Pillar · Privacy Act / APP / NDB

The Notifiable Data Breach scheme. The 30-day clock starts the moment you know.

Under Part IIIC of the Privacy Act 1988, an eligible data breach triggers a 30-day clock. Within those 30 days you must assess, prepare a Statement of Notifiable Data Breach, lodge it with OAIC at oaic.gov.au, and notify each affected individual. Miss it and the body-corporate civil penalty is up to $50M.

How XIntelliSync changes the NDB equation

The 30-day clock starts the moment your business becomes aware of facts suggesting an eligible breach. The single biggest unknown for an SMB is "have we had one we don't know about?"

XIntelliSync's answer is structural, not aspirational. Every action that touches personal information emits a verification signature. Silent-write failure — the breach class where a write returns success but the database receives nothing — is exactly the pattern that, on personal-information tables, would start the 30-day clock without anyone knowing. XGVS Stage 0 + Stage 5 gates exist specifically to make that failure mode impossible to hide on this platform. You see the signal before OAIC ever sees the breach.

What XIntelliSync deliberately does NOT do: lodge the Statement of Notifiable Data Breach with OAIC on your behalf. Section 26WK of the Privacy Act puts lodgement and affected-individual notification on you as the APP entity. We prepare the Statement template populated with the incident facts. You submit it via oaic.gov.au.

← Privacy Act pillar · See how the Trust Stack works →

Three tests for an eligible data breach

All three must be true. Then the 30-day clock starts.

1

Personal information was lost or accessed without authorisation

Or there is a reasonable likelihood it will be accessed without authorisation. Loss includes loss of physical media (laptop, USB, paper file). Unauthorised access includes ransomware, compromised credentials, mistaken email recipient, mis-shared cloud-storage link.

2

A reasonable person would conclude this is likely to result in serious harm

Serious harm includes serious physical, psychological, emotional, financial, or reputational harm. Test factors: kind + sensitivity of the information, ease of identification of individuals, whether protections (e.g. encryption) prevent harm, who obtained the information, and whether harm has actually materialised.

3

You are an APP entity (Privacy Act applies)

You are covered if turnover above $3M annually, OR you provide a health service, OR you handle TFNs, OR you provide credit / are a credit reporting body, OR you operate a residential tenancy database, OR you trade in personal information.

The 30-day clock

Awareness → Assessment → Statement → Notification.

The 30 days runs from the moment you become aware of facts suggesting an eligible breach has likely occurred — not from the moment you are certain. Document every step of the timeline.

Day 0

Awareness

You become aware of facts suggesting an eligible breach has likely occurred. Examples: customer reports an unexpected charge, security tooling flags unusual access, an employee reports a lost laptop. Awareness starts the 30-day clock.

Day 0–14

Reasonable assessment

Take reasonable steps to assess whether the suspected breach is in fact eligible. Document the assessment process. Engage incident response. Identify scope: whose information, what kind, what risk of serious harm.

Day 14–28

Prepare the Statement

If assessment confirms an eligible breach: prepare a Statement of Notifiable Data Breach. Include the entity identity, the breach description, the kind of information involved, recommended steps for affected individuals, and contact details for further information.

Day 30 (latest)

Notify OAIC + affected individuals

Lodge the Statement with OAIC via the online NDB form at oaic.gov.au + notify each affected individual. If notifying every individual is impracticable: publish the Statement on your website + take reasonable steps to publicise. Failure to notify within 30 days: civil penalty exposure.

Where to lodge externally

XIntelliSync prepares the Statement. You lodge with OAIC.

XIntelliSync is not a registered agent of the Office of the Australian Information Commissioner and does not lodge data breach notifications on your behalf. Once XIntelliSync prepares the Statement of Notifiable Data Breach + the affected-individual notification template, lodge externally:

All 22+ industries served

The most-likely NDB scenario for every industry XIntelliSync serves.

Every industry has a characteristic data-breach pattern. Construction loses subcontractor TFNs on-site. Healthcare loses Medicare numbers via practice-management-system breaches. Retail loses card data via POS / e-commerce platform breaches. Use the matrix below to model your own threat surface.

Construction

Likely NDB scenario — Site supervisor laptop with subcontractor TFNs lost on site → eligible data breach if 2+ individuals affected. Notify OAIC + each affected sub within 30 days of awareness.

Healthcare

Likely NDB scenario — Practice-management-system breach exposing patient appointments + Medicare numbers = always notifiable. Clinical notes leak adds AHPRA professional reporting obligations on top of OAIC NDB.

Hospitality

Likely NDB scenario — Booking-system breach exposing customer names + dietary requirements (health info) + phone numbers — sensitive-information element triggers NDB regardless of turnover for the affected venue.

Retail

Likely NDB scenario — POS / e-commerce platform breach exposing card data + customer PII = NDB-eligible. Loyalty database breach with email + purchase history = also eligible if 2+ individuals affected.

Professional Services / Consulting

Likely NDB scenario — Engagement-server breach exposing client business plans + TFNs + employee data. Hard-drive theft from a client site visit is a frequently-cited NDB scenario for consulting.

Digital / Tech / SaaS

Likely NDB scenario — Database-credential leak via misconfigured cloud bucket or compromised dev token = high-volume NDB. SaaS vendor breach can cascade NDB to every customer (downstream notification).

Finance / Mortgage Brokers

Likely NDB scenario — Credit-application database breach exposing credit scores + financial position = always notifiable. Mortgage broker laptop with client tax returns + bank statements lost is the classic case.

