The 30-day clock is not the deadline you think it is
The Notifiable Data Breaches scheme has a 30-day rule that almost everyone quotes and almost no one quotes correctly. It is not 30 days to tell anyone. It is 30 days to decide whether you have to.
What counts as an eligible data breach
Under Part IIIC of the Privacy Act, an eligible data breach exists when three things are all true: personal information your organisation holds has been accessed, disclosed or lost without authorisation; a reasonable person in your position would conclude the breach is likely to cause serious harm to at least one of the individuals involved; and you have not been able to prevent that harm through remedial action taken in time.
"Serious harm" is deliberately broad — physical, psychological, emotional, financial or reputational — and the OAIC expects a holistic assessment rather than a checklist. A leaked spreadsheet of names and emails is a different animal to a leaked spreadsheet of names, Medicare numbers and mental health notes. The kind of information involved does most of the work in that judgement.
Whether it applies to you
The scheme applies to Australian Government agencies and to organisations with annual turnover of more than $3 million. If you read that and assumed you are under the line and therefore exempt, read the second half of the sentence: several categories of smaller business are pulled in regardless of turnover, including
- health service providers, of any size
- businesses that trade in personal information
- credit reporting bodies and credit providers
- tax file number recipients — which covers most employers
- CDR-accredited and digital ID accredited entities
That "TFN recipients" line is the one people miss. If you run payroll, you hold tax file numbers, and holding tax file numbers is one of the carve-ins. A great many organisations that are confident the scheme does not apply to them are confident for the wrong reason — the same pattern we wrote about with the small business exemption and the new privacy tort. Two different schemes, the same mistake: assuming a headline exemption covers more than it does.
The clock nobody quotes correctly
Here is the version most people have in their head: you have 30 days to notify a data breach. Here is the actual rule: once you suspect you may have an eligible data breach, you have up to 30 calendar days to assess whether it actually is one. The Commissioner treats 30 days as a ceiling, not a target — the guidance explicitly says entities should aim to finish sooner, because the risk to individuals generally grows the longer the assessment runs.
Notification is a separate clock that starts only once you conclude the breach is eligible, and it runs on "as soon as practicable" rather than a fixed number of days. Practicable accounts for the time, effort and cost genuinely involved — it does not excuse delay for convenience. In practice, that means the true worst case is not 30 days. It is 30 days of assessment, immediately followed by notification with no further grace period, because you already knew it was coming.
This is also not the only clock that might be running. A breach involving a ransom payment can trigger the separate 72-hour reporting obligation under the Cyber Security Act — see If you pay a ransom, you have 72 hours — on top of, not instead of, your NDB obligations.
The three-step assessment
The OAIC's own guidance describes the assessment as three steps, and treating it as three discrete steps rather than one vague activity is what keeps it inside 30 days:
- Initiate. Decide that an assessment is needed and name who is running it. This sounds obvious and is the step most organisations skip — a suspected breach gets discussed informally for a week before anyone formally starts the clock, which eats directly into the 30 days.
- Investigate. Gather the facts: what information was involved, who accessed or received it, how, and what has already happened to it or could happen next.
- Evaluate. Weigh what you found against the serious harm test and reach a documented conclusion — eligible or not, with reasons. "We decided informally and moved on" is not a defensible position if the Commissioner ever asks.
The exception that can end it early
If you take remedial action fast enough that serious harm is no longer likely, the breach is not an eligible data breach and there is nothing to notify — even if it looked serious at the outset. The OAIC's own examples are mundane rather than dramatic: confirming an accidental recipient deleted an email without opening the attachment, or remotely wiping a lost phone before its content could plausibly be accessed.
This is the part worth taking seriously operationally, not just legally. The organisations that use this exception are the ones who can act inside hours — remote wipe already configured, the accidental recipient already identified and contacted, the log already pulled to prove nothing was opened. That capability has to exist before the incident, not get built during it.
What the notification has to say
If you do reach an eligible data breach, the statement to the OAIC and to affected individuals has to cover the same ground either way:
- your organisation's identity and contact details
- a description of the breach — what happened, and when
- the kind of information involved
- what you recommend affected individuals do in response
You are not required to notify the Commissioner first. Individuals can be told before the OAIC is, which matters when the practical priority is getting people to change a password or watch their account rather than completing a government form.
What to do before you need it
- Write down your turnover position, including whether any of the carve-in categories apply to you regardless of turnover — the same recorded position we recommend for the ransomware payment reporting threshold, kept in the same place.
- Name who runs an assessment and who has authority to conclude it, separate from whoever is handling the technical response. Assessing harm to individuals is a different skill from containing a breach, and one person is rarely good at both under pressure.
- Draft the notification statement as a template, with the four required elements already structured, so day 29 is filling in facts rather than writing from a blank page.
- Confirm your remedial-action capability actually works — remote wipe, access revocation, recall — before you need to prove you used it inside hours, not days.
- Rehearse the decision, not just the technical response. A tabletop exercise that includes "is this notifiable, and who decides" finds the gap in a meeting room instead of during an actual 30-day clock.
Ask whoever would run your response to name the two clocks and explain what starts each one. If you get back one clock and one number, that is the gap — and it costs nothing to close before an incident closes it for you.
This is general information about a Commonwealth scheme, not legal advice. Whether a specific incident is an eligible data breach depends on facts the Commissioner assesses case by case — get advice from a lawyer on an actual notification decision, not a website.
Know which clock is running before you need to
An assessment covers your incident response plan, notification readiness and the detection that gives you time to use the remedial-action exception instead of needing it to have already worked.