What to do if your business has been breached

Download this fact sheet (PDF)

Businesses that experience a breach may have specific obligations depending on whether the Privacy Act applies to them, the type of personal data involved, and the risk of serious harm resulting from the breach. Serious harm does not have to be explicitly financial, it can be psychological, physical or reputational harm. 

Current requirements 

A small business is defined under the Privacy Act 1988 (Cth) as one which has an annual turnover of less than 3 million Australian dollars (Section 6D(1)). This value is inclusive of income from all sources and does not include assets held, capital gains or the proceeds of capital gains (Office of the Australian Information Commissioner OAIC). 

If your small business falls under the Privacy Act and experiences a breach, there are obligations under the Notifiable Data Breach scheme. However, some small businesses that are not covered by the Privacy Act still must report a data breach event irrespective of their turnover, these include businesses: 

  • That provide a health service, or hold any health information, except an employee record; or 
  • That disclose personal information about another individual to anyone else for a benefit, service or advantage; or 
  • Provide a benefit, service or advantage to collect personal information about another individual from anyone else; or 
  • That are contracted service providers for a Commonwealth contract; or  
  • That are credit reporting bodies (Section 6D(4); OAIC). 

What constitutes an eligible data breach? 

  • Unauthorised access or disclosure to personal information, or a loss of personal information, held by an agency; or 
  • That is likely to result in “serious harm” to one or more individuals; or 
  • The organisation or agency has not been able to prevent the likely risk of serious harm with remedial action. (OAIC) 

How to report a data breach? 

  • You should report a data breach to the OAIC as soon as practicable. However, the maximum amount of time before making a report is 30 days after you believe that you experienced a data breach event.  This timeframe is provided for the business to assess the risk of “serious harm” to the individual as a result of the data breach. (Section 26WH (2)(b)); OAIC) 
  • You may also wish to contact the OAIC enquiries line: 1300 363 992 

What do I notify about? 

You must notify the OAIC and any affected individuals of: 

  • Your organisation’s name and contact details 
  • A description of the data breach 
  • Types of information involved 
  • Recommendations of response steps an individual should take (OAIC) 

IDCARE can offer your business additional support in drafting and preparing data breach notifications and supporting impacted individuals. 

‍

For additional support or information, contact IDCARE by submitting a Get Help Form or call 1800 595 160 (Aus) or 0800 121 068 (NZ).

If you would like to provide feedback please use our Feedback Form.

Join the global list of organisations making a real difference in people’s lives by supporting our service.

SBS Bank
HSBC
ANZ
Department of home affairs
Curtin University
Suncorp
Powercor Australia
ING
Regional Australia Bank
Culture Amp
Mercy Health
Queensland Country Bank
Sportsbet
NGM Group
City of Goldcoast
ConnectID
TPG
Western Sydney University
BOQ
Department of Premiere and Cabinet off of Digital Government
ABC
Coles
REA Group
Equip Super
Return to Work SA
Urban Utilities
Transurban
Westpac
Internal Affairs
Allianz
Commonwealth Bank
Bupa
Services Australia
Qantas
NAB
Australia Post
Victoria State Government
NBN
NDIS
Kiwi Bank
Tasmanian Government
Telstra
UTS
Makesure
Australian Super
Australia Post
Urban Utilities
Brisbane City Council

Copyright © 2025, IDCARE. All Rights Reserved.

ABN 84 164 038 966