Data breach response plan in Australia: the first hours, days and 30 days (NDB scheme)
Build a data breach response plan for Australia: the first hours, days and 30 days under the NDB scheme, team roles, working with vendors and a template.
On this page
- The OAIC's four steps: contain, assess, notify, review
- What counts as an eligible data breach?
- Your data breach response plan timeline in Australia
- Who does what: the response team
- What the statement and notifications must contain
- Working with IT vendors during a breach
- Other reports you may need to make
- What may change: the 72-hour proposal
- A template outline for your plan
- What to do next
A data breach response plan tells your team what to do when personal information is exposed: contain it in the first hours, assess it over the following days and, under Australia's Notifiable Data Breaches (NDB) scheme, finish your assessment within 30 days at the latest and notify the OAIC and affected people as soon as practicable if the breach is eligible. This guide sets out that timeline, the roles you need, how to work with IT vendors, and an outline for your own plan.
This article is general information, not legal advice. It is part of our guide to healthcare software development in Australia, but the steps apply to any organisation covered by the Privacy Act.
The OAIC's four steps: contain, assess, notify, review#
The OAIC's data breach response guidance is built around four steps.
- Contain. Stop the unauthorised practice, recover the records or shut down the system, while being careful not to destroy evidence that could help identify the cause.
- Assess. Gather the facts and evaluate the risks, including the type of personal information involved, the circumstances of the breach, the nature of the potential harm and whether remedial action can reduce it.
- Notify. Tell affected individuals and the Commissioner where required.
- Review. Learn from the incident, including a security review with root cause analysis, a prevention plan and updates to policies, training and service delivery partners.
The OAIC says the first three steps may be undertaken simultaneously or in quick succession, and in some cases notifying early makes sense before containment or assessment is finished. Your plan should not force a strict sequence.
What counts as an eligible data breach?#
Under the NDB scheme, a breach is eligible when three things are true:
- there is unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information;
- this is likely to result in serious harm to one or more individuals; and
- you have not been able to prevent the likely risk of serious harm with remedial action.
To judge serious harm, the Privacy Act points to matters such as the kind and sensitivity of the information, the security measures protecting it, who has or could obtain it, whether they are likely to intend harm, and the nature of the harm. Serious harm can be physical, psychological, emotional, financial or reputational. Health information is sensitive information, so a breach involving it will often weigh heavily in that assessment.
There is an important escape hatch. If you take remedial action quickly enough that the breach is no longer likely to result in serious harm, it is not an eligible data breach. Fast containment is not just good practice; it can change your legal position.
Your data breach response plan timeline in Australia#
When | Goal | Key actions | Lead |
|---|---|---|---|
First hour | Stop the harm spreading | Revoke access, isolate affected systems, reset credentials, preserve logs, start an incident log | IT or security lead |
First 24 hours | Understand the scope | Identify what data, whose and how much; check whether the attacker still has access; brief leaders; contact your insurer | Team leader and privacy officer |
Days 2 to 7 | Assess and reduce harm | Investigate, take remedial action, assess serious harm, draft the statement and notices | Privacy officer, legal, communications |
By day 30 at the latest | Finish the assessment | Complete and document the assessment; if eligible, notify as soon as practicable, not at day 30 | Team leader and legal |
After the incident | Improve | Find the root cause, fix it, update the plan, retrain, review vendors | Senior management |
Two clocks matter. If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware. The OAIC expects organisations to treat 30 days as a maximum and to finish much sooner where possible; if it takes longer, document the reasonable steps you took and why. Once you have reasonable grounds to believe an eligible data breach has occurred, you must prepare a statement and notify the Commissioner and affected individuals as soon as practicable.
Who does what: the response team#
The OAIC's guidance on preparing a response plan lists the roles a response team typically needs.
Role | Main responsibility |
|---|---|
Team leader | Leads the response and reports to senior management |
Project manager | Coordinates the team and tracks actions |
Privacy officer | Runs the NDB assessment and drafts the statement |
Legal support | Advises on obligations, notices and contracts |
Risk management | Handles insurance and wider business risk |
ICT or forensics | Contains the breach, preserves evidence, investigates |
Information and records management | Identifies which records were involved |
Human resources | Handles matters involving staff |
Media and communications | Prepares messages for individuals and the public |
In a small organisation one person may hold several roles. Name a deputy for each, and keep an up-to-date contact list that includes your IT vendors, insurer and lawyer, with after-hours numbers.
