NSW Businesses: OAIC 30 Day Test for Notifiable Data Breaches
Someone just told you a laptop left a car. Or a shared folder was open to the web. Your stomach is already doing the maths. Do you ring the OAIC? Do you email every client? Or do you fix it first and then decide?
- Ask whether you are even covered. Turnover over $3 million, health records, tax file numbers, or trading in personal information. Small is not automatically out.
- Ask what actually leaked. Names. Logins. Health notes. Card numbers. The kind of data changes the harm test.
- Ask whether you can still contain it. Remote wipe. Revoke the login. Pull the folder down. Speed here is the cheapest compliance tool you have.
- Ask who owns the write-up. A reasonable assessment needs a name, a timeline, and a decision. Not a group chat at 11pm.
If you would rather not guess the ports and the paperwork, Cybersecurity Scientist can walk the assessment with you. Sydney businesses can start with cybersecurity help across Sydney. Central Coast offices can use cybersecurity help on the Central Coast.
This is about the OAIC 30 day test, not a lost photo. File recovery after a scare sits in NAS data recovery. A mailbox that is already someone else's sits in recover hacked email.
Key takeaways
Most Australian organisations with turnover over $3 million, or that handle health records or tax file numbers, sit inside the notifiable data breach scheme. An eligible breach is unauthorised access, disclosure, or loss that is likely to cause serious harm, and that you could not undo in time. The 30 days are for the assessment. Containment starts now.
| Point | Details |
|---|---|
| Who is in | APP entities. Government agencies. Private businesses over $3 million. Health providers, credit bodies, TFN holders, and anyone trading in personal information, even if they are small. |
| Eligible breach | Unauthorised access, disclosure, or loss. A reasonable person would say serious harm is more likely than not. Remedial action has not removed that risk. |
| Serious harm | Not only money. Physical, psychological, emotional, financial, or reputational. Look at the whole picture. |
| 30 calendar days | Finish a reasonable assessment where it is practicable. Document every day. Do not wait 30 days to wipe a lost phone. |
| Notify | OAIC and the people affected, as soon as practicable after you decide it is eligible. Say what happened, what data, and what they should do. |
Table of contents
- Does the scheme apply to you?
- What counts as an eligible data breach?
- How do you assess a suspected breach within 30 days?
- How do you notify the OAIC and affected people?
- Contain, remediate, notify, review
- When you do not have to notify
- How NSW businesses can prepare
- Where to find the official OAIC guidance
- Why compliance checklists miss the point
- Sources
- FAQ
Does the notifiable data breach scheme in Australia apply to you?
The NDB scheme covers APP entities. In plain terms, that is anyone bound by the Australian Privacy Principles. Most Australian Government agencies. A wide slice of private business.
You are almost certainly in if any of these is true:
- Annual turnover above $3 million
- A private health service, even a small clinic
- A credit reporting body or credit provider
- You collect or hold tax file numbers
- You trade in personal information, no matter how small the team
Under the turnover line is not a free pass. Health records, TFNs, or a mailing list you sell still put you in. Work that out now. Write down how you reached it. If a breach ever happens, that note is the first thing you will want in your hand.
What counts as an eligible data breach?
An eligible breach is the kind that triggers notification. Three parts sit together. Unauthorised access, disclosure, or loss of personal information. A reasonable person would conclude serious harm is more likely than not. And what you did afterwards did not remove that likely harm.
Serious harm is not only a bank transfer. The OAIC treats it as physical, psychological, emotional, financial, or reputational. Look at it as a whole, not one ticked box.
Patterns we see across NSW businesses:
- A staff laptop stolen from a car, unencrypted, with client files on it
- A customer database opened, with logins or payment details sitting there
- A cloud folder left public by a setting nobody checked
- An email that went to the wrong list, with medical or financial records attached
A lost phone with no lock and a customer list on it is a different risk to the same phone, encrypted, wiped in the hour. The scheme is built around that difference.
How do you assess a suspected breach within 30 days?
Once you have reasonable grounds to suspect a breach, the clock starts. The OAIC wants the assessment reasonable and quick. Where it is practicable, finish it within 30 calendar days.
- Get the facts fast. Timeline. Which systems. What kinds of personal information. Whether a supplier sat in the chain.
- Apply the reasonable person test. Would a sensible outsider, looking at the same facts, say serious harm is more likely than not?
- Test what you can still undo. Recover the device before it is opened. Revoke the login. Pull the file down. Fast enough that the harm risk actually disappears.
- Write the reasoning down. Who assessed it. What they checked. What you tried. Why you landed where you did.
Pro Tip: Do not notify a low-risk incident just to feel safer. The OAIC has said premature notices wear people out and weaken the ones that matter. Use the assessment window if you need it. Document every day of it.
How do you notify the OAIC and affected people?
Once you decide it is eligible, the statement to the OAIC is specific. Section 26WK(3) sets out what belongs in it. A general apology email is not that statement.
| Statement must include | What that looks like |
|---|---|
| Who you are, and how to reach you | Organisation name and a real contact for follow-up |
| What happened | What, when, and how you found it |
| Kinds of information | Names, addresses, financial details, health data, credentials |
| What people should do | Change passwords, watch statements, speak to a credit agency, report to Scamwatch |
You can tell people by phone, email, or letter. Use the channel you already use with them. If you cannot reach them directly, publish the statement on your website and take real steps to put it in front of them. The OAIC online NDB form is how you lodge it with the regulator. There is a training version of that form. Use it before a Saturday morning forces your hand.
What is the response sequence: contain, remediate, notify, review?
The OAIC four-step frame holds whether you are a five-person clinic or a 200-seat firm.
- Contain first. Isolate the system. Revoke the login. Trigger a remote wipe.
