CTS - Computer Technology Specialists
Notifiable Data Breaches Scheme Obligations
The Australian Notifiable Data Breaches (NDB) scheme requires eligible businesses to notify the OAIC and affected individuals when a data breach is likely to cause serious harm — and a 30-day assessment window is the maximum time allowed before notification must occur.
Melbourne IT support with visible local credentials
CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.
Certifications, affiliations and technology partners
Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.
Who is covered by the NDB scheme?
The NDB scheme applies to Australian Government agencies and private sector organisations covered by the Privacy Act 1988. Private sector coverage generally includes businesses with annual turnover greater than $3 million, health service providers regardless of turnover, organisations that handle tax file numbers, credit providers, and several other specific categories. Businesses below the $3 million turnover threshold may still be covered if they opt in, handle certain categories of sensitive information, or fall under a regulated sector. Businesses that are unsure of their coverage status should seek legal advice — the consequences of being covered and failing to notify can include regulatory action and civil liability.
What triggers an NDB notification obligation?
A notification obligation arises when there has been an eligible data breach — unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any of the individuals to whom the information relates. Ransomware attacks that encrypt personal information, phishing incidents that result in email account access, lost or stolen unencrypted devices, and database exposures resulting from web application vulnerabilities are all common triggers. Importantly, the breach does not need to be confirmed — if a reasonable person would conclude that there is a likely risk of serious harm, the obligation to assess and potentially notify exists.
The 30-day assessment window
When an organisation suspects an eligible data breach has occurred, it has 30 days to assess whether notification is required. During this window, the organisation should determine the scope and nature of the breach, assess whether the information involved is personal information under the Privacy Act, assess whether the breach is likely to result in serious harm, and either notify (if the assessment concludes notification is required) or document the assessment and conclude that notification is not required. The 30-day window begins when the organisation becomes aware of grounds to suspect a breach — not when the breach is confirmed. Delays in beginning the assessment process are a compliance risk.
What a notification must include
An NDB notification to the OAIC and to affected individuals must include: the identity and contact details of the organisation, a description of the data breach, the kinds of information involved, what steps the organisation recommends individuals take in response, and the contact details for further enquiries. The OAIC provides a standard notification form. Where it is not practicable to notify all affected individuals directly (because contact details are not available or the number of affected individuals is very large), the organisation may instead publish a statement on its website and take reasonable steps to bring it to the attention of affected individuals.
Consequences of failing to notify
Failure to notify when required is a breach of the Privacy Act. The OAIC can investigate, make determinations, require remediation, and refer matters to the Federal Court for civil penalty orders. The maximum civil penalty for a serious or repeated interference with privacy is $50 million for corporations. Beyond regulatory penalties, failure to notify can damage client trust, create civil liability from affected individuals, and result in adverse regulatory findings that affect professional licences in regulated sectors such as financial planning and legal services.
How CTS helps Melbourne businesses prepare for NDB obligations
CTS helps Melbourne businesses prepare for NDB obligations through incident response planning, security controls that reduce breach likelihood, and documentation of the evidence needed for breach assessment. CTS managed IT clients have monitoring that detects unusual data access patterns, endpoint protection that limits malware impact, and immutable backups that support recovery without ransom payment. CTS can assist in breach assessment — providing technical logs, access records, and scope analysis — during the 30-day assessment window. CTS maintains an incident response contact list for each managed IT client that includes insurer contacts, legal counsel, and the OAIC notification portal.
Frequently asked questions
Which Australian businesses are covered by the Notifiable Data Breaches scheme?
The NDB scheme covers Australian Government agencies and private sector organisations under the Privacy Act 1988. For the private sector, this generally includes businesses with annual turnover greater than $3 million, health service providers regardless of turnover, credit providers, businesses that handle tax file numbers, and other specifically regulated categories. Businesses unsure of their coverage status should seek legal advice — being covered and failing to notify when required can result in regulatory action and civil liability.
What happens if our business doesn't notify under the NDB scheme when required?
Failure to notify is a breach of the Privacy Act. The OAIC can investigate, make determinations, require remediation, and refer matters to the Federal Court for civil penalty orders. The maximum civil penalty is $50 million for a serious or repeated interference with privacy. Beyond regulatory penalties, failure to notify can damage client trust and create civil liability from affected individuals — particularly material for businesses in professional services where client trust is foundational.