Using shared spreadsheets to manage customer or employee records
  • Outsourcing admin, marketing or IT support without clear confidentiality and security terms
  • Launching online forms or lead generation campaigns that collect personal information
  • Working remotely with personal devices and weak password practices
  • Integrating payment, health, HR or identity verification tools

Breached privacy issues are also common after a relationship breaks down, such as when a founder leaves, a contractor is terminated, or a supplier account is not shut off properly.

Examples that are easy to underestimate

Not every incident looks dramatic on day one. Small errors can still create legal risk.

  • A medical practice sends appointment details to the wrong patient
  • An online store exposes order histories through a customer portal bug
  • A recruiter shares candidate resumes outside the intended hiring team
  • A professional services firm loses an unencrypted USB containing client records
  • A hospitality business keeps ID scans longer than necessary and stores them insecurely

In each case, the practical question is the same. What information was involved, who could access it, what harm could follow, and what should the business do now?

Why this issue is not just a privacy policy problem

A privacy breach often shows up as a systems or people problem, but it can quickly become a contract, employment and governance problem too.

For example, if your service agreement promises certain security measures, a client may allege breach of contract. If an employee caused the problem, you may need to manage disciplinary steps carefully and review employment contracts and training records. If your software provider contributed to the incident, the supplier agreement may affect liability, cooperation and timing.

This is why businesses should treat a breached privacy event as a cross-functional issue. Legal, management, IT and operations usually need to work together.

Practical Steps And Common Mistakes

The best first response is to contain the breach, investigate the facts, and make decisions from evidence rather than panic. A rushed response can create fresh problems, especially if you notify too early, say too much, or miss a reporting obligation.

1. Contain the issue straight away

Your first priority is to stop further loss or disclosure of personal information. The exact steps depend on the incident, but speed matters.

  • Disable compromised accounts or reset passwords
  • Shut down public access to exposed files or systems
  • Recall emails where possible and contact unintended recipients
  • Recover devices, files or hard copy records
  • Suspend risky integrations or user permissions
  • Ask IT or security providers to preserve logs and forensic evidence

A common mistake is deleting affected data or wiping systems immediately. That can make it harder to understand what happened and whether notification is required. Preserve evidence before major clean-up work where possible.

2. Identify what information is involved

You need a clear fact base before you can assess legal risk. Start with a simple incident record.

  • What happened and when
  • How the incident was discovered
  • What systems, devices or records were involved
  • What categories of personal information were affected
  • How many individuals may be affected
  • Whether the information was encrypted, password protected or otherwise secured
  • Who may have gained access

Do not assume that a low number of affected people means low risk. A small breach involving health information, identification documents or payroll details can be more serious than a larger breach involving basic contact information.

3. Assess whether serious harm is likely

This assessment is often the key legal turning point. If the Privacy Act applies to your business, you may need to carry out a reasonable and expeditious assessment of suspected eligible data breaches.

Think about factors such as:

  • The sensitivity of the information
  • Whether the information could be used for identity theft, fraud, blackmail or targeting
  • Whether the recipient is trustworthy or unknown
  • Whether the information is already public or can be easily matched with other data
  • Whether remedial action has made serious harm unlikely

Sometimes a business can take steps quickly enough to reduce the risk below the notification threshold. For example, if an email goes to the wrong recipient but is deleted immediately and you have reliable confirmation, the outcome may differ from a situation where a public link was available for days.

4. Decide whether notification is required

If the incident is likely to result in serious harm and meets the legal threshold, notification may be required to affected individuals and the privacy regulator. Timing and content matter.

Your notice should be accurate, practical and calm. It should usually explain:

  • What happened
  • What kind of information was involved
  • What your business has done so far
  • What affected individuals should do next
  • How they can contact your business for support

A common mistake is sending vague language that sounds defensive or minimises the issue. Another is overpromising before the investigation is complete. Keep the message factual and useful.

5. Check your contracts and insurance

Many businesses forget that privacy breaches can trigger separate notice obligations under commercial documents. Before you reply to clients or suppliers, review the paperwork.