Legal

Likely NDB scenario — Email-account compromise exposing privileged-matter content = NDB + Law Society reporting. Practice-management-system breach exposes trust-account ledgers — financial + identity exposure.

Childcare / Early Learning

Likely NDB scenario — Centre-management-software breach exposing CCS records + child immunisation status + parent IDs = always-notifiable. Photo album leak with identifiable children is a high-profile NDB.

Education / RTOs

Likely NDB scenario — Student information system (SIS) breach exposing TFNs + USIs + assessment records. Email-list leak of student email addresses is a frequently-cited low-severity NDB.

Manufacturing

Likely NDB scenario — ERP system breach exposing customer payment terms + supplier ABNs + employee records = NDB-eligible. Biometric timeclock vendor breach cascades NDB to the manufacturing customer.

Transport / Logistics

Likely NDB scenario — Telematics-vendor breach exposing driver routes + work diary entries + license details = NDB. Customer delivery-address database leak compromises customer privacy at scale.

Mining / Resources

Likely NDB scenario — Site-access system breach exposing biometric templates + employment records is high-severity (biometrics cannot be re-issued). NDB notification triggers AS/NZS 4360 risk review.

Agriculture / Primary Production

Likely NDB scenario — Farm-management-software breach exposing yield data + soil tests + worker PII. Seasonal worker payroll system breach exposing WHM passport copies is the classic agriculture NDB.

Fitness / Health Clubs

Likely NDB scenario — Gym-management-software breach exposing member health screening + DD payment details = always-notifiable. Photo-leak from PT video sessions adds image-based privacy harm.

Not-for-Profit

Likely NDB scenario — CRM breach exposing donor giving history + beneficiary case notes — beneficiary harm risk is often higher than donor harm. NDB notification to beneficiaries needs trauma-informed handling.

Events / Conferences

Likely NDB scenario — Ticketing-platform breach exposing attendee names + dietary needs + payment details. Speaker contract database breach exposes speaker fees + bank details = financial harm NDB.

Creative / Photography / Production

Likely NDB scenario — Image-archive breach with identifiable minors or sensitive-context shots = high-severity NDB. Cloud-storage credentials leak exposing client deliverables triggers contract + privacy harm.

Marketing / Advertising Agencies

Likely NDB scenario — Email-marketing platform breach exposing subscriber lists + segmentation tags. Audience-data marketplace acquisition may trigger derivative NDB across the bought lists.

HR / Recruitment

Likely NDB scenario — ATS (applicant tracking system) breach exposing candidate resumes + reference checks + bank details for placed candidates = NDB across multiple employers.

Insurance Brokers / Underwriters

Likely NDB scenario — Claims-management-system breach exposing medical reports + claim payouts = high-severity NDB. Re-insurance data flow breach via overseas processor cascades responsibility back to AU broker.

Real Estate / Property Management

Likely NDB scenario — Property-management-software breach exposing tenant applications + bank statements + landlord trust-account records. Utility-data integration creates derivative NDB across multiple tenants.

FAQs

The NDB scheme — answered.

When did the NDB scheme start?

The Notifiable Data Breach scheme commenced 22 February 2018 under Part IIIC of the Privacy Act 1988 (added by the Privacy Amendment (Notifiable Data Breaches) Act 2017). It applies to all APP entities (the same coverage rules as the rest of the Privacy Act).

What does "serious harm" mean?

Serious harm is not defined exhaustively in the Act. It includes serious physical, psychological, emotional, financial, or reputational harm. The OAIC assessment factors: kind of information (e.g. financial vs marketing email list), sensitivity (sensitive information weighs heavier), ease of re-identification, whether protections prevent harm (e.g. strong encryption), who obtained the information (criminals vs accidental third party), and whether harm has actually materialised. A breach exposing a single email address may not trigger NDB; the same breach plus credit card data almost certainly does.

What if I am not sure whether the breach is "eligible"?

The Act allows reasonable time to assess (typically up to 30 days). Document the assessment. If after assessment you decide the breach is not eligible — keep the documentation, because OAIC may later disagree. If you cannot decide within 30 days, lodge anyway and explain the uncertainty in the Statement; under-notifying is the costly mistake.

How do I lodge a Statement of Notifiable Data Breach with OAIC?

Use the online NDB form at oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach. The form captures: your identity, the breach description, the kind of information, the number of individuals affected, the steps you have taken or recommend, and contact details. Submission is free; OAIC acknowledges receipt and may follow up with questions.

How do I notify affected individuals?

Three options under Pt IIIC: (a) notify each affected individual directly (preferred — by email, letter, or in-app notice using the same channel they use to engage with you); (b) notify only individuals at risk of serious harm; or (c) if direct notification is impracticable, publish the Statement on your website + take reasonable steps to publicise (e.g. media release, public notice). Document why you chose the path you chose.

What is the maximum penalty for failing to notify?

For serious or repeated interference with privacy by a body corporate: the greater of $50M, three times the benefit derived from the breach, or 30% of adjusted turnover for the relevant period. For individuals: up to $2.5M. Plus reputational damage, OAIC investigation costs, and customer trust loss. Unintentional non-notification may attract lower penalties + an enforceable undertaking instead.

Does XIntelliSync notify OAIC on my behalf?

No. XIntelliSync prepares the Statement of Notifiable Data Breach template populated with the facts of the incident, but the customer must submit it via the OAIC NDB online form at oaic.gov.au. We are not acting as your agent for OAIC reporting. The customer retains lodgement authority + accountability. We document the incident timeline + assessment so the lodgement is fast and complete when you submit.