
Data breach obligations for small business in Australia depend first on whether the Privacy Act 1988 covers your business. Most businesses with an annual turnover of $3 million or less are not covered, but several kinds are, whatever their size. If you are covered and a breach of personal information is likely to cause serious harm, the Notifiable Data Breaches scheme requires you to notify the affected people and the Office of the Australian Information Commissioner (OAIC). This guide sets out those rules as the OAIC states them, and how to prepare. It is general information, not legal advice.
Who the Privacy Act covers
The Privacy Act applies to Australian Government agencies and to organisations with an annual turnover of more than $3 million. The OAIC's small business guidance says that most small businesses are not covered by the Act, but some are, and defines a small business as one with an annual turnover of $3 million or less.
Small businesses that are covered regardless of turnover
According to the OAIC, the Privacy Act covers any business, regardless of turnover, that is:
- a health service provider
- trading in personal information
- a contractor that provides services under a Commonwealth contract
- an operator of a residential tenancy database
- a credit reporting body
- a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006
- an employee association registered or recognised under the Fair Work (Registered Organisations) Act 2009
- a business that conducts protected action ballots
- accredited under the Consumer Data Right system
- related to a business the Privacy Act covers
- prescribed by the Privacy Regulation 2013
- a business that has opted in to be covered
"Health service provider" is wider than many owners assume. The OAIC's checklist describes it as a business providing services in relation to physical, emotional, psychological and mental health, and names medical practitioners, pharmacists and allied health professionals among the examples, so a small clinic or pharmacy should check its position with care.
Tax file numbers
One more point reaches most employers. The OAIC's guidance says the Notifiable Data Breaches scheme applies to tax file number (TFN) recipients in relation to their handling of TFN information, and that a TFN recipient is any person who is in possession or control of a record that contains TFN information. A small business that keeps its employees' TFNs should not assume it sits wholly outside the scheme. Ask your adviser how this applies to you.
The Notifiable Data Breaches scheme
The Notifiable Data Breaches (NDB) scheme is the part of the Privacy Act that requires covered entities to tell individuals and the Commissioner about data breaches that are likely to cause serious harm. The detail in this section comes from Part 4 of the OAIC's data breach preparation and response guide.
What an eligible data breach is
An eligible data breach occurs when three things are true:
- there is unauthorised access to, or unauthorised disclosure of, personal information that an entity holds, or the information is lost
- this is likely to result in serious harm to one or more individuals
- the entity has not been able to prevent the likely risk of serious harm with remedial action
The OAIC explains that "likely" means the risk of serious harm is more probable than not, and that serious harm is not defined in the Act but may include serious physical, psychological, emotional, financial or reputational harm.
If you act quickly, for example by remotely wiping a lost laptop before anyone can open it, and that action means serious harm is no longer likely, the incident is not an eligible data breach.
Assessment timing
If you suspect an eligible data breach but are not sure, you must carry out a reasonable and expeditious assessment. The OAIC states that an entity must take all reasonable steps to complete the assessment within 30 calendar days after the day it became aware of the grounds for its suspicion. The Commissioner expects entities to treat 30 days as a maximum and to aim for a much shorter timeframe, because the risk of harm often grows with time.
Notification timing and content
Once there are reasonable grounds to believe an eligible data breach has happened, the entity must, as soon as practicable, prepare a statement for the Commissioner and notify individuals of its contents. The statement must include:
- the identity and contact details of the entity
- a description of the eligible data breach
- the kind or kinds of information involved
- the steps the entity recommends individuals take in response
Depending on what is practicable, you can notify everyone whose information was involved, notify only those at risk of serious harm, or, if neither is practicable, publish the statement on your website and take reasonable steps to publicise it.
These rules are changing. The OAIC notes that it is updating its guide to reflect the Privacy and Other Legislation Amendment Act 2024. Separately, on 31 August 2026 the Attorney-General's Department opened consultation on exposure draft privacy legislation. Its consultation paper proposes that an entity give the Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred, while the 30-day assessment step would remain. The department says the Bill remains subject to further consideration by government, so this is a proposal and not the law. Check the current OAIC pages, or ask a lawyer, before relying on any summary.
If the scheme does not apply to you
Being outside the Privacy Act does not make a breach harmless. Customers still expect to be told when their details have been exposed, and contracts with larger clients often contain their own security and notification clauses. A small business can also opt in to the Privacy Act, which the OAIC says could bring benefits including increased consumer confidence and trust.
The four steps of a response
The OAIC's guide describes four key steps for responding to a data breach:
| Step | What the OAIC says | What it looks like in a small business |
|---|---|---|
| 1. Contain | Contain the breach to prevent any further compromise of personal information | Reset passwords, disable the affected account, recall the email, isolate the device |
| 2. Assess | Gather the facts and evaluate the risks, including potential harm, and remediate where possible | Work out what information, whose, how it was exposed and who could have seen it |
| 3. Notify | Notify individuals and the Commissioner if required | Send clear notices with practical advice; lodge the statement with the OAIC |
| 4. Review | Review the incident and consider what can be done to prevent future breaches | Fix the cause, update the plan, brief staff |
The OAIC says the first three steps should be undertaken either simultaneously or in quick succession.
Practical preparation: a response plan checklist
The OAIC describes a data breach response plan as a framework that sets out the roles and responsibilities involved in managing a data breach, and the steps an entity will take if one occurs. Part 2 of the same guide includes a checklist of what a plan should contain. Adapted for a small business, your plan should set out:
- what a data breach is and how staff can identify one
- who a staff member tells first, and how a suspected breach is escalated
- who is on the response team, with a backup person for each role
- which outside experts you would call, such as your IT provider, a lawyer and your insurer
- how you will assess a suspected breach and who decides whether it is notifiable
- how and when individuals will be notified, and who writes the notice
- when the OAIC, the police or others need to be contacted
- how every incident is recorded, including minor ones
- how the plan is tested and reviewed
Keep a printed copy away from the systems that might be affected, and rehearse it with the team.
Prevention sits beside the plan: know what personal information you hold, delete what you no longer need and limit who can see it. Comingwave is an Australian technology company that helps small and medium businesses with cyber security, IT consulting and managed IT support. To discuss the technical side of your preparation, contact us for a quote.
Key takeaways
- Most businesses with turnover of $3 million or less are not covered by the Privacy Act, but health service providers, businesses trading in personal information and several other kinds are.
- An eligible data breach is one likely to cause serious harm that remedial action has not prevented.
- Assess a suspected breach within 30 calendar days, sooner where possible, and notify as soon as practicable.
- Write and rehearse a response plan now, whether or not the scheme applies to you.
Frequently asked questions
Does the Privacy Act apply to my small business?
Possibly. The OAIC says most small businesses, meaning those with an annual turnover of $3 million or less, are not covered, but some are regardless of turnover, including health service providers and businesses that trade in personal information.
What is an eligible data breach?
A breach in which personal information is accessed or disclosed without authorisation, or lost, that is likely to result in serious harm to one or more individuals and that remedial action has not prevented.
How long do we have to report a data breach?
If you only suspect an eligible data breach, the OAIC says you must take all reasonable steps to complete an assessment within 30 calendar days. Once you have reasonable grounds to believe one has occurred, you must notify the Commissioner and the individuals at risk as soon as practicable. A 72-hour deadline for telling the Commissioner has been proposed but is not law.
What should a data breach response plan include?
Following the OAIC's guidance, it should explain what a breach is, set out escalation steps and the response team, describe how breaches are assessed and notified, require records to be kept, and provide for regular testing and review.