The Notifiable Data Breach scheme. The 30-day clock starts the moment you know.
Under Part IIIC of the Privacy Act 1988, an eligible data breach triggers a 30-day clock. Within those 30 days you must assess, prepare a Statement of Notifiable Data Breach, lodge it with OAIC at oaic.gov.au, and notify each affected individual. Miss it and the body-corporate civil penalty is up to $50M.
How XIntelliSync changes the NDB equation
The 30-day clock starts the moment your business becomes aware of facts suggesting an eligible breach. The single biggest unknown for an SMB is "have we had one we don't know about?"
XIntelliSync's answer is structural, not aspirational. Every action that touches personal information emits a verification signature. Silent-write failure — the breach class where a write returns success but the database receives nothing — is exactly the pattern that, on personal-information tables, would start the 30-day clock without anyone knowing. XGVS Stage 0 + Stage 5 gates exist specifically to make that failure mode impossible to hide on this platform. You see the signal before OAIC ever sees the breach.
What XIntelliSync deliberately does NOT do: lodge the Statement of Notifiable Data Breach with OAIC on your behalf. Section 26WK of the Privacy Act puts lodgement and affected-individual notification on you as the APP entity. We prepare the Statement template populated with the incident facts. You submit it via oaic.gov.au.
Three tests for an eligible data breach
All three must be true. Then the 30-day clock starts.
Personal information was lost or accessed without authorisation
Or there is a reasonable likelihood it will be accessed without authorisation. Loss includes loss of physical media (laptop, USB, paper file). Unauthorised access includes ransomware, compromised credentials, mistaken email recipient, mis-shared cloud-storage link.
A reasonable person would conclude this is likely to result in serious harm
Serious harm includes serious physical, psychological, emotional, financial, or reputational harm. Test factors: kind + sensitivity of the information, ease of identification of individuals, whether protections (e.g. encryption) prevent harm, who obtained the information, and whether harm has actually materialised.
You are an APP entity (Privacy Act applies)
You are covered if turnover above $3M annually, OR you provide a health service, OR you handle TFNs, OR you provide credit / are a credit reporting body, OR you operate a residential tenancy database, OR you trade in personal information.
The 30-day clock
Awareness → Assessment → Statement → Notification.
The 30 days runs from the moment you become aware of facts suggesting an eligible breach has likely occurred — not from the moment you are certain. Document every step of the timeline.
Day 0
Awareness
You become aware of facts suggesting an eligible breach has likely occurred. Examples: customer reports an unexpected charge, security tooling flags unusual access, an employee reports a lost laptop. Awareness starts the 30-day clock.
Day 0–14
Reasonable assessment
Take reasonable steps to assess whether the suspected breach is in fact eligible. Document the assessment process. Engage incident response. Identify scope: whose information, what kind, what risk of serious harm.
Day 14–28
Prepare the Statement
If assessment confirms an eligible breach: prepare a Statement of Notifiable Data Breach. Include the entity identity, the breach description, the kind of information involved, recommended steps for affected individuals, and contact details for further information.
Day 30 (latest)
Notify OAIC + affected individuals
Lodge the Statement with OAIC via the online NDB form at oaic.gov.au + notify each affected individual. If notifying every individual is impracticable: publish the Statement on your website + take reasonable steps to publicise. Failure to notify within 30 days: civil penalty exposure.
Where to lodge externally
XIntelliSync prepares the Statement. You lodge with OAIC.
XIntelliSync is not a registered agent of the Office of the Australian Information Commissioner and does not lodge data breach notifications on your behalf. Once XIntelliSync prepares the Statement of Notifiable Data Breach + the affected-individual notification template, lodge externally:
OAIC NDB Form — oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach
Official online form to lodge a Statement of Notifiable Data Breach with the Australian Information Commissioner. Lodge within 30 days of awareness. Plus notify each affected individual using the same Statement.
OAIC NDB Scheme — oaic.gov.au/privacy/notifiable-data-breaches
OAIC's authoritative explainer on the NDB scheme — coverage, eligibility, assessment guidance, and notification requirements. Updated regularly with regulator interpretation notes.
