Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When must you notify an eligible data breach?

Updated

If Part IIIC applies, notify the Commissioner and affected individuals as soon as practicable after becoming aware of reasonable grounds to believe an eligible data breach occurred (ss 26WK–26WL). The 30-day window is assessment, not a notify clock. Not legal advice; does not start a clock.

Australia NDB jurisdiction guide, last verified 8 September 2026 against Privacy Act 1988 compilation no. 104 (compilation date 4 June 2026; C2026C00227; includes amendments up to Act No. 75, 2025) Part IIIC on legislation.gov.au, the Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) commencement table, and OAIC Notifiable Data Breaches pages actually fetched. OAIC guidance is guidance, not the Act. It is not legal advice, not a filing, not an eligible-data-breach finding on YOUR facts, not a determination that the Privacy Act or the NDB scheme applies, and not a substitute for counsel.

This is Part IIIC, not YOUR determination

Audience: a compliance lead, privacy officer, CISO, or counsel at an APP entity, credit reporting body, credit provider, or file number recipient triaging an incident that may involve personal information held in Australia or under an Australian link. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Privacy Act 1988 applies, that you are an APP entity, that an eligible data breach occurred, that serious harm is likely, or that you must file.

The Notifiable Data Breaches scheme is Privacy Act 1988 Part IIIC. Section 26WA: this Part sets up a scheme for notification of eligible data breaches. An eligible data breach happens if there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity, and the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates. Those sections are legal requirements only if the Act applies to YOUR facts. Last verified 8 September 2026. Not legal advice.

  • Statute versus guidance: Part IIIC (ss 26WA–26XH) is a legal requirement only if the Act applies. OAIC Notifiable Data Breaches pages, the OAIC Data Breach Preparation and Response Part 4 guide (updated February 2025), and the OAIC online Notifiable Data Breach form are OAIC materials, not the Act. This page quotes which kind of text it is relying on.
  • This page does not start a 30-day assessment clock, does not convert the 30-day assessment window in s 26WH into a 30-day notification deadline, and does not convert 'as soon as practicable' in ss 26WK–26WL into GDPR 72 hours or any other hour-count.
  • The reporting-deadlines page on this site is the statute table of clocks. The who-to-notify page on this site is the recipient-class map. The which-jurisdictions-apply page on this site is the applicability map, including Australia Privacy Act 1988 section 5B extra-territorial operation. The supporting-evidence page on this site is the evidentiary record.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not an NDB clock, and it does not file with the OAIC. A named human still submits.

Eligible data breach — unauthorised access, disclosure, or loss AND likely serious harm

Section 26WE is the definition. Unauthorised access or unauthorised disclosure, or loss in circumstances where unauthorised access or disclosure is likely to occur, is not enough on its own. A reasonable person would also have to conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. This page quotes that test. It does not find likely serious harm on YOUR facts. Last verified 8 September 2026. Not legal advice.

s 26WE eligible data breach (legal requirement only if the Act applies — not YOUR finding; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
Who it can attach tos 26WE(1): an APP entity holding personal information and required under s 15 not to breach APP 11.1; a credit reporting body holding credit reporting information and required to comply with s 20Q; a credit provider holding credit eligibility information and required to comply with s 21S(1); or a file number recipient holding tax file number information and required under s 18 not to breach a s 17 rule.Legal requirement — s 26WE(1). This page does not determine that YOU are any of those entities.8 September 2026
Access or disclosure limbs 26WE(2)(a): there is unauthorised access to, or unauthorised disclosure of, the information, and a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates.Legal requirement — s 26WE(2)(a). Both conditions. This page does not find unauthorised access on YOUR facts.8 September 2026
Loss limbs 26WE(2)(b): the information is lost in circumstances where unauthorised access to, or unauthorised disclosure of, the information is likely to occur, and, assuming that access or disclosure were to occur, a reasonable person would conclude that it would be likely to result in serious harm to any of the individuals to whom the information relates.Legal requirement — s 26WE(2)(b). Loss without likely subsequent unauthorised access or disclosure is not this limb.8 September 2026
At risks 26WE(2)(d): an individual covered by subparagraph (a)(ii) or (b)(ii) is at risk from the eligible data breach.Legal requirement — s 26WE(2)(d). Not a census of YOUR individuals.8 September 2026
Remedial-action exceptions 26WF: if the entity takes action before the access or disclosure results in serious harm (or, for loss, before unauthorised access or disclosure occurs) and, as a result, a reasonable person would conclude that serious harm would not be likely, the access, disclosure, or loss is not, and is taken never to have been, an eligible data breach.Legal requirement — s 26WF. This page does not find that YOUR remedial action prevented likely serious harm.8 September 2026
My Health Records carve-outs 26WD: if an unauthorised access, unauthorised disclosure, or loss has been, or is required to be, notified under s 75 of the My Health Records Act 2012, this Part does not apply in relation to that access, disclosure, or loss.Legal requirement — s 26WD. A different instrument. This page does not apply s 75.8 September 2026

