Worth being upfront about what this is: a practical explainer, not legal advice. If you're actually in the middle of assessing whether something you're looking at is a reportable breach, get advice specific to your situation rather than working from a blog post — the stakes and the details matter too much to wing it. What follows is the working knowledge that should tell you whether you need to be worried at all, and what "worried" actually looks like in practice.
What the NDB scheme actually is
The Notifiable Data Breaches (NDB) scheme is Part IIIC of the Privacy Act 1988, administered by the Office of the Australian Information Commissioner (OAIC). It's been in force since February 2018, and the short version is this: if an organisation covered by the Australian Privacy Principles suffers a data breach likely to cause serious harm, it has to tell both the OAIC and the people affected.
The short version: if your business is covered by the Privacy Act, and you have a data breach likely to cause serious harm to someone, you have to assess it within 30 days of suspecting it and notify the regulator and the affected people once you've confirmed it. Whether your business is covered at all is the first question, and it isn't always obvious.
Does it actually apply to your business
This is where most small businesses either relax too early or worry for nothing. The Privacy Act generally applies to businesses with annual turnover over $3 million. If that's not you, the default assumption is that you're not covered — but there's a list of exceptions that apply regardless of turnover, and they catch more small businesses than people expect:
- Health service providers — this is a broad category, and covers more than clinics. A business that holds health information as part of what it does can fall into this bucket even if healthcare isn't its main line of work.
- Businesses that trade in personal information — buying or selling personal information as part of your business, not just holding it.
- TFN recipients — any business that collects Tax File Numbers, which in practice means most employers.
- Credit providers and credit reporting bodies — a wider net than "banks and lenders" once you include businesses offering payment plans or buy-now-pay-later style arrangements.
- Contracted service providers under a Commonwealth contract, and a handful of other specific categories set out in the Act.
Don't assume you're exempt just because you're small. "We're only a small business" is true and irrelevant if one of the exceptions applies to you. The turnover test is the headline rule, but it's not the whole rule — check the exceptions against what your business actually does, not just its revenue.
If you genuinely don't fall under the Privacy Act at all, the NDB scheme's mandatory obligations don't apply to you. That's a real category of small business, and it's worth knowing which one you're in before an incident forces you to work it out under pressure.
What counts as an "eligible data breach"
Not every security incident is a notifiable one. The scheme is specifically about an eligible data breach, which has a defined meaning:
- Unauthorised access to, or unauthorised disclosure of, personal information held by your business — or personal information is lost in circumstances where unauthorised access or disclosure is likely to occur; and
- A reasonable person would conclude that this is likely to result in serious harm to any of the individuals the information relates to; and
- The business hasn't been able to prevent that likely risk of serious harm with remedial action taken before it eventuated.
"Serious harm" isn't limited to financial loss — it can include serious harm to reputation, or physical, psychological, or emotional harm, depending on the nature of the information involved. A spreadsheet of names and email addresses sent to the wrong person is a different risk profile to a spreadsheet of names, dates of birth, and government identifiers sent to the wrong person, even though both are technically "a disclosure."
The reassuring part: most everyday slip-ups don't clear this bar. A laptop that goes missing but was properly encrypted, or a misdirected email that gets caught and recalled before anyone reads it, generally won't meet the "likely to result in serious harm" threshold. The scheme is aimed at breaches with real consequences for real people, not every mistake that happens in a normal working week.
The 30-day assessment clock
This is the part that catches people out, because the trigger is earlier than most people expect. The clock doesn't start when you've confirmed a breach happened — it starts when you have reasonable grounds to suspect one might have. From that point, you must carry out a reasonable and expeditious assessment, and take all reasonable steps to ensure that assessment is completed within 30 days.
| Stage | What triggers it | What you do |
|---|---|---|
| Suspicion | Reasonable grounds to suspect an eligible data breach may have occurred | Start a reasonable and expeditious assessment — the 30-day clock is now running |
| Assessment | Ongoing, within the 30-day window | Gather facts: what happened, what information was involved, who's affected, how serious the likely harm is |
| Confirmation | You conclude there are reasonable grounds to believe an eligible data breach occurred | Notify the OAIC and affected individuals as soon as practicable |
The clock starts on suspicion, not certainty. Waiting until you're completely sure before you start assessing is a common and costly mistake — it eats into your 30 days before you've even started the process the scheme requires. Start the assessment as soon as something looks wrong, and treat "we're not sure yet" as a reason to assess faster, not a reason to wait.