- Remediate where you can. Recovering a device before it is opened, or shutting a public folder, can take you out of notification.
- Notify once assessed. Someone senior should own the words. Not whoever found the folder.
- Review afterwards. Close the gap. Retrain. Update the plan so the next one is shorter.
Pro Tip: A device wiped in minutes of being reported lost often never becomes a notifiable breach. Speed of containment is cheaper than a six-week write-up.
When do you not have to notify?
A few genuine exceptions exist. Enforcement activity. Certain secrecy rules. An OAIC declaration for a specific breach. My Health Record incidents can sit under a separate scheme, so check which rules actually apply before you assume Part IIIC is the only page.
- Enforcement-body exceptions where notice would harm an investigation
- Secrecy provisions under other Commonwealth law
- An OAIC declaration that exempts that breach
- My Health Record incidents that may trigger a different scheme
If several organisations are in the same incident, the one closest to the people affected usually leads the notice. If you hold data in another state or offshore, get that checked. Extra rules can sit on top of the federal scheme.
How NSW businesses can prepare before a breach happens
Preparation is the difference between a five-minute wipe and a six-week scramble. An incident plan on paper. An assessment template ready. A reporting line staff actually use. Privacy training so people recognise a breach when they see one.
On the technical side: encrypted backups, multi-factor authentication, remote wipe on every phone and laptop that leaves the office, and logging you can actually read. Review supplier contracts for data-handling and breach clauses. A vendor breach can still land on your desk.
Run a tabletop once a year. Keep a blank OAIC statement on file. Test restore before you need it for real.
- Draft and store an incident plan and an OAIC statement template
- Turn on MFA and encrypted backups across devices
- Confirm remote wipe on every laptop and phone that leaves the office
- Review vendor contracts for data-handling and breach-notification clauses
Pro Tip: If you do not have an in-house security team, ask your IT person to include breach-readiness, backup testing, and device encryption in a normal maintenance visit. Do not wait for the emergency callout.
Business cybersecurity is that kind of preparation for NSW organisations. Network exposure that nobody noticed still belongs with Network Scientist before it becomes an incident.
Where to find the official OAIC guidance
Bookmark the OAIC NDB page, the self-assessment tool, and the Privacy Amendment (Notifiable Data Breaches) Act 2017 text. Save the training form so your team can rehearse it.

Why compliance checklists miss the point
Most write-ups on this topic read like an exam answer. Define the test. Cite the section. Move on. What actually decides whether you cope is what you did in the weeks before it happened, not how tidy the statutory analysis looks afterwards.

Notification is not the finish line. Containment speed is. A device wiped in ten minutes, or a credential revoked before it is used, often never becomes an eligible breach. That is the scheme working. It rewards organisations that can act, not only organisations that can explain why they could not.
If you take one thing: encrypted devices, tested backups, and a written response plan sitting where someone can find it at 7am on a Saturday. Smaller NSW organisations skip this because it is nobody's job until something breaks. The businesses that recover fastest had already rehearsed it. That pattern shows up in our case studies as well.
Call 0493 563 381 if you want a person to look at encryption, remote wipe, and the assessment template before you need them. We will talk it through honestly, then help you take the next small step.
Sources
These pages help when you want the official wording, not a paraphrase:
- Office of the Australian Information Commissioner
- Privacy Amendment (Notifiable Data Breaches) Act 2017
- Scamwatch - Australian Competition and Consumer Commission
Frequently Asked Questions
Straight answers about notifiable data breaches in Australia - without jargon or pressure. Call 0493 563 381 for advice, or get help below.
Want the quickest answer? 0493 563 381 for free advice.
Both the OAIC and every person whose personal information was involved, once you decide the breach is eligible. A few narrow exceptions exist. Write those down if you are relying on one.
Part IIIC of the Privacy Act 1988. It was added by the Privacy Amendment (Notifiable Data Breaches) Act 2017. APP entities have to report eligible breaches to the OAIC and to the people affected.
They depend on how serious the failure is. The OAIC can investigate, give directions, and take serious or repeated failures to court under the Privacy Act.
Notify as soon as practicable after you decide it is eligible. The statement needs your contact details, what happened, what kinds of information were involved, and what people should do next.
The assessment should be reasonable and quick. Where it is practicable, finish it within 30 calendar days. Containment can still happen on day one. Do not sit on a laptop in a car park waiting for the calendar.
Cybersecurity across NSW
Still working out if this breach is notifiable?
If a laptop left a car, or a folder was open, that is okay. Get help in your area and we will take the assessment from here.
Start here
Get cybersecurity help
Optional Need a Sydney city or region?
Choose a side of Sydney
These are Sydney cities and regions, such as the Northern Beaches or Inner West. First tap a side of Sydney. Then open the city or region that covers you.
C Sydney City / Inner 3 areas
N Northern Sydney 6 areas
NW North-West / Central Sydney 3 areas
W Western Sydney 1 area
SW South-West Sydney 3 areas
S Southern Sydney 2 areas
Optional Find your suburb
Type a suburb from our listed coverage. This opens the matching city or region page for this topic. Listed suburb pages are general technology services, not this specialist page.
If your suburb is not listed, use the city or region list above, or call 0493 563 381.
Disclaimer
The information in this article is provided for general educational and informational purposes only. While PC Scientist strives to keep all content accurate and up to date, technology issues can vary depending on your device, software, network configuration, and individual circumstances. Always back up important data before attempting repairs or system changes. If you are unsure or the issue cannot be resolved safely, contact PC Scientist today for professional onsite or remote IT support. PC Scientist is not liable for any loss of data, damage, or other issues resulting from the use of the information provided in this article.