Likely serious harm — s 26WG relevant matters, not YOUR score

Section 26WG lists matters to have regard to when determining whether a reasonable person would conclude that an access or disclosure would be likely, or would not be likely, to result in serious harm. The list is the Act. OAIC restatements of 'serious harm' are OAIC guidance, not the Act. This page does not score likely serious harm on YOUR facts. Last verified 8 September 2026. Not legal advice.

s 26WG relevant matters (legal requirement only if the Act applies — not YOUR assessment; not legal advice)
MatterWhat the text saysKind of textLast verified
(c) kindthe kind or kinds of informationLegal requirement — s 26WG(c).8 September 2026
(d) sensitivitythe sensitivity of the informationLegal requirement — s 26WG(d).8 September 2026
(e)–(f) security measureswhether the information is protected by one or more security measures; if so, the likelihood that any of those security measures could be overcomeLegal requirement — s 26WG(e)–(f). This page does not find that YOUR encryption holds.8 September 2026
(g) who obtained itthe persons, or the kinds of persons, who have obtained, or who could obtain, the informationLegal requirement — s 26WG(g).8 September 2026
(h) security technologyif a security technology or methodology was used and was designed to make the information unintelligible or meaningless to persons not authorised to obtain it: the likelihood that persons who have obtained or could obtain the information, and who have or are likely to have the intention of causing harm, have obtained or could obtain information or knowledge required to circumvent that technology or methodology. Note: if the technology is encryption, an encryption key is an example of information required to circumvent it.Legal requirement — s 26WG(h) and its note. Not a finding about YOUR key management.8 September 2026
(i)–(j) harm and other mattersthe nature of the harm; any other relevant mattersLegal requirement — s 26WG(i)–(j). 'Serious harm' is not defined in the Part this page fetched.8 September 2026
OAIC restatement of serious harmOAIC Data Breach Preparation and Response Part 4 (updated February 2025): 'likely to occur' means more probable than not (rather than possible); 'serious harm' is not defined in the Privacy Act; in the context of a data breach, serious harm to an individual may include serious physical, psychological, emotional, financial, or reputational harm. That paragraph is OAIC guidance, not s 26WG.OAIC guidance, not the Act. This page does not apply those examples to YOUR facts.8 September 2026

Two clocks — 30-day assessment is not a 30-day notify deadline

Suspect and believe are different verbs in the Act. Section 26WH is the assessment duty when an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach, and is not aware that there are reasonable grounds to believe that the relevant circumstances amount to one. Sections 26WK and 26WL fire when the entity is aware that there are reasonable grounds to believe that there has been an eligible data breach. Keep those two clocks distinct. The 30-day window is not GDPR Article 33(1) 72 hours. Last verified 8 September 2026. Not legal advice.

Assessment versus notification (legal requirement only if the Act applies — not YOUR start time; not legal advice; does not start a clock)
ClockTrigger as the section states itTiming as the section states itKind of textLast verified
Assessment — s 26WHThe entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach of the entity, and is not aware that there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity.Carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach, and take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware of those grounds to suspect (s 26WH(2)).Legal requirement — s 26WH. 30 days is the assessment outer mark. It is not a 30-day notification deadline.8 September 2026
Statement to the Commissioner — s 26WKThe entity is aware that there are reasonable grounds to believe that there has been an eligible data breach of the entity.Prepare a statement that complies with s 26WK(3) and give a copy to the Commissioner, as soon as practicable after the entity becomes so aware (s 26WK(2)).Legal requirement — s 26WK. 'As soon as practicable' is not converted here into 30 days, 72 hours, or any other number.8 September 2026
Notify individuals — s 26WLThe entity is aware that there are reasonable grounds to believe that there has been an eligible data breach, and has prepared a s 26WK(3) statement relating to it.Comply with s 26WL(2) as soon as practicable after the completion of the preparation of the statement (s 26WL(3)). If practicable, notify the contents to each individual to whom the information relates, or each individual at risk; otherwise publish the statement on the entity's website (if any) and take reasonable steps to publicise its contents.Legal requirement — s 26WL. Individual notice is not the Commissioner's copy, and not GDPR Article 34.8 September 2026
OAIC 30 calendar daysOAIC Part 4: an entity must take all reasonable steps to complete the assessment within 30 calendar days after the day the entity became aware of the grounds that caused it to suspect an eligible data breach. The Commissioner expects that wherever possible entities treat 30 days as a maximum time limit and endeavour to complete the assessment in a much shorter timeframe.That '30 calendar days' and 'maximum time limit' restatement is OAIC guidance, not the words of s 26WH(2)(b), which says '30 days'.OAIC guidance, not the Act. Do not paste it onto ss 26WK–26WL.8 September 2026

