Notifiable Data Breach Scheme

The Notifiable Data Breaches (NDB) scheme under Part IIIC of theĀ Privacy Act 1988 (Privacy Act) established requirements for entities in responding to data breaches.

All agencies and organisations in Australia that are covered by the Privacy Act will be required to notify individuals whose personal information is involved in a data breach that is likely to result in “serious harm”, as soon as practicable after becoming aware of a breach.

Who must comply with the NDB scheme?

The NDB scheme applies to agencies and organisations that the Privacy Act requires to take steps to secure certain categories of personal information. This includes Australian Government agencies, businesses and not-for-profit organisations with an annual turnover of $3 million or more, credit reporting bodies, health service providers, and TFN recipients, among others.

For more information please read this article from ZDNet

NDB Resources

The Office of the Australian Information Commissioner has provided detailed guidance on compliance together with a raft of NDB-related resources.