Australia now has mandatory data breach notification legislation
Summary
This blog post, "Australia now has mandatory data breach notification legislation", is a blueAPACHE article from 2017 covering security. The recent passing of mandatory data breach notification laws through the senate imposes on organisations a need for increased transparency and accountability. It is written for readers evaluating emPOWER Security, Governance, Risk and Compliance. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2017 |
| Topic | Australia now has mandatory data breach notification legislation |
| Services referenced | emPOWER Security, Governance, Risk and Compliance |
| Named products or vendors | None named beyond blueAPACHE |
| Cited statistic | Australian government agencies, businesses and not-for-profit organisations with an annual turnover of more than $3 million will soon be legally obliged to disclose eligible data breaches. |
Article
The recent passing of mandatory data breach notification laws through the senate imposes on organisations a need for increased transparency and accountability. Australian government agencies, businesses and not-for-profit organisations with an annual turnover of more than $3 million will soon be legally obliged to disclose eligible data breaches. The Privacy Amendment (Notifiable Data Breaches) Bill 2016 has been passed by both houses of parliament and will come into effect within the next 12 months. Unlike many other countries, Australia does not currently have a mandatory data breach notification law. Organisations could voluntarily undertake notification of data breaches, however, there has been no express requirement under the Privacy Act for them to do so. The new bill makes it a legal requirement for organisations subject to the Privacy Act to make notification of data breaches as soon as they are aware of it. This includes organisations with an annual turnover of more than $3 million, smaller organisations in the health and education sectors covered under the Privacy Act and individuals who handle personal information for a living, including those who handle credit reporting information, tax file numbers and health records.
Eligible data breaches
Once the law is passed, if organisations have reasonable grounds to suspect that there may have been an eligible data breach, they must carry out, and complete, an assessment within 30 days. Notification of such breaches must be made to the Australian Information Commissioner and affected individuals. An eligible data breach is one where there has been unauthorised access to, or disclosure of, personal information and there is a likely risk of serious harm to any of the affected individuals, or where personal information is lost in circumstances that are likely to give rise to unauthorised access to or disclosure. Whether an individual was at risk of “serious harm” would depend on a number of factors, such as whether the information is encrypted (and how hard that encryption would be to break) and the sensitivity of the information. The notification to the Australian Privacy and Information Commissioner and affected individuals should contain a description of the data breach, the kind of information involved, and steps that individuals can take to respond to the security incident.
Non-compliance
Disclosure in a timely manner can be a daunting task for many Australian businesses that are ill-equipped to detect a breach, often not finding out until months later. On average, breaches remain unnoticed for 229 days. Even then, while the company may know an intruder has accessed its systems, it might not be able to determine what, if anything, was stolen. The need to make a potentially damaging declaration in the event of a breach is now an incentive for organisations to review their information handling processes and ensure security systems are as tight as possible. Failure to comply with the notification scheme will be deemed an interference with the privacy of an individual and penalties include fines of $360,000 for individuals and $1.8 million for organisations. To assess if your customer data has been adequately secured and to equip your organisation with a response plan in the event of a data breach, contact the blueAPACHE team.
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Governance, Risk and Compliance
- Brotherhood of St Laurence (case study)
Frequently asked questions
What legislation does the article describe, and when does it take effect?
The Privacy Amendment (Notifiable Data Breaches) Bill 2016, passed by both houses of parliament, coming into effect within 12 months of the article.
Which organisations does the new law apply to, per the article?
Government agencies, businesses and not-for-profits with annual turnover over $3 million, smaller organisations in health and education covered under the Privacy Act, and individuals who handle personal information such as credit reporting data, tax file numbers and health records.
What timeframe does the article give for assessing a suspected eligible data breach?
Organisations must carry out and complete an assessment within 30 days of having reasonable grounds to suspect an eligible data breach.
How does the article define an "eligible data breach"?
Unauthorised access to or disclosure of personal information where there is a likely risk of serious harm to affected individuals, or personal information lost in circumstances likely to lead to unauthorised access or disclosure.
What factors does the article say determine whether harm is "serious"?
Factors such as whether the information is encrypted, and how hard that encryption would be to break, and the sensitivity of the information.
What must a breach notification to the Commissioner and affected individuals contain, per the article?
A description of the data breach, the kind of information involved, and steps individuals can take to respond to the security incident.
How long does the article say breaches typically go unnoticed on average?
The article states breaches remain unnoticed for an average of 229 days.
What penalties does the article cite for non-compliance with the notification scheme?
Fines of $360,000 for individuals and $1.8 million for organisations.
Source
- origin post (2017)
Knowledge Base
What is the name of the legislation discussed in this blueAPACHE article?
The article discusses the Privacy Amendment (Notifiable Data Breaches) Bill 2016, which was passed by both houses of the Australian parliament and was set to come into effect within 12 months of the article's publication (dated April 6, 2017).
Which organisations are required to comply with the mandatory data breach notification law?
According to the article, the law applies to Australian government agencies, businesses and not-for-profit organisations with an annual turnover of more than $3 million, smaller organisations in the health and education sectors covered under the Privacy Act, and individuals who handle personal information for a living, including those who handle credit reporting information, tax file numbers and health records.
What is an 'eligible data breach' under this legislation?
An eligible data breach is one where there has been unauthorised access to, or disclosure of, personal information and there is a likely risk of serious harm to any of the affected individuals, or where personal information is lost in circumstances likely to give rise to unauthorised access to or disclosure. Whether an individual is at risk of 'serious harm' depends on factors such as whether the information is encrypted (and how hard that encryption would be to break) and the sensitivity of the information.
How much time do organisations have to assess a suspected data breach?
Once the law is passed, if organisations have reasonable grounds to suspect an eligible data breach, they must carry out and complete an assessment within 30 days.
Who must be notified of an eligible data breach, and what must the notification contain?
Notification of an eligible data breach must be made to the Australian Information Commissioner and affected individuals. The notification should contain a description of the data breach, the kind of information involved, and steps that individuals can take to respond to the security incident.
What penalties apply for failing to comply with the data breach notification scheme?
Failure to comply with the notification scheme is deemed an interference with the privacy of an individual, and penalties include fines of $360,000 for individuals and $1.8 million for organisations.
Did Australia have mandatory data breach notification requirements before this bill?
No. The article states that, unlike many other countries, Australia did not currently have a mandatory data breach notification law at that time. Organisations could voluntarily undertake notification of data breaches, but there was no express requirement under the Privacy Act for them to do so.
How long do breaches typically go unnoticed, according to the article?
The article states that on average, breaches remain unnoticed for 229 days, and even after a company knows an intruder has accessed its systems, it might not be able to determine what, if anything, was stolen.
What can organisations do to prepare for this data breach notification requirement, according to blueAPACHE?
The article advises that the need to make a potentially damaging declaration in the event of a breach is an incentive for organisations to review their information handling processes and ensure security systems are as tight as possible. It suggests contacting the blueAPACHE team to assess whether customer data has been adequately secured and to equip the organisation with a response plan in the event of a data breach.
Under which part of Australian law is the Notifiable Data Breaches Scheme now governed?
According to the knowledge base, Australia's Notifiable Data Breaches Scheme is governed under Part IIIC of the Privacy Act 1988 (Cth).
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bef56ba2a604e909006_Data-breach-notification-laws.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)