What the statement must set out — s 26WK(3)

Section 26WK(3) is the content of the statement given to the Commissioner and, via s 26WL, notified to individuals. This page does not draft YOUR statement. Last verified 8 September 2026. Not legal advice.

  • Legal requirement — s 26WK(3): identity and contact details of the entity; a description of the eligible data breach that the entity has reasonable grounds to believe has happened; the particular kind or kinds of information concerned; recommendations about the steps that individuals should take in response.
  • Legal requirement — s 26WK(4): if the entity has reasonable grounds to believe the same access, disclosure, or loss is an eligible data breach of one or more other entities, the statement may also set out the identity and contact details of those other entities.
  • Legal requirement — s 26WL(4): if the entity normally communicates with a particular individual using a particular method, the notification to that individual may use that method. That sentence does not limit s 26WL(2)(a) or (b).
  • OAIC materials (Report a data breach page, fetched 8 September 2026): to notify the OAIC, you should use the online Notifiable Data Breach form at webform.oaic.gov.au (entitytype=DBN). That form URL is OAIC materials about how to give the Commissioner a copy, not a rewrite of s 26WK. This product does not submit that form. A named human still submits.

Exceptions — other entities, enforcement, secrecy, Commissioner declaration

Part IIIC names exceptions. Mapping an exception is not a finding that it applies to YOU. Last verified 8 September 2026. Not legal advice.

  • Jointly held information — assessment: s 26WJ. If an entity complies with s 26WH in relation to an eligible data breach of the entity, and the same access, disclosure, or loss is an eligible data breach of one or more other entities, s 26WH does not apply in relation to those other entities' breaches.
  • Jointly held information — notification: s 26WM. If an entity complies with ss 26WK and 26WL, those sections do not apply in relation to the other entities' breaches of the same access, disclosure, or loss.
  • Enforcement related activities — s 26WN: if the entity is an enforcement body and its chief executive officer believes on reasonable grounds that compliance with s 26WL would be likely to prejudice one or more enforcement related activities conducted by or on behalf of the enforcement body, paragraph 26WK(3)(d) and s 26WL do not apply. The statement to the Commissioner can still be required.
  • Secrecy provisions — s 26WP: a Commonwealth secrecy provision (other than this Act) that prohibits or regulates use or disclosure. ss 26WK(2) and 26WL do not apply to the extent of inconsistency, with a separate rule for prescribed secrecy provisions.
  • Commissioner declaration — s 26WQ: the Commissioner may declare that ss 26WK and 26WL do not apply, or that notification is delayed for a specified period, if satisfied that it is reasonable in the circumstances. OAIC Part 4 says the Commissioner expects declarations under s 26WQ only in exceptional cases. That 'exceptional cases' sentence is OAIC guidance, not s 26WQ.
  • Commissioner direction — s 26WR: if the Commissioner is aware there are reasonable grounds to believe there has been an eligible data breach, the Commissioner may direct the entity to prepare a statement, give a copy to the Commissioner, and notify individuals or publicise. Comply as soon as practicable after the direction is given (s 26WR(10)).

Reform status — what is in force on 8 September 2026

Do not treat a Bill as law. Do not treat an uncommenced provision as commenced. Last verified 8 September 2026 against the Privacy Act 1988 compilation no. 104 (4 June 2026) and the Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) commencement table on legislation.gov.au.

