The Notifiable Data Breach scheme: the 30-day rule small businesses miss
19 August 2026 · 4 min read
The Notifiable Data Breach (NDB) scheme is triggered by any unauthorised access to or disclosure of personal information that's likely to cause serious harm — not just a hack. Accidentally emailing a client's quote and contact details to the wrong recipient, or a lost phone with unencrypted client photos, can trigger the same 30-day obligation as an actual cyberattack.
What actually starts the clock
Once a business is aware of a suspected breach, it has 30 days to assess whether it's likely to cause serious harm to the people affected. Small operators often assume the scheme only applies to businesses that get "properly hacked" — the trigger is broader than that, and it applies regardless of business size if the harm test is met (this is one of the areas where the small-business exemption doesn't fully shield you, since it's tied to the nature of the incident, not turnover).
What counts as "serious harm"
Financial loss, identity theft risk, and reputational or physical harm all count. A quote export with names, phone numbers and job addresses sent to the wrong person is a real example that can meet the threshold — it's not limited to financial or health information.
What to do if it happens
- Contain it immediately — recall the email if possible, revoke access, stop the spread.
- Assess within 30 days whether serious harm is likely, documenting the reasoning either way.
- If serious harm is likely, notify the OAIC and the individuals affected, with what happened and what you're doing about it.
- Fix the process gap that caused it, not just the individual incident.
This is exactly the kind of thing worth having a plain-English answer ready for before it happens, not scrambling to work out during the 30-day clock.
Fixed-price Privacy Act compliance for AU small business — including a breach-response plan you can actually follow.
RELATED
Australia's Privacy Act changes: what small businesses actually need to do before 10 December 2026
"We're too small for privacy law" stops being reliably true this year. Here's what changes and what doesn't.
ReadDo sole traders need a privacy policy in Australia?
"I'm under $3 million turnover" is true for almost every sole trader. It's not the whole answer anymore.
ReadWANT THIS APPLIED TO YOUR BUSINESS?
15 minutes is enough to know if there's a real gap worth closing.
BOOK YOUR FREE AI AUDIT CALL