Skip to content
Pylon Digital

Glossary

Notifiable Data Breaches (NDB) scheme

The Notifiable Data Breaches (NDB) scheme is the part of the Privacy Act 1988 that requires covered organisations to tell affected individuals and the Office of the Australian Information Commissioner (OAIC) about an eligible data breach. A breach is eligible when personal information is lost, or accessed or disclosed without authorisation; this is likely to result in serious harm to someone; and the organisation cannot prevent that likely harm with remedial action. An organisation that suspects an eligible breach must take all reasonable steps to assess it within 30 days, then notify as soon as practicable. The scheme has applied since 22 February 2018, including to tax file number recipients for breaches involving TFN information.

Also called NDB scheme, mandatory data breach notification

Last updated:

Example

In an accounting firm

A staff member at a 25-person accounting firm pastes a client's tax return, including their tax file number, into a personal AI account. The firm treats it as a suspected breach: it records what was shared, asks the provider to delete it and assesses within 30 days whether serious harm is likely. If it is, the firm must notify the client and the OAIC.

Where is the official guidance?

The OAIC publishes the rules, worked examples and the online notification form. Start with About the Notifiable Data Breaches scheme, then read Part 4 of the OAIC’s data breach preparation and response guide, which explains the 30-day assessment and the ways to notify individuals.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call