Privacy Act reform actually fetched (not a complete reform map; not legal advice)
MeasureStatus as fetchedKind of textLast verified
NDB scheme (Part IIIC Divisions 1–4)In force. Eligible data breach, 30-day assessment, statement to the Commissioner, and individual notice are unchanged in the compilation this page fetched as the core NDB duties (ss 26WE, 26WH, 26WK, 26WL).Legal requirement — Privacy Act 1988 compilation no. 104, 4 June 2026.8 September 2026
POLA 2024 Schedule 1 Part 7 — eligible data breach declarationsIn force from 11 December 2024 (POLA 2024 s 2 table item 2: Schedule 1 Parts 1 to 7, the day after Royal Assent on 10 December 2024). Inserted Part IIIC Division 5 (ss 26X–26XH): the Minister may make an eligible data breach declaration authorising collection, use, and disclosure of personal information to prevent or reduce a risk of harm from misuse following unauthorised access or disclosure. That is not a rewrite of the s 26WE threshold and not a new notification clock.Legal requirement — POLA 2024 Schedule 1 Part 7, commenced 11 December 2024. In compilation no. 104.8 September 2026
POLA 2024 Schedule 2 — statutory tort for serious invasions of privacyIn the Privacy Act as Schedule 2 in compilation no. 104 (4 June 2026). POLA 2024 s 2 table item 8: Schedule 2 commences on a day to be fixed by Proclamation, or if not within 6 months after Royal Assent, the day after that 6-month period — 10 June 2025. Compilation no. 103 (10 June 2025) already included Schedule 2 items 1–10. The tort is a cause of action for a serious invasion of privacy. It is not the NDB scheme and does not replace ss 26WK–26WL.Legal requirement — Privacy Act Schedule 2, in force in compilation no. 104. Not Part IIIC notification.8 September 2026
POLA 2024 Schedule 1 Part 15 — automated decisions and privacy policiesNot commenced as of 8 September 2026. POLA 2024 s 2 table item 7: Schedule 1 Part 15 commences the day after the end of the period of 24 months beginning on Royal Assent — 10 December 2026. Compilation no. 104's 'About this compilation' states that the effect of uncommenced amendments is not shown in the text of the compiled law.Enacted, not yet commenced. Do not treat APP automated-decision disclosure as a current NDB duty.8 September 2026
Children's Online Privacy Code (s 26GC)s 26GC (development of APP codes by the Commissioner — Children's Online Privacy Code) is in compilation no. 104. POLA 2024 timing toward 10 December 2026 for related APP-code work is in-flight. A code that is not registered is not a substitute for Part IIIC.In-flight / code-development duty. Not an NDB notification clock. Last-verified 8 September 2026.8 September 2026
Further Privacy Act review (small-business exemption, 'fair and reasonable')This page did not fetch an enacted second-tranche statute changing the small-business exemption in s 6D or inserting a 'fair and reasonable' APP test. A government review proposal is not law. Do not treat it as a current NDB duty.Not enacted as of last-verified 8 September 2026. Not a Bill treated as law.8 September 2026

PIPEDA, HIPAA, SEC Item 1.05, and GDPR 72 hours do not discharge the NDB scheme

Part IIIC is not GDPR Article 33. It is not PIPEDA s. 10.1. It is not HIPAA 45 CFR §§164.400–414. It is not Form 8-K Item 1.05. Filing one does not discharge the others. That is a strategy note, not a determination that any named instrument applies to YOU. Last verified 8 September 2026. Not legal advice.

  • GDPR Article 33(1) 72 hours from having become aware does not discharge ss 26WK–26WL. The 30-day assessment window in s 26WH is not 72 hours. The GDPR breach-notification guide on this site is Articles 33–34.
  • HIPAA 60 calendar days from discovery does not discharge the NDB scheme. HIPAA discovery is not s 26WH awareness of grounds to suspect. The HIPAA breach-notification guide on this site.
  • SEC Form 8-K Item 1.05 does not discharge the NDB scheme. Item 1.05 is a registrant material-cybersecurity-incident disclosure. Clock-start there is a materiality determination, not an eligible-data-breach finding. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106.
  • PIPEDA s. 10.1 'as soon as feasible' after the organization determines that the breach has occurred is a different federal statute. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64.
  • State and Territory health or public-sector schemes are different instruments. Section 3 saves certain State and Territory laws. This page treats Part IIIC. It does not map those State or Territory schemes. s 26WD is the My Health Records s 75 exception this page fetched.
  • Civil-penalty maxima this page fetched: s 13(4A) — contravention of ss 26WH(2), 26WK(2), 26WL(3), or 26WR(10) is taken to be an act that is an interference with the privacy of an individual. s 13G (serious interference) maxima: not more than $2,500,000 for a person other than a body corporate; for a body corporate, the greatest of $50,000,000, 3 times the reasonably attributable benefit, or 30 per cent of adjusted turnover during the breach turnover period. s 13H: must not exceed 2,000 penalty units. s 13K(2): a s 26WK statement that does not comply with s 26WK(3) — must not exceed 200 penalty units. Those are maxima, not typical OAIC fines, not a typical incident-cost figure, and not YOUR penalty. This page does not convert penalty units into dollars. The failure-to-report-consequences page on this site is the maxima table.

