Notifiable Data Breaches
What Boards Need to Know

Under the NDB scheme, organisations covered by the Privacy Act must assess suspected breaches and notify the OAIC and affected people when serious harm is likely. Here’s how it works, and how to be ready before it happens.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

How the NDB Scheme Works

An eligible data breach happens when personal information is accessed, disclosed or lost without authorisation, it is likely to result in serious harm to the people affected, and the harm hasn’t been prevented by remedial action.

If you suspect one, you must take reasonable steps to carry out an assessment, generally within 30 days. If it is an eligible breach, you must notify the OAIC and affected individuals as soon as practicable. Queensland government agencies have had their own mandatory scheme since 1 July 2025, and local councils since 1 July 2026.

In 2025 the OAIC received a record 1,205 notifications. Business and professional associations were the 4th most-notified sector.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

The Assessment

Depends on

the Technical

Facts

The Assessment Depends

on the Technical Facts

The Assessment Depends

on the Technical Facts

Whether a breach is notifiable turns on questions only a technical investigation can answer: what