What the statement and notifications must contain#
If a breach is eligible, the statement to the Commissioner must set out:
- your organisation's identity and contact details;
- a description of the eligible data breach;
- the kind or kinds of information concerned; and
- recommendations about the steps individuals should take in response.
You then have three options for telling individuals: notify everyone whose information was involved, notify only those at risk of serious harm, or, where notifying people directly is not practicable, publish the statement on your website and take reasonable steps to publicise it.
The OAIC asks organisations to use its online Notifiable Data Breach form, and to attach a copy of the notification sent to individuals. It also says the more you tell it about the circumstances, your containment and any remedial action, the better it can respond. Write notices to individuals in plain English and make the recommended steps concrete, such as changing a password or watching for scam messages that use the leaked details.
Working with IT vendors during a breach#
Many breaches involve a vendor: a hosting provider, a software supplier or a managed IT firm. Where more than one organisation jointly holds the affected information, the NDB scheme lets one of them carry out the assessment and notification for all of them. The OAIC recommends that the entity with the most direct relationship with the individuals at risk should usually notify.
Settle these points in the contract, before anything goes wrong:
- how quickly the vendor must tell you about a suspected breach, and through whom;
- the vendor's duty to preserve logs and evidence, and to give you access to them;
- who leads containment on systems the vendor runs;
- who decides whether the breach is eligible and who notifies; and
- how costs are handled.
During an incident, keep one shared incident log, ask the vendor for a timeline of events and a list of affected systems and accounts, and make sure nobody rebuilds servers or deletes data before evidence is preserved. If the vendor is overseas, you generally remain accountable for how it handles the information under APP 8; our explainer on offshore developers and APP 8 covers what to put in place beforehand, and our vendor questions for health information include breach notification.
If we manage your servers, our part is the technical response: containing the incident, preserving evidence, investigating and restoring service. Decisions about eligibility and notification stay with you as the organisation that holds the information.
Other reports you may need to make#
The NDB scheme is not the only obligation that can apply. The OAIC suggests checking whether an incident triggers reporting obligations to other bodies, and consulting any investigating agency before making details public if law enforcement is involved. Three to check:
- Ransomware and cyber extortion payments. Under section 27 of the Cyber Security Act 2024, a business carrying on business in Australia with annual turnover of A$3 million or more in the previous financial year, or a responsible entity for a critical infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act 2018, must report a ransomware or cyber extortion payment within 72 hours, including a payment made on its behalf.
- My Health Record. Registered healthcare provider organisations, registered repository and portal operators and registered contracted service providers must notify the Australian Digital Health Agency (as System Operator) and the OAIC of My Health Record data breaches as soon as practicable; state and territory bodies notify the System Operator. A breach of information already downloaded into your local records falls under the NDB scheme instead.
- Cyber incident reporting. ASD's cyber.gov.au has a form for reporting cyber security incidents, including malicious cyber activity related to a data breach; fraud and cybercrime go through ReportCyber. Entities regulated under Part 2B of the Security of Critical Infrastructure Act 2018, whose asset classes include critical hospitals, may have to report critical cyber security incidents within 12 hours and other incidents with a relevant impact within 72 hours. The Australian Cyber Security Hotline is 1300 CYBER1 (1300 292 371).
What may change: the 72-hour proposal#
On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. Its data breach changes would, among other things:
- require an organisation to give the Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe there has been an eligible data breach, with an incomplete statement allowed at first in some circumstances;
- add the steps the organisation has taken or proposes to take in response to the matters the statement must include;
- require reasonable steps, as soon as practicable, to prevent or reduce harm once there are reasonable grounds to believe or suspect a data breach; and
- require practices, procedures and systems that enable an effective response.
It is a draft and may change. Even so, a plan that can produce a clear statement within three days is a good plan under today's law too.
A template outline for your plan#
Keep the plan short enough to use at 2am. The OAIC says a plan should explain what a data breach is, set out a strategy for containing, assessing and managing breaches, include a communications strategy, define staff roles, say how breaches are recorded, and include a post-breach review.
