If personal information held by your business is lost, or accessed or disclosed without authorisation, you may have obligations under Australian privacy law. This article explains the scheme in plain terms so that you know what you are dealing with.
This is general information, not legal advice. Whether a particular incident triggers an obligation depends on the facts and on your circumstances, and it is a legal question. If you suspect a breach, involve a lawyer as well as us, early rather than late.
The Notifiable Data Breaches scheme sits within the Privacy Act. It requires organisations covered by the Act to respond to a data breach involving personal information, and in some cases to notify both the affected individuals and the regulator.
The regulator is the Office of the Australian Information Commissioner, usually shortened to the OAIC. It publishes guidance for businesses at oaic.gov.au, and that guidance is the authoritative source rather than anything you will read here.
Not every Australian business is covered by the Privacy Act. Coverage depends on things like your turnover and the kind of information you handle, and some small businesses are covered because of the sector they operate in or the contracts they hold, even where they would otherwise be exempt. Working out whether you are covered is one of the first questions for your lawyer, and it is worth answering before an incident rather than during one.
The threshold is an eligible data breach. In broad terms, that is where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that this is likely to result in serious harm to any of the individuals the information relates to.
Two parts matter there. Personal information means information about an identified individual, or one who is reasonably identifiable, which covers far more than names and addresses. And serious harm is broader than financial loss. It can include identity theft, physical or psychological harm, damage to reputation, or serious embarrassment, depending on the sensitivity of what was exposed.
An important qualification: if you take action quickly enough that the breach is unlikely to result in serious harm, it may not be an eligible breach at all. This is one of several reasons speed matters.
Where you suspect an eligible data breach may have occurred, the scheme requires you to assess the situation promptly and, if it is an eligible data breach, to notify the affected individuals and the OAIC without undue delay.
We are deliberately not stating specific time limits here as though they were fixed legal facts, because the requirements are expressed in the legislation and the OAIC's guidance and you should take them from there or from your lawyer. What is safe to say is that the scheme is built around acting promptly, and that a delay you cannot justify is itself a problem.
Our part is the facts, not the legal conclusion. We can establish what systems were involved, what data was accessible, whether it was actually accessed, over what period, and whose information is likely to be affected. We can produce that as a written account your lawyer and, if needed, the OAIC can work from, and we can secure the environment so the exposure stops.
What we will not do is tell you whether the incident is an eligible data breach, or whether and when to notify. Those are decisions for you with legal advice.
Two things make a real difference. Know whether the Privacy Act applies to you, and know who you would ring. A single page listing your lawyer, your insurer, your policy number and our number, kept somewhere you can reach without a computer, removes an hour of confusion from the worst morning of your business year.
Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.
Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.