NSW Businesses: OAIC 30 Day Test for Notifiable Data Breaches
If a breach of personal information is likely to cause serious harm and you can't fix it through remedial action, the law requires you to notify both the OAIC and every individual affected, as soon as practicable. That's the whole test in one sentence: unauthorised access, disclosure or loss, likely serious harm, and no remedy in reach. The Privacy Act 1988, specifically Part IIIC, requires you to carry out a reasonable and expeditious assessment and, where practicable, complete that assessment within 30 calendar days before you act.
Key takeaways
- Most Australian organizations with over $3 million annual turnover or handling sensitive information like health records or tax details must comply with breach notification laws.
- An eligible breach involves unauthorized access, disclosure, or loss of data likely to cause serious harm, which can be physical, emotional, reputational, or financial.
- Rapid containment, remediation, and documentation within 30 days are critical to reducing notification obligations and minimizing harm.
- Pre-breach preparation, including incident response plans, encryption, backups, and staff training, significantly improves the ability to respond quickly and avoid notification.
- Proper notification must detail the breach, involved data types, and recommended actions, and can be communicated via multiple channels or published online to reach affected individuals.
Table of Contents
- Does the notifiable data breach scheme in Australia apply to you?
- What counts as an eligible data breach?
- How do you assess a suspected breach within 30 days?
- How do you notify the OAIC and affected individuals?
- What's the response sequence: contain, remediate, notify, review?
- When don't you have to notify?
- How NSW businesses can prepare before a breach happens
- Where to find the official OAIC guidance
- Why compliance checklists miss the point
- Sources
- FAQ
Does the notifiable data breach scheme in Australia apply to you?
The NDB scheme covers "APP entities," which is a fancy way of saying anyone bound by the Australian Privacy Principles. In practice, that includes most Australian Government agencies and a wide slice of the private sector.
You're almost certainly covered if your organisation fits any of these:
- Annual turnover above $3 million
- A private sector health service provider, regardless of size
- A credit reporting body or credit provider
- An entity that collects or holds tax file numbers
- A business that trades in personal information, no matter how small
Small businesses under the turnover threshold aren't automatically exempt. If you handle health records, TFNs, or you sell mailing lists, you're in scope even at a handful of employees. Don't guess. Work out your status early and write down how you reached that conclusion, because if a breach ever happens, that documentation is the first thing you'll want on hand.
What counts as an eligible data breach?
An "eligible" breach, the kind that triggers notification, occurs when there is unauthorised access to or disclosure of personal information, or the information is lost; a reasonable person would conclude the breach is likely to result in serious harm, meaning it is more probable than not; and remedial action has not prevented the likely risk of serious harm.
Serious harm isn't limited to financial loss. The OAIC treats it as physical, psychological, emotional, financial or reputational, assessed holistically rather than by ticking one box.
Real-world triggers we see regularly across NSW businesses:
- A staff laptop stolen from a car, unencrypted, with client files on it
- A hacked customer database exposing login credentials or payment details
- A misconfigured cloud folder that accidentally makes sensitive files public
- An email sent to the wrong distribution list containing medical or financial records
A lost phone with no lock screen and a customer contact list on it is a very different risk profile to the same phone, encrypted, wiped remotely within the hour. The scheme is built around that distinction.
How do you assess a suspected breach within 30 days?
Once you have reasonable grounds to suspect a breach, the clock starts. The OAIC's self-assessment guidance expects the assessment to be reasonable and expeditious, and where practicable, completed within 30 calendar days.
- Gather the facts fast. Build a timeline: what happened, which systems were touched, what kinds of personal information were involved, and whether a third party or supplier was part of the chain.
- Apply the reasonable person test. Would a sensible outsider, looking at the same facts, conclude serious harm is more likely than not?
- Test your remedial options. Can you recover a lost device before it's accessed, revoke compromised credentials, or pull down an exposed file, quickly enough that the risk of harm disappears?