  • Service agreements with clients
  • Supplier contracts and data processing terms
  • Confidentiality agreements
  • Managed IT or cloud provider terms
  • Cyber insurance policies and notice conditions
  • Employment agreements and internal policies

Some contracts require prompt notice of security incidents. Insurance policies may also require timely notification and cooperation. Late notice can create avoidable disputes.

6. Manage internal communications carefully

Your team needs enough information to respond, but not every employee should have unrestricted details about the incident. Nominate who is authorised to investigate, communicate externally and approve key decisions.

Tell staff what to do if customers ask questions. Give them a short approved script and a clear escalation point. This reduces inconsistent messaging and off-the-cuff admissions.

7. Fix the underlying cause

A privacy breach is rarely just bad luck. There is usually a process gap, training gap, contractual gap or technical weakness underneath it.

After the immediate response, review what needs to change. That may include:

  • Updating your privacy policy and collection notices
  • Improving internal access controls
  • Refreshing onboarding and offboarding procedures
  • Adding confidentiality, security and data handling clauses to contracts
  • Training staff on phishing, email handling and secure storage
  • Setting retention and deletion rules for personal information
  • Reviewing vendor due diligence before you sign a contract

If your business sells online or uses third party apps heavily, this is also a good time to review your website terms, platform setup and customer communications so they match what your business actually does with data.

8. Document every decision

Good records help if customers complain, a regulator asks questions, or a client wants an explanation later. They also make future incidents easier to manage.

Your incident file should cover:

  • The timeline of events
  • The evidence reviewed
  • The people involved in decisions
  • Your serious harm assessment
  • Why you did or did not notify
  • The remediation steps taken
  • The follow up actions assigned

Founders often handle the first part of a breach well, then fail to document the reasoning. That creates problems months later when memories fade.

Common mistakes that make things worse

Some errors repeat across businesses of every size. These are the ones worth watching for.

  • Treating the breach as only an IT problem
  • Assuming a small business is automatically exempt from all privacy obligations
  • Not checking whether the exposed information includes sensitive data
  • Ignoring contractual notice requirements
  • Sending a rushed email to customers before the facts are clear
  • Failing to preserve logs, screenshots and other evidence
  • Not reviewing whether the privacy policy matches actual data handling
  • Leaving old user access in place after staff or contractors leave

The main risk is not just the original incident. It is the combination of weak process, poor communication and missing records after the incident.

FAQs

Does every privacy breach need to be reported in Australia?

No. Not every incident triggers mandatory notification. The key issue is whether the relevant privacy law applies and whether the breach is likely to result in serious harm. You still need to assess and document the incident properly.

What counts as personal information?

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It can include obvious details like names and emails, as well as less obvious information that can identify someone when combined with other data.

Can an accidental email to the wrong person be a privacy breach?

Yes. An accidental disclosure can absolutely be a privacy breach. The seriousness depends on what was sent, who received it, whether it was opened, and whether the risk was contained quickly.

What should a small business do first after breached privacy is discovered?

Contain the incident, preserve evidence, identify the information involved, and assess whether serious harm is likely. Then check your contracts, internal policies and any insurance notice requirements before sending external communications.

Should we update our documents after a breach?

Usually, yes. Many businesses need to review their privacy policy, collection notices, staff procedures, supplier contracts, confidentiality clauses and incident response processes after a breach.

Key Takeaways

  • Breached privacy can include cyber incidents, accidental disclosures, lost devices, poor access controls and mishandled paper records
  • Your first steps should be to contain the issue, preserve evidence and identify exactly what personal information was affected
  • Australian businesses may need to assess whether serious harm is likely and whether notification obligations apply
  • Contracts, insurance terms, staff procedures and supplier arrangements can all affect your response
  • Clear documentation and careful communication are essential, especially before you notify customers or commercial partners
  • After the immediate incident, review your policies, contracts, access controls and training so the same problem is less likely to happen again

If your business is dealing with breached privacy and wants help with privacy compliance, breach notification, supplier and customer contracts, and policy updates, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.