A breach starts a legal process, not just a technical one
When personal information leaks, most teams instinctively treat it as an engineering problem: find the hole, close it, move on. Under Australian law it is also the start of a defined process with obligations and timing. The Notifiable Data Breaches scheme, in Part IIIC of the Privacy Act 1988, requires organisations covered by the Act to assess suspected breaches and, where the test is met, to notify both the regulator and the people affected. Handling the technical side well but ignoring the legal side is how a contained incident becomes a regulatory one.
The scheme applies to the entities the Privacy Act covers, which includes most Australian businesses over the small business turnover threshold and, regardless of size, those handling certain categories such as health service providers. If you are unsure whether the Act binds you, that is itself worth resolving before an incident, not during one.
What counts as an eligible data breach
Not every exposure triggers notification. The scheme turns on a specific test: there must be unauthorised access to, unauthorised disclosure of, or loss of personal information, and that must be likely to result in serious harm to one or more of the individuals it relates to. Serious harm is assessed on the facts: the sensitivity of the information, whether it was protected by encryption or other measures, the kinds of people who could have accessed it, and the nature of the harm that could follow, from identity theft to physical safety.
There is an important relief valve. If you take remedial action quickly enough that serious harm is no longer likely, the breach may not be notifiable at all. A laptop lost and then remotely wiped, or exposed data that was strongly encrypted with the keys uncompromised, can fall on the right side of that line. This is one of the concrete reasons encryption and rapid response pay for themselves: they can turn a notifiable breach into a non event.
The assessment obligation and its clock
When you have reasonable grounds to suspect an eligible breach but are not yet sure, you must carry out a reasonable and expeditious assessment. The Act frames this as an expectation to complete that assessment within thirty days of becoming aware of the grounds for suspicion, and to take all reasonable steps to do so. Thirty days is an outer bound, not a target: the regulator expects you to move faster where you can.
The practical trap is that the clock starts at awareness, and awareness often predates anyone realising the legal process has begun. The help desk ticket, the odd export in the logs, the staff member who mentions a misdirected email: these are the moments the obligation attaches. An organisation that has decided in advance who runs the assessment, and what evidence they gather, moves through this cleanly. One that improvises loses days it does not have.
In practice the assessment is a small, disciplined investigation. You establish what information was involved and whose, how it was exposed and for how long, who could plausibly have accessed it, and whether any protection such as encryption reduces the likelihood of harm. Documenting that reasoning as you go matters as much as the conclusion, because if the regulator later asks why you decided a breach was not notifiable, the contemporaneous record of a genuine, reasonable assessment is your answer. A decision reached carefully and written down at the time is defensible in a way that a verbal judgement recalled months later is not.
Who you must tell, and what you must say
If the assessment concludes the breach is eligible, two notifications follow. You prepare a statement for the Office of the Australian Information Commissioner, and you notify the affected individuals as soon as practicable. The statement covers the entity involved, a description of the breach, the kinds of information concerned, and the steps you recommend individuals take in response.
The recommendation to individuals is not a formality, it is the point. Telling someone that their identity document details were exposed, and precisely what they should do about it, is what lets them protect themselves. Where notifying every individual is not practicable, the scheme allows publishing the statement and taking reasonable steps to publicise it. The tone that survives scrutiny later is plain, specific, and free of minimising language.
Preparation is the whole difference
The organisations that come through a breach with their reputation intact are almost never the ones that avoided a breach. They are the ones that had decided what to do before it happened. A data breach response plan that names the decision makers, sets out how the assessment runs, holds template notifications, and has been rehearsed once against a realistic scenario turns a chaotic fortnight into a controlled process.
Two upstream disciplines quietly make the day easier. Knowing what personal information you hold and where, so the scope question can be answered in hours rather than days, and collecting less of it in the first place, so there is less to expose. Both reduce the size of the problem before it ever occurs, which is always cheaper than managing it afterwards.
The general information caveat
This note explains the shape of the obligations so a business can prepare sensibly. It is general information, not legal advice, and the application of the Privacy Act to a specific breach can turn on details that matter. When an actual incident hits, the assessment and notification decisions should be made with current regulator guidance and, where the stakes warrant it, legal input. The goal of preparing in advance is simply to make sure those decisions are made calmly, by people who already know it is their job.
