AUSTRALIAN NDB GUIDANCE

Contain. Assess.
Notify. Review.

A suspected breach needs a prompt, proportionate response. This overview is general information, not legal advice. Confirm your organisation’s coverage, exceptions and other obligations with a qualified adviser.

What can a data breach look like?

A misdirected email, unauthorised system access, an exposed file or a lost device can compromise personal information. Start by containing further exposure and preserving evidence.

When might notification be required?

The Australian NDB scheme generally considers whether personal information was accessed or disclosed without authorisation (or lost in circumstances where that is likely), serious harm to an individual is likely, and remedial action has not prevented that risk. Coverage and exceptions matter.

Respond promptly

Take reasonable steps to finish assessing a suspected eligible breach within 30 calendar days of awareness of the grounds for suspicion. This is an assessment period, not a waiting period for notification. Once there are reasonable grounds to believe an eligible breach occurred, notify as soon as practicable.

Keep a reasoned record

Document what happened, the information involved, possible harm, remedial action and your reviewer’s conclusion—including reasons for deciding not to notify. Reassess when new facts emerge.

Prepare a useful notification

A notification should explain who the organisation is and how to contact it, what occurred, the kinds of information involved, and practical protective steps for individuals. Review your draft before submitting it or contacting affected people.

This application does not submit notifications. Your organisation must make and carry out the final decision.

Primary sources

Guidance basis reviewed 4 September 2026. This application does not automatically monitor changes to the law. Check the current OAIC guidance when assessing an incident.

Start a free assessment ↗