Notifiable data breaches: your obligations in plain English

Notifiable data breaches: your obligations in plain English

If personal information held by your business is lost, or accessed or disclosed without authorisation, you may have obligations under Australian privacy law. This article explains the scheme in plain terms so that you know what you are dealing with.

This is general information, not legal advice. Whether a particular incident triggers an obligation depends on the facts and on your circumstances, and it is a legal question. If you suspect a breach, involve a lawyer as well as us, early rather than late.

What the scheme is

The Notifiable Data Breaches scheme sits within the Privacy Act. It requires organisations covered by the Act to respond to a data breach involving personal information, and in some cases to notify both the affected individuals and the regulator.

The regulator is the Office of the Australian Information Commissioner, usually shortened to the OAIC. It publishes guidance for businesses at oaic.gov.au, and that guidance is the authoritative source rather than anything you will read here.

Not every Australian business is covered by the Privacy Act. Coverage depends on things like your turnover and the kind of information you handle, and some small businesses are covered because of the sector they operate in or the contracts they hold, even where they would otherwise be exempt. Working out whether you are covered is one of the first questions for your lawyer, and it is worth answering before an incident rather than during one.

What makes a breach notifiable

The threshold is an eligible data breach. In broad terms, that is where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that this is likely to result in serious harm to any of the individuals the information relates to.

Two parts matter there. Personal information means information about an identified individual, or one who is reasonably identifiable, which covers far more than names and addresses. And serious harm is broader than financial loss. It can include identity theft, physical or psychological harm, damage to reputation, or serious embarrassment, depending on the sensitivity of what was exposed.

An important qualification: if you take action quickly enough that the breach is unlikely to result in serious harm, it may not be an eligible breach at all. This is one of several reasons speed matters.

What the scheme requires of you

Where you suspect an eligible data breach may have occurred, the scheme requires you to assess the situation promptly and, if it is an eligible data breach, to notify the affected individuals and the OAIC without undue delay.

We are deliberately not stating specific time limits here as though they were fixed legal facts, because the requirements are expressed in the legislation and the OAIC's guidance and you should take them from there or from your lawyer. What is safe to say is that the scheme is built around acting promptly, and that a delay you cannot justify is itself a problem.

What to do first

  1. Contain it. Stop the exposure continuing. That might mean locking an account, disabling access, or recalling something sent in error.
  2. Call us on 03 9028 4358. We will help establish the facts: what was accessed, by whom, when, and for how long.
  3. Contact your lawyer, and your insurer if you hold cyber cover. Many policies require early notification, and some provide access to a breach response team.
  4. Do not delete anything, including suspicious emails, logs, or the affected files. It is evidence and it is often the only way to establish scope.
  5. Write down what you know and when you knew it. A simple dated log. It will matter later, both for the assessment and for demonstrating that you acted promptly.
  6. Do not announce anything until you know what happened. An early message that turns out to be wrong causes real damage.

How we help

Our part is the facts, not the legal conclusion. We can establish what systems were involved, what data was accessible, whether it was actually accessed, over what period, and whose information is likely to be affected. We can produce that as a written account your lawyer and, if needed, the OAIC can work from, and we can secure the environment so the exposure stops.

What we will not do is tell you whether the incident is an eligible data breach, or whether and when to notify. Those are decisions for you with legal advice.

Worth doing before anything happens

Two things make a real difference. Know whether the Privacy Act applies to you, and know who you would ring. A single page listing your lawyer, your insurer, your policy number and our number, kept somewhere you can reach without a computer, removes an hour of confusion from the worst morning of your business year.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • The Essential Eight in plain English

      Someone has asked whether you follow the Essential Eight, probably in a tender document, an insurance form or a client questionnaire. Here is what it is, without the jargon. The Essential Eight is a list of eight practical controls published by the ...
    • You have been sent a security questionnaire: what to do

      A client, a prospective client, an insurer or a head contractor has sent you a spreadsheet or an online form with anywhere from twenty to three hundred security questions, and a due date that is sooner than you would like. It arrives with no warning ...
    • Evidence we can provide for a tender or a client audit

      Winning larger work increasingly means proving things rather than asserting them. A tender asks for evidence of your security arrangements, a big client's procurement team wants documentation before they will onboard you, or an auditor asks to see ...
    • Cyber insurance questions we can answer for you

      Cyber insurance applications and renewals used to be a page. Now they ask specific technical questions, and getting one wrong can mean a higher premium, a condition on the policy, or an argument at exactly the wrong moment. Most of these questions ...