What notification actually looks like
Once you've concluded there are reasonable grounds to believe an eligible data breach has occurred, two things need to happen as soon as practicable:
- Notify the OAIC, using their Notifiable Data Breach statement form, describing the breach, the information involved, and the steps you've taken or plan to take.
- Notify the individuals at risk — either everyone affected, or just those at risk of serious harm, depending on what's practicable. If direct notification genuinely isn't practicable, you publish a statement about the breach and take reasonable steps to publicise it instead.
The notification itself needs to cover the identity and contact details of your business, a description of the breach, the kinds of information involved, and recommendations about what affected individuals should do in response — changing a password, watching for suspicious activity on an account, that sort of thing.
Practical steps for a business without a dedicated security team
Most small businesses don't have an in-house security team, and the scheme doesn't assume you do. What it does assume is that you can act reasonably and promptly once something happens — which is a much lower bar, and one you can meet with preparation rather than headcount.
- Know where your personal information actually lives — which systems hold customer data, staff records, or anything with names attached to identifying details. You can't assess a suspected breach quickly if the first step is figuring out what was even at risk.
- Have a who-to-call list before you need it. Your hosting or IT provider, a lawyer if the situation warrants one, and your insurer if you carry cyber insurance. Deciding who to ring during an actual incident wastes hours you don't have in the assessment window.
- Don't wait for certainty before you start assessing. A suspicion is enough to start the clock and enough to start the process — treat "we think something might have happened" as the trigger, not "we've confirmed exactly what happened."
- Document your assessment even when you conclude notification isn't required. If you decide an incident doesn't meet the eligible data breach threshold, write down why. That record is what shows you took the obligation seriously if the question ever comes up later.
- Remember third-party breaches count too. If a payroll processor, a booking platform, or any other vendor holding your customers' or staff's personal information has a breach, that can be your notification obligation as much as theirs, depending on the arrangement. Know which of your vendors hold what.
None of this requires a security operations centre. It requires knowing, in advance, what data you hold, who to call, and that the clock starts earlier than feels intuitive. Businesses that get caught out badly by the NDB scheme are usually the ones improvising all three of those for the first time during an actual incident.
Not sure whether the NDB scheme applies to your business, or want a second opinion on an incident? Get in touch — we can talk through where your systems and data actually sit, which is usually the first thing worth getting straight.
Get in touch →Frequently asked questions
Does the Notifiable Data Breaches scheme apply to small businesses?
Only if your business is covered by the Australian Privacy Principles. Most businesses under $3 million turnover are exempt, but exceptions apply regardless of size — health service providers, businesses that trade in personal information, TFN recipients, and credit providers or credit reporting bodies are covered no matter how small they are.
What counts as an eligible data breach under the NDB scheme?
Unauthorised access, unauthorised disclosure, or loss of personal information that a reasonable person would conclude is likely to result in serious harm — and the business hasn't been able to prevent that risk with remedial action. Not every incident meets this bar.
How long do I have to assess a suspected data breach?
Once you have reasonable grounds to suspect an eligible data breach may have occurred, you must complete a reasonable and expeditious assessment within 30 days. The clock starts on suspicion, not confirmation.
Who do I have to notify if I have an eligible data breach?
The OAIC and the individuals at risk of serious harm, as soon as practicable after you conclude an eligible data breach occurred. If direct notification isn't practicable, you publish and publicise a statement instead.