Checklist

This is a question list, not a filing, not an eligible-data-breach finding, and not YOUR statement. Walk it with counsel. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The supporting-evidence page on this site is the evidentiary record.

  • Does the Privacy Act apply, including via an Australian link in s 5B? Are you an APP entity, credit reporting body, credit provider, or file number recipient as s 26WE(1) uses those terms? This page does not decide. The obligation-map `au_privacy_app` in-scope mark is not that determination.
  • Was there unauthorised access to, unauthorised disclosure of, or loss of, personal information the entity holds? Counsel applies s 26WE(2). This page does not.
  • Would a reasonable person conclude that the access or disclosure would be likely to result in serious harm, having regard to s 26WG? This page does not find likely serious harm on YOUR facts.
  • Did remedial action under s 26WF prevent likely serious harm, or (for loss) prevent unauthorised access or disclosure? This page does not find that it did.
  • If you only suspect: s 26WH — reasonable and expeditious assessment, all reasonable steps to complete it within 30 days of becoming aware of grounds to suspect. That is not a 30-day notify clock. This page does not start it.
  • If you believe (reasonable grounds): s 26WK statement to the Commissioner as soon as practicable, and s 26WL individual notice as soon as practicable after the statement is prepared. Content as s 26WK(3) states. This product does not prepare or lodge that statement.
  • Do overlapping instruments also sit on the facts — GDPR Articles 33–34, HIPAA Subpart D, Form 8-K Item 1.05, a US-state statute? Filing one does not discharge Part IIIC.
  • Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Eligible data breachs 26WE(2): unauthorised access or unauthorised disclosure, or loss where unauthorised access or disclosure is likely, AND a reasonable person would conclude that the access or disclosure would be likely to result in serious harm. Subject to s 26WF.
Likely to result in serious harms 26WE(2) plus s 26WG relevant matters. This page does not score it. OAIC's 'more probable than not' restatement is OAIC guidance, not the Act.
30-day assessment windows 26WH(2)(b): all reasonable steps to ensure a reasonable and expeditious assessment is completed within 30 days after becoming aware of grounds to suspect. Not a 30-day notification deadline. Not GDPR 72 hours.
As soon as practicables 26WK(2)(b) (statement to the Commissioner after becoming aware of reasonable grounds to believe) and s 26WL(3) (individual notice after the statement is prepared). Not converted here into a number of hours or days.
APP entityAn agency or organisation the APPs bind. s 26WE(1)(a) is the NDB attachment for APP 11.1 security obligations. This page does not determine that YOU are one.
Australian links 5B extra-territorial operation, including carrying on business in Australia or an external Territory (s 5B(3)). The which-jurisdictions-apply page on this site is that class. Not a GDPR Article 3 test.
OAIC guidanceOAIC Notifiable Data Breaches pages and the Data Breach Preparation and Response Part 4 guide. Not Part IIIC. This page labels them when it relies on them.
Eligible data breach declarations 26X: a Ministerial declaration, in force from 11 December 2024, about collection, use, and disclosure after an eligible data breach. Not the s 26WE threshold and not YOUR notification.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that the Privacy Act applies, does not determine that the organisation is an APP entity, does not run an eligible-data-breach assessment, does not find likely serious harm, does not start a 30-day assessment clock, does not convert 'as soon as practicable' into a number, and does not file with the OAIC. None of the surfaces below is a s 26WK statement, a s 26WL individual notice, or an instruction to submit a filing. The product does not have an NDB reporting ladder and does not auto-file to the OAIC form.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not an NDB clock, not a 30-day assessment window, not an OAIC submission, and not an eligible-data-breach assessment. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.

