Security
What a data breach obligation looks like in Australia
Data breach notification obligations in Australia for a website — the shape of the Notifiable Data Breaches scheme, and why specifics depend on the facts.
Australia has a Notifiable Data Breaches scheme, under the Privacy Act, requiring entities it applies to notify affected individuals and the regulator of an eligible data breach in specified circumstances. This page describes the general shape of that scheme so a business knows what to ask about after a compromise. It is not legal advice. It does not determine whether the scheme applies to a particular business, and it does not describe what a specific business must do in a specific incident. Those are questions for a lawyer, informed by the actual facts.
Why “does this apply to me” under the Privacy Act is not answered generally
Whether an entity is covered by the scheme depends on whether the Privacy Act applies to it at all, which in turn depends on factors including turnover and the nature of the entity — the same small-business exemption question touched on elsewhere on this site, and one whose future status is genuinely uncertain rather than settled. A business should not assume either that it is covered or that it is exempt without checking its actual position.
The general shape of an “eligible data breach” under the Notifiable Data Breaches scheme, in broad terms
The scheme is generally engaged where personal information is accessed without authorisation, disclosed without authorisation, or lost in circumstances where unauthorised access or disclosure is likely to follow, and a reasonable person would conclude that this is likely to result in serious harm to the individuals concerned. The third limb — loss — is independent of the first two and is easy to read past: a stolen laptop or a misplaced file, where nobody has actually accessed anything yet, can still trigger the scheme, because the risk of future unauthorised access or disclosure is what the loss limb is testing for, not whether access has already happened. Each of the terms in that sentence — unauthorised, serious harm, reasonable person — carries specific legal meaning that determines the outcome in any actual case, and this page does not attempt to resolve any of them for a specific situation.
What the Act says “serious harm” actually weighs
Section 26WG sets out the matters relevant to assessing whether unauthorised access, disclosure or loss is likely to result in serious harm, and this list is fixed by the Act rather than a judgement this page is making: the kind and sensitivity of the information, whether it was protected by security measures such as encryption and how easily those measures could be overcome, who has obtained or could obtain the information, and the nature of the harm that could result. These are the factors any assessment is required to weigh — which specific conclusion they produce for a specific incident is exactly the kind of outcome-dependent judgement this page leaves to a lawyer.
Timing for breach notification, stated plainly where the law is specific
Two of the timing questions here have a single, fixed answer that applies identically to every entity. Stating them is not a judgement call about any individual reader’s circumstances. Once an entity becomes aware it may have experienced an eligible data breach, it generally has a maximum of 30 days to carry out a reasonable assessment of whether the breach is in fact eligible — a statutory cap under section 26WH, not a target or a guideline. Once a breach is assessed as eligible, the Act’s own standard for notifying affected individuals and the regulator is “as soon as practicable” — that phrase is the specific legal test itself, not a placeholder for a number this page is withholding. Neither of these figures depends on the size of the business, the nature of the breach, or any other fact specific to a reader, which is exactly why they are stated here rather than left out.
What a business can reasonably do in general, pending specific advice
Keep a record of what happened, when it was discovered, and what data was potentially affected. This factual record is useful regardless of which specific legal obligations ultimately apply. Engage a lawyer or a qualified privacy adviser promptly once a suspected breach is identified, rather than attempting to self-assess the notification obligation from general information. Address the technical cause of the breach in parallel, covered from the security side in why small-business websites get compromised.
What this page deliberately does not do
Apply the “serious harm” test, the reasonable-person standard, or the assessment and notification timeframes stated above to any particular business’s actual facts, and it does not state the specific penalty regime — those require current legislation and qualified advice informed by what actually happened, not a general web page. The distinction this page draws throughout is between facts that are fixed by the Act regardless of who is reading, which are stated plainly, and judgements that depend on a specific reader’s own circumstances, which are not resolved here.
Who the turnover exemption does not reach, regardless of entity size
The small-business exemption discussed above never applies to a defined set of entities, whatever their turnover: health service providers, of any size, providing a health service and holding health information otherwise than as an employee record; businesses that trade in personal information for a benefit or consideration; credit reporting bodies; recipients of tax file number information; and providers of services under a Commonwealth contract. A business in any of these categories is bound by the Privacy Act, and by the Notifiable Data Breaches scheme described above, irrespective of how small it is. This list is fixed by the Act itself and does not vary by reader, which is why it is stated directly rather than left as a general caution.
Where to go from here: OAIC guidance, entities and obligations
The current OAIC guidance and a qualified privacy or data-breach lawyer are the appropriate sources for anything specific to an actual incident. Several of the industries this site covers carry their own additional obligations on top of the general scheme described here, set out on industries.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- data breach notification obligations australia website
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 3 August 2026
- Search results inspected for intent
- No
Source: research/outer-volume-au.json · DataForSEO Google Ads search_volume and Labs bulk_keyword_difficulty, location_code 2036 (Australia), language en · pulled 3 August 2026.
Provenance
Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-04. Reviewed by legal-compliance on 2026-08-04.
Sources
- Outer-cluster demand measurement (this site) —
research/outer-volume-au.json - Privacy Act 1988 (Cth), including the Notifiable Data Breaches scheme (Part IIIC) and the small-business exemption (accessed 2026-08-03)