- Purpose and scope. What counts as a data breach, and which systems and data are covered.
- Response team and contacts. Names, deputies, after-hours numbers, vendors, insurer and lawyer.
- Detection and escalation. How staff report a suspected breach, and who is on call.
- Containment playbooks. Short checklists for common cases: a compromised account, a lost device, a misdirected email, ransomware and a breach at a vendor.
- Evidence preservation. Which logs and systems to preserve, and who is responsible.
- Assessment. The serious harm factors, a 30-day tracker and a decision record.
- Notification. Templates for the OAIC statement and for individual notices, and a list of other bodies to consider.
- Communications. Internal updates, customer messages and media handling.
- Vendor coordination. Contract terms, contacts and who notifies for jointly held information.
- Post-incident review. Root cause, actions, owners and plan updates.
- Testing. The OAIC says plans should be reviewed and tested regularly; a tabletop exercise each year is a sensible minimum.
Runbooks and rehearsals make the difference on the day. Our guide to incident response runbooks and post-mortems covers the operational side, and the Essential Eight explained covers the controls that make breaches less likely.
What to do next#
If you want help with the technical side of breach readiness, including monitoring, alerting and a rehearsed incident process for your servers, see our monitoring and incident response service.
Frequently asked questions
What is an eligible data breach?
Under the Privacy Act, an eligible data breach has three parts: unauthorised access to or disclosure of personal information, or a loss of it in circumstances where that is likely; the breach is likely to result in serious harm to one or more individuals; and you have not been able to prevent that likely risk of serious harm with remedial action. If quick remedial action removes the risk, the breach is not eligible.
How long do we have to notify the OAIC?
Under the current law, you must notify the OAIC and affected individuals as soon as practicable after you have reasonable grounds to believe an eligible data breach has occurred. If you only suspect one, you must take all reasonable steps to complete an assessment within 30 days. An exposure draft released on 31 August 2026 proposes a 72-hour deadline for the statement to the OAIC, but it is not law.
What must a data breach notification include?
The statement must include your organisation's identity and contact details, a description of the eligible data breach, the kinds of information involved, and recommendations about the steps individuals should take in response. You can notify every affected person, notify only those at risk of serious harm, or, where notifying people directly is not practicable, publish the statement on your website and take reasonable steps to publicise it.
Do we have to report a ransomware payment?
If your business carries on business in Australia with annual turnover of A$3 million or more in the previous financial year, or is a responsible entity for a critical infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act 2018, the Cyber Security Act 2024 requires you to report a ransomware or cyber extortion payment within 72 hours. This is separate from NDB notification.
Sources
- Part 2: Preparing a data breach response plan — Office of the Australian Information Commissioner — accessed 18 September 2026
- Part 3: Responding to data breaches — four key steps — OAIC — accessed 18 September 2026
- Part 4: Notifiable Data Breach (NDB) Scheme — OAIC — accessed 18 September 2026
- Report a data breach — OAIC — accessed 18 September 2026
- Ransomware payment and cyber extortion payment reporting — Australian Signals Directorate (cyber.gov.au) — accessed 18 September 2026
- Report a cyber security incident — Australian Signals Directorate (cyber.gov.au) — accessed 18 September 2026
- Guide to mandatory data breach notification in the My Health Record system — OAIC — accessed 18 September 2026
- Privacy reform: consultation on exposure draft legislation — Attorney-General's Department — accessed 18 September 2026
- Exposure draft: Privacy Amendment (Personal Data Protection) Bill 2026, Schedule 3 — Attorney-General's Department — accessed 18 September 2026
Facts in this article were last checked on 18 September 2026.
Inventure Engineering Team
Engineers at Inventure Technologies who build, host and run software for clients in Nepal and Australia. We write about what we do every day.
Keep reading
The Essential Eight explained for small and medium businesses
The Essential Eight explained for SMEs: the eight strategies, maturity levels zero to three, how they apply to web apps and servers, and first steps.
Read articleWeb application security checklist based on the OWASP Top 10
A practical OWASP Top 10 checklist for Node, Next.js and PHP teams: what each 2025 risk means, how it shows up in code, and how to test for it.
Read articleWant engineers who handle this for you?
We build, host and run software for teams in Nepal and Australia — with dedicated support on every plan.