Australian Privacy Principles is a bundled framework in the catalog (`au_privacy_app`, labelled Privacy Act 1988 (Cth) — 13 Australian Privacy Principles + NDB scheme (starter subset), not the full Act, and not Part IIIC as a filing pack). That framework is internal-tester-only until reviewed; it is not a customer-visible NDB filing pack. The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that the organization is an APP entity, not a determination that the Privacy Act or the NDB scheme applies, and not a legal opinion that Part IIIC has been triggered. The starter control set includes a manual-evidence 'NDB scheme' row titled that eligible data breaches are assessed and notified to the OAIC and affected individuals. That row is not an eligible-data-breach assessment, not a s 26WK statement, and not an OAIC submission. A recorded `australiaOperations` profile flag is an input to obligation-tiering, not a s 5B Australian-link finding. The cyber risk register lives under Security. None of those surfaces files with the OAIC, notifies an individual, or starts 30 days.

Primary sources (last verified 8 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Privacy Act 1988 compilation no. 104 (compilation date 4 June 2026; C2026C00227; includes amendments up to Act No. 75, 2025) on legislation.gov.au is a legal requirement only if the Act applies. Part IIIC is ss 26WA–26XH. s 26WE is eligible data breach. s 26WF is remedial action. s 26WG is likely-serious-harm relevant matters. s 26WH is the 30-day assessment. ss 26WK–26WL are the statement to the Commissioner and individual notice. s 13(4A) treats contravention of ss 26WH(2), 26WK(2), 26WL(3), or 26WR(10) as an interference with privacy. s 13G, s 13H, and s 13K are civil-penalty maxima, not typical fines. s 5B is extra-territorial operation. s 3 saves certain State and Territory laws. Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) s 2 is the commencement table this page fetched: Schedule 1 Parts 1 to 7 (including Part 7 eligible data breach declarations) commenced 11 December 2024; Schedule 2 (statutory tort) is in compilation no. 104; Schedule 1 Part 15 (automated decisions) commences 10 December 2026 and is not shown as commenced in compilation no. 104. OAIC About the Notifiable Data Breaches scheme, When to report a data breach, Report a data breach, and Data Breach Preparation and Response Part 4 (updated February 2025) are OAIC materials, not the Act. The OAIC online Notifiable Data Breach form this page fetched is webform.oaic.gov.au/prod?entitytype=DBN&layoutcode=DataBreachWF. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. The India DPDP / CERT-In jurisdiction guide on this site. A dedicated UAE/Dubai guide is not on this site yet. Naming them is not a link. Not legal advice.

The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table of clocks. The supporting-evidence page on this site is the evidentiary record. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64.

Frequently asked questions

When must you notify an eligible data breach?

If Part IIIC applies and the entity is aware that there are reasonable grounds to believe that there has been an eligible data breach: prepare a s 26WK(3) statement and give a copy to the Commissioner as soon as practicable (s 26WK(2)), and notify individuals as soon as practicable after that statement is prepared (s 26WL(3)). If the entity only suspects, s 26WH requires a reasonable and expeditious assessment, with all reasonable steps to complete it within 30 days — that 30-day window is assessment, not notification. Last verified 8 September 2026. Not legal advice.

Is this legal advice?

No. It is an Australia NDB jurisdiction guide distilled from Privacy Act 1988 Part IIIC this page fetched on legislation.gov.au (compilation no. 104, 4 June 2026) and from OAIC pages labelled as OAIC materials, not the Act. Whether the Privacy Act applies, whether you are an APP entity, whether an eligible data breach occurred, whether serious harm is likely, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file with the OAIC?

No. The signed-in app does not file with the OAIC, does not send individual notices, does not run an eligible-data-breach assessment, does not start a 30-day assessment clock, and does not have an NDB reporting ladder. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not an NDB clock and not an OAIC submission. The obligation map is frameworks marked in-scope, not a determination that the org is an APP entity. A named human still submits.

Is the 30-day window a notification deadline?

No. s 26WH(2)(b) is the time to carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach, taking all reasonable steps to complete that assessment within 30 days of becoming aware of grounds to suspect. Notification under ss 26WK–26WL is as soon as practicable after becoming aware there are reasonable grounds to believe. That is not a 30-day notify clock and not GDPR 72 hours. OAIC's '30 calendar days' restatement is OAIC guidance, not the Act. Not legal advice.

Does a GDPR Article 33 notice discharge the NDB scheme?

No. Part IIIC is not GDPR Article 33. HIPAA Subpart D, SEC Form 8-K Item 1.05, and PIPEDA s. 10.1 also do not discharge the NDB scheme. Filing one instrument is not filing the others. That is a strategy note, not a determination that any named statute applies to YOU. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.