- Write down your reasoning. Record who assessed it, what evidence they checked, what remediation was attempted, and why you landed where you did.
Pro Tip: Don't rush to notify a low-risk incident just to "be safe." The OAIC has flagged that premature notifications can cause alert fatigue and dilute trust in genuine warnings. Take the full assessment window if you need it, but document every day of it.
How do you notify the OAIC and affected individuals?
Once you've determined a breach is eligible, the statement you lodge with the OAIC needs specific content, not a general apology email. Section 26WK(3) sets out exactly what belongs in it.
| Statement must include | What that looks like in practice |
|---|---|
| Entity identity and contact details | Your organisation's name and a real contact point for follow-up questions |
| Description of the breach | What happened, when, and how it was discovered |
| Kinds of information involved | Names, addresses, financial details, health data, credentials, etc. |
| Recommended steps for recipients | Change passwords, watch bank statements, contact credit agencies, report to Scamwatch |
You can notify individuals directly by phone, email or letter, whichever method you'd normally use to reach them. Where direct contact isn't practicable, publish the statement on your website and take active steps to publicise it, social posts, a media note, whatever gets it in front of people who might be affected. The OAIC's online NDB form is how you lodge the notification with the regulator itself, and a read-only training version exists if you want your team to practise the form before a real incident forces their hand.
What's the response sequence: contain, remediate, notify, review?
The OAIC's four-step framework is the backbone of a defensible response, and it works whether you're a five-person clinic or a 200-seat firm.
- Contain first. Isolate the affected system, revoke compromised logins, trigger a remote wipe on a lost device.
- Remediate where you can. Recovering a device before it's accessed, or shutting down public exposure, can genuinely remove the notification obligation.
- Notify once assessed. Someone senior, usually your privacy officer or ops lead, should own the communication, not whoever happened to find the breach.
- Review afterwards. Update controls, retrain staff, and close the gap that let it happen.
Pro Tip: A device that's remotely wiped within minutes of being reported lost often never becomes a notifiable breach at all. Speed of containment is the cheapest compliance tool you have.
When don't you have to notify?
A few genuine exceptions exist. Notification obligations can be set aside for enforcement-related activities, certain secrecy provisions, or where the OAIC has made a specific declaration. My Health Record breaches run under their own overlapping notification scheme, so check which rules actually apply before assuming Part IIIC covers it alone.
- Enforcement-body exceptions where notification would compromise an investigation
- Secrecy provisions under other Commonwealth legislation
- An OAIC declaration exempting a specific breach
- My Health Record incidents, which may trigger a separate scheme
Multi-entity incidents, where a breach touches several organisations at once, usually default to whichever entity has the closest relationship with the affected individuals taking the lead on notifying. If you operate across state lines or hold data offshore, get a compliance check done, because state laws and international rules can stack on top of the federal scheme.
How NSW businesses can prepare before a breach happens
Good preparation is the difference between a five-minute containment and a six-week scramble. Governance matters as much as technology: have an incident response plan written down, an assessment template ready to go, clear staff reporting lines, and regular privacy training so people actually recognise a breach when they see one.
On the technical side, encrypted backups, multi-factor authentication, remote-wipe capability on every mobile device, and proper logging and monitoring all reduce the odds a small incident becomes a notifiable one. It's also worth reviewing supplier contracts for student data privacy and data-handling clauses, since a breach at a third-party vendor can still land on your desk.
Run a tabletop exercise once a year. Keep a blank OAIC statement template on file. Test your data restoration process before you need it for real.
- Draft and store an incident response plan and OAIC statement template
- Enforce MFA and encrypted backups across all devices
- Confirm remote-wipe capability on every laptop and phone that leaves the office
- Review vendor contracts for data-handling and breach-notification clauses
Pro Tip: If your team relies on onsite or remote IT support rather than an in-house security department, ask your provider to include breach-readiness, backup testing, and device encryption checks as part of a standard maintenance visit, not a separate emergency callout. PC Scientist's business cybersecurity services cover exactly this kind of preparation for NSW organisations, alongside network and Wi-Fi assessments that catch exposure points before they become incidents.