OAIC NDB Quarterly Statistics — oaic.gov.au NDB statistics
Quarterly OAIC reports breaking down NDB notifications by industry, breach kind, source, and information type. Use as benchmarking + risk-pattern reference for your own threat model.
OAIC Data Breach Preparation + Response — oaic.gov.au data-breach-preparation-and-response
OAIC's practical guide to preparing for and responding to a data breach. Covers data breach response plans, the 4-step response (Contain → Assess → Notify → Review), and post-breach remediation.
AustLII — Privacy Act 1988 (Cth), Part IIIC
Free public access to Pt IIIC of the Privacy Act 1988 (the NDB scheme as enacted). The legal source — quote from this when responding to OAIC investigations or drafting incident-response procedures.
All 22+ industries served
The most-likely NDB scenario for every industry XIntelliSync serves.
Every industry has a characteristic data-breach pattern. Construction loses subcontractor TFNs on-site. Healthcare loses Medicare numbers via practice-management-system breaches. Retail loses card data via POS / e-commerce platform breaches. Use the matrix below to model your own threat surface.
Construction
Likely NDB scenario — Site supervisor laptop with subcontractor TFNs lost on site → eligible data breach if 2+ individuals affected. Notify OAIC + each affected sub within 30 days of awareness.
Healthcare
Likely NDB scenario — Practice-management-system breach exposing patient appointments + Medicare numbers = always notifiable. Clinical notes leak adds AHPRA professional reporting obligations on top of OAIC NDB.
Hospitality
Likely NDB scenario — Booking-system breach exposing customer names + dietary requirements (health info) + phone numbers — sensitive-information element triggers NDB regardless of turnover for the affected venue.
Retail
Likely NDB scenario — POS / e-commerce platform breach exposing card data + customer PII = NDB-eligible. Loyalty database breach with email + purchase history = also eligible if 2+ individuals affected.
Professional Services / Consulting
Likely NDB scenario — Engagement-server breach exposing client business plans + TFNs + employee data. Hard-drive theft from a client site visit is a frequently-cited NDB scenario for consulting.
Digital / Tech / SaaS
Likely NDB scenario — Database-credential leak via misconfigured cloud bucket or compromised dev token = high-volume NDB. SaaS vendor breach can cascade NDB to every customer (downstream notification).
Finance / Mortgage Brokers
Likely NDB scenario — Credit-application database breach exposing credit scores + financial position = always notifiable. Mortgage broker laptop with client tax returns + bank statements lost is the classic case.
Legal
Likely NDB scenario — Email-account compromise exposing privileged-matter content = NDB + Law Society reporting. Practice-management-system breach exposes trust-account ledgers — financial + identity exposure.
Childcare / Early Learning
Likely NDB scenario — Centre-management-software breach exposing CCS records + child immunisation status + parent IDs = always-notifiable. Photo album leak with identifiable children is a high-profile NDB.
Education / RTOs
Likely NDB scenario — Student information system (SIS) breach exposing TFNs + USIs + assessment records. Email-list leak of student email addresses is a frequently-cited low-severity NDB.
Manufacturing
Likely NDB scenario — ERP system breach exposing customer payment terms + supplier ABNs + employee records = NDB-eligible. Biometric timeclock vendor breach cascades NDB to the manufacturing customer.
Transport / Logistics
Likely NDB scenario — Telematics-vendor breach exposing driver routes + work diary entries + license details = NDB. Customer delivery-address database leak compromises customer privacy at scale.
Mining / Resources
Likely NDB scenario — Site-access system breach exposing biometric templates + employment records is high-severity (biometrics cannot be re-issued). NDB notification triggers AS/NZS 4360 risk review.
Agriculture / Primary Production
Likely NDB scenario — Farm-management-software breach exposing yield data + soil tests + worker PII. Seasonal worker payroll system breach exposing WHM passport copies is the classic agriculture NDB.
Fitness / Health Clubs
Likely NDB scenario — Gym-management-software breach exposing member health screening + DD payment details = always-notifiable. Photo-leak from PT video sessions adds image-based privacy harm.
