08/12/2025
When a data breach occurs, Australian organisations must act swiftly and comprehensively. Under the Office of the Australian Information Commissioner (OAIC) Privacy Act 1988 and the Privacy Amendment (Notifiable Data Breaches) Act 2017 (NDB) scheme, entities covered by the act must:
• Assess the incident within 30 days of becoming aware of any unauthorised access, disclosure, or loss of personal information.
• If the breach is likely to cause serious harm, notify both affected individuals and the OAIC without undue delay.
• Maintain a detailed record of the incident, including causes, mitigation actions and future prevention plans.
Boards and senior leadership must ensure governance frameworks are in place, obligations are clearly assigned, and that the organisation aligns with the APP 11 requirement to take reasonable steps to protect personal information.
A total of 1,113 notifications were recorded in 2024, the highest since the scheme began. Organisations must no longer disregard regulatory compliance.
[https://hubs.li/Q03Wzqjm0]
Want to test your breach-response readiness? Schedule a simulation with Anitech today: https://hubs.li/Q03Wzp_T0