Where to find the official OAIC guidance
Bookmark the OAIC's main NDB page, the self-assessment tool, and the Privacy Amendment (Notifiable Data Breaches) Act 2017 text. Save the OAIC training form too, so your team can rehearse it.

Why compliance checklists miss the point
Most guidance on this topic reads like a legal exam answer: define the test, cite the sections, move on. What actually determines whether your organisation copes with a breach is what you did in the weeks before it happened, not the elegance of your statutory analysis afterwards.

The conventional advice treats notification as the finish line. It isn't. The real finish line is containment speed, because a device wiped in ten minutes or a credential revoked before it's used often never becomes an eligible breach at all. That's not a loophole, it's the scheme working as designed, rewarding organisations that can act fast over those that can only explain, after the fact, why they couldn't.
If you take one thing from this article, prioritise the boring stuff: encrypted devices, tested backups, a written response plan sitting somewhere your team can actually find it at 7am on a Saturday. Smaller NSW organisations without a dedicated security team tend to underinvest here, not because they don't care, but because nobody assigns it as anyone's job until something breaks. Our case studies reflect the same pattern again and again: the businesses that recover fastest are the ones who'd already rehearsed it.
- PC Scientist
Sources
Recommended
- Data Recovery Scientist | Files & Backup Help NSW
- Cybersecurity Scientist | Safer Devices NSW
- Business Cybersecurity NSW | After a Scare
Frequently Asked Questions
Straight answers about NSW Businesses: OAIC 30 Day Test for Notifiable Data Breaches - without jargon or pressure. Call 0493 563 381 for advice, or get help below.
Want the quickest answer? 0493 563 381 for free advice.
Both the OAIC and every individual whose personal information was involved must be notified once a breach is assessed as eligible, unless a specific exception applies.
It's Part IIIC of the Privacy Act 1988, introduced by the Privacy Amendment (Notifiable Data Breaches) Act 2017, requiring APP entities to report eligible breaches to the OAIC and affected individuals.
Penalties depend on the nature and severity of the non-compliance and are enforced by the OAIC, which can investigate, issue directions, and pursue serious or repeated failures through the courts under the Privacy Act.
You must notify as soon as practicable after determining a breach is eligible, and the statement must include your organisation's contact details, a description of the breach, the kinds of information involved, and recommended steps for affected recipients.
Cybersecurity across NSW
Still stuck after a notifiable data breach?
If the device still does not feel safe, that is okay. Get help in your area and we will take it from here.
Start here
Get cybersecurity help
Optional Need a Sydney city or region?
Choose a side of Sydney
These are Sydney cities and regions, such as the Northern Beaches or Inner West. First tap a side of Sydney. Then open the city or region that covers you.
C Sydney City / Inner 3 areas
N Northern Sydney 6 areas
NW North-West / Central Sydney 3 areas
W Western Sydney 1 area
SW South-West Sydney 3 areas
S Southern Sydney 2 areas
Optional Find your suburb
Type a suburb from our listed coverage. This opens the matching city or region page for this topic. Listed suburb pages are general technology services, not this specialist page.
If your suburb is not listed, use the city or region list above, or call 0493 563 381.
Disclaimer
The information in this article is provided for general educational and informational purposes only. While PC Scientist strives to keep all content accurate and up to date, technology issues can vary depending on your device, software, network configuration, and individual circumstances. Always back up important data before attempting repairs or system changes. If you are unsure or the issue cannot be resolved safely, contact PC Scientist today for professional onsite or remote IT support. PC Scientist is not liable for any loss of data, damage, or other issues resulting from the use of the information provided in this article.