Australia · Office of the Australian Information Commissioner (OAIC) · OAIC NDB

Notifiable Data Breaches Scheme

Mandatory notification of eligible data breaches likely to result in serious harm to any affected individual.

What it is

The NDB scheme sits inside the Privacy Act 1988 and applies to all APP entities. When an entity has reasonable grounds to believe there has been an eligible data breach - unauthorised access, disclosure or loss of personal information likely to result in serious harm - it must promptly notify the individuals at risk and the OAIC. Where the entity is only suspicious, it has 30 days to assess whether the breach is notifiable. Practical cybersecurity programs tie detection, containment and decision-making inside this 30-day window.

Who it applies to

Any entity covered by the Privacy Act 1988, including APP entities, credit reporting bodies, credit providers, TFN recipients and health service providers.

Requirements

Preventative controls

Reasonable security under APP 11 to prevent eligible data breaches in the first place.

Assessment within 30 days

Assessment of whether a suspected breach is likely to result in serious harm.

Remedial action

Steps taken to contain the breach and mitigate harm before notification may not be required.

Notification

Prompt notification to affected individuals and a statement to the OAIC describing the breach, information involved, and steps being taken.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.