A breach is bad enough on its own. What catches a lot of business owners off guard is that, depending on what happened, the law may also require you to tell a federal regulator and the people whose data was exposed - within a set timeframe, in a specific way. This is the Notifiable Data Breaches (NDB) scheme, and it applies to far more small businesses than most realise.
What the NDB Scheme Actually Is
The Notifiable Data Breaches scheme sits within Australia's Privacy Act. It requires organisations covered by the Act to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when a data breach is likely to result in serious harm - and to do so as soon as practicable once the business becomes aware of it.
Does It Apply to Your Business?
The Privacy Act generally applies to businesses with an annual turnover over $3 million, but there are important exceptions that catch many smaller Perth businesses regardless of revenue, including:
- Health service providers, including allied health, dental, and medical practices
- Businesses that trade in personal information
- Credit reporting bodies and businesses providing credit
- Businesses contracted to provide services to the Australian Government
- Some childcare and family service providers
If you're not sure whether your business is covered, it's worth checking - many small businesses assume the turnover threshold exempts them, without realising one of these exceptions applies.
What Counts as an "Eligible Data Breach"
Not every security incident triggers a reporting obligation. The scheme applies specifically to an "eligible data breach" - broadly, where there's unauthorised access to, or disclosure of, personal information, and a reasonable person would conclude this is likely to result in serious harm to the individuals concerned. A lost laptop with unencrypted client records, a compromised email account containing personal data, or a ransomware incident affecting customer information are common examples that can meet this bar.
What You're Required to Do
- Contain and assess - once you suspect a breach, you have an obligation to carry out a reasonable and expeditious assessment of whether it's likely to cause serious harm.
- Notify the OAIC - if it's assessed as an eligible data breach, you must notify the OAIC using their Notifiable Data Breach form.
- Notify affected individuals - you must also notify the individuals at risk of serious harm, or publish a statement if direct notification isn't practicable.
- Act as soon as practicable - there's no fixed number of days in the legislation, but delay is treated unfavourably; the expectation is prompt action once you're aware.
What Happens If You Don't Comply
Failing to notify when required can result in regulatory action from the OAIC, financial penalties, and - often more damaging in practice - the reputational fallout of a breach becoming public well after the fact, looking like it was covered up rather than disclosed.
How to Prepare Before You Need This
The businesses that handle this well aren't the ones that have never had an incident - they're the ones who knew exactly what to do the moment one happened. That means knowing in advance whether your business is covered, having a documented incident response plan that includes the assessment and notification steps, and understanding what "personal information" you actually hold and where it lives.
Frequently Asked Questions
What is the Notifiable Data Breaches scheme?
The Notifiable Data Breaches (NDB) scheme sits within Australia's Privacy Act. It requires organisations covered by the Act to notify the OAIC and affected individuals when a data breach is likely to result in serious harm, as soon as practicable once the business becomes aware of it.
Does the NDB scheme apply to small businesses?
The Privacy Act generally applies to businesses with annual turnover over $3 million, but exceptions catch many smaller businesses regardless of revenue - including health service providers, businesses that trade in personal information, credit providers, government contractors, and some childcare and family service providers.
What counts as an eligible data breach?
Broadly, where there's unauthorised access to or disclosure of personal information, and a reasonable person would conclude this is likely to result in serious harm to the individuals concerned. A lost laptop with unencrypted client records or a ransomware incident affecting customer information are common examples.
What happens if a business doesn't comply?
Failing to notify when required can result in regulatory action from the OAIC, financial penalties, and reputational fallout if the breach becomes public later, looking like it was covered up rather than disclosed.
We help Perth businesses understand their data breach obligations and build an incident response plan that holds up if the NDB scheme applies to you.
Cybersecurity Services →Not sure if the NDB scheme applies to your business?
Call 0433 087 091 for a free, no-obligation conversation about your obligations and how prepared you currently are.
Book a Free ConsultationThis article is general information, not legal advice. For guidance specific to your business, consult a qualified privacy lawyer or refer to the OAIC's official guidance.