If your business is covered by the Privacy Act and a data breach is likely to cause serious harm, you must assess it quickly, notify the affected individuals and notify the Office of the Australian Information Commissioner. The notifiable data breaches scheme sets that obligation. It applies to organisations bound by the Privacy Act, generally those above the annual turnover threshold the OAIC states, plus categories such as health service providers regardless of size. Check your status on the OAIC website.
Which businesses the scheme covers
The obligation follows the Privacy Act. Australian Government agencies and organisations bound by the Act have to comply, and the OAIC explains that most small businesses fall outside it unless they meet the annual turnover threshold it publishes or fall into one of the listed categories. Those categories catch far more small operators than owners expect, including private health service providers, businesses that trade in personal information, credit reporting bodies, tax file number recipients and some contractors delivering services under a Commonwealth contract.
Two points matter here. The threshold and the list change over time, so read the current position on the OAIC site rather than relying on what someone told you in a previous business. And a business outside the Act still faces the commercial consequences of a breach: the customers, the contract terms with clients who are covered, and the cost of getting systems working again.
What counts as an eligible data breach
Three elements have to line up. There must be unauthorised access to, unauthorised disclosure of, or loss of personal information the organisation holds. That incident must be likely to result in serious harm to one or more individuals. And the organisation must not have been able to prevent that harm through remedial action.
The last element gets missed. If you act fast enough that serious harm is no longer likely, for example by recovering a device before anything was opened or forcing a password reset that closes off the access, the breach may not be notifiable. That is one reason the response in the first hours is worth planning before it is needed.
The assessment clock
Where you suspect an eligible breach but are not sure, the OAIC’s guidance on the notifiable data breaches scheme requires a reasonable and expeditious assessment, and it must be completed within 30 days of becoming aware of the grounds for suspicion. Thirty days is the outer limit, not a target. Regulators expect you to move faster where the harm is obvious.
A workable order of business looks like this:
- Contain the incident and stop further access.
- Record what happened, when you became aware, and what data is involved.
- Assess the risk of serious harm to the individuals whose information is affected.
- Notify the OAIC and the affected individuals if the test is met.
- Review what allowed it to happen and fix that.
What notification involves
Notification is a statement to the OAIC through its online form, describing the breach, the kinds of information involved, and what those affected should do to protect themselves. You also have to tell the individuals at risk, either directly or, where that is not practicable, by publishing the statement and taking reasonable steps to publicise it. The Australian Cyber Security Centre is a separate reporting channel for the cyber incident itself, and reporting there does not satisfy the privacy obligation.
Keep a record of the decision either way. If you assess a breach and conclude it is not notifiable, write down what you looked at and why you reached that view. The file note is what you produce if the OAIC asks about it later, and it is far easier to write on the day than to reconstruct from memory months afterwards.
Write the notification as if a customer will read it, because they will. Plain language about what happened, what data was involved and what to do next does more for the relationship than a legal statement that explains nothing.
Where insurance fits
A cyber policy is built around this sequence. It generally funds incident response from the first call: a specialist to work out what was accessed, IT forensics, legal advice on whether the breach is notifiable, the cost of notifying individuals, credit monitoring where offered, public relations support, and the business interruption loss while systems are down. Ransom and extortion sections are also common.
Read the response section closely. Many policies give you a hotline and a panel of specialists who take the first call, which is worth more at two in the morning than an extra million on the limit. Some insurers apply a separate sub limit to response costs, and some require you to use their panel rather than your own lawyers, so the practical detail belongs in the decision.
The second policy is management liability, which responds to claims against directors and officers personally, including regulatory investigations into how the business was run. A serious breach can produce both a privacy problem and a management problem, and they are handled by different sections.
What FRS does
We match the cyber wording to how your business actually holds data, check the incident response arrangements attached to the policy, and confirm the response limits sit separately from the main limit where the insurer offers that. We also make sure the notification numbers on the schedule reflect the size of your customer database rather than a generic figure, and we walk clients through the claim process while the incident is still running.
For cover that funds the response as well as the loss, start with our cyber insurance page.
Frequently asked questions
Does the scheme apply to my small business?
It depends on whether the Privacy Act binds you. The OAIC sets an annual turnover threshold and also lists categories that are covered regardless of size, such as private health service providers and businesses trading in personal information. Check your position on the OAIC website, and check it again if your turnover or activities change.
How quickly do I have to report a breach?
Notify as soon as practicable once you have concluded a breach is notifiable. Where you only suspect one, the notifiable data breaches scheme allows an assessment period of up to 30 days from the date you become aware of the grounds for suspicion, and the OAIC expects that assessment to be reasonable and expeditious rather than drawn out.
What if a supplier caused the breach?
You may still hold the obligation for information you are responsible for, including data held on your behalf by a payroll provider, a booking platform or an IT contractor. Check what your agreements say about notification and cost sharing, and ask suppliers whether they carry cyber cover of their own.
Will a cyber policy pay the notification costs?
Most Australian cyber wordings include the cost of legal advice, forensic investigation and notifying affected individuals, often through an incident response panel you call on the first day. Limits and sub limits vary, so read what applies to response costs specifically rather than assuming the full policy limit is available.