Not-for-Profit
Likely NDB scenario — CRM breach exposing donor giving history + beneficiary case notes — beneficiary harm risk is often higher than donor harm. NDB notification to beneficiaries needs trauma-informed handling.
Events / Conferences
Likely NDB scenario — Ticketing-platform breach exposing attendee names + dietary needs + payment details. Speaker contract database breach exposes speaker fees + bank details = financial harm NDB.
Creative / Photography / Production
Likely NDB scenario — Image-archive breach with identifiable minors or sensitive-context shots = high-severity NDB. Cloud-storage credentials leak exposing client deliverables triggers contract + privacy harm.
Marketing / Advertising Agencies
Likely NDB scenario — Email-marketing platform breach exposing subscriber lists + segmentation tags. Audience-data marketplace acquisition may trigger derivative NDB across the bought lists.
HR / Recruitment
Likely NDB scenario — ATS (applicant tracking system) breach exposing candidate resumes + reference checks + bank details for placed candidates = NDB across multiple employers.
Insurance Brokers / Underwriters
Likely NDB scenario — Claims-management-system breach exposing medical reports + claim payouts = high-severity NDB. Re-insurance data flow breach via overseas processor cascades responsibility back to AU broker.
Real Estate / Property Management
Likely NDB scenario — Property-management-software breach exposing tenant applications + bank statements + landlord trust-account records. Utility-data integration creates derivative NDB across multiple tenants.
FAQs
The NDB scheme — answered.
When did the NDB scheme start?
The Notifiable Data Breach scheme commenced 22 February 2018 under Part IIIC of the Privacy Act 1988 (added by the Privacy Amendment (Notifiable Data Breaches) Act 2017). It applies to all APP entities (the same coverage rules as the rest of the Privacy Act).
What does "serious harm" mean?
Serious harm is not defined exhaustively in the Act. It includes serious physical, psychological, emotional, financial, or reputational harm. The OAIC assessment factors: kind of information (e.g. financial vs marketing email list), sensitivity (sensitive information weighs heavier), ease of re-identification, whether protections prevent harm (e.g. strong encryption), who obtained the information (criminals vs accidental third party), and whether harm has actually materialised. A breach exposing a single email address may not trigger NDB; the same breach plus credit card data almost certainly does.
What if I am not sure whether the breach is "eligible"?
The Act allows reasonable time to assess (typically up to 30 days). Document the assessment. If after assessment you decide the breach is not eligible — keep the documentation, because OAIC may later disagree. If you cannot decide within 30 days, lodge anyway and explain the uncertainty in the Statement; under-notifying is the costly mistake.
How do I lodge a Statement of Notifiable Data Breach with OAIC?
Use the online NDB form at oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach. The form captures: your identity, the breach description, the kind of information, the number of individuals affected, the steps you have taken or recommend, and contact details. Submission is free; OAIC acknowledges receipt and may follow up with questions.
How do I notify affected individuals?
Three options under Pt IIIC: (a) notify each affected individual directly (preferred — by email, letter, or in-app notice using the same channel they use to engage with you); (b) notify only individuals at risk of serious harm; or (c) if direct notification is impracticable, publish the Statement on your website + take reasonable steps to publicise (e.g. media release, public notice). Document why you chose the path you chose.
What is the maximum penalty for failing to notify?
For serious or repeated interference with privacy by a body corporate: the greater of $50M, three times the benefit derived from the breach, or 30% of adjusted turnover for the relevant period. For individuals: up to $2.5M. Plus reputational damage, OAIC investigation costs, and customer trust loss. Unintentional non-notification may attract lower penalties + an enforceable undertaking instead.
Does XIntelliSync notify OAIC on my behalf?
No. XIntelliSync prepares the Statement of Notifiable Data Breach template populated with the facts of the incident, but the customer must submit it via the OAIC NDB online form at oaic.gov.au. We are not acting as your agent for OAIC reporting. The customer retains lodgement authority + accountability. We document the incident timeline + assessment so the lodgement is fast and complete when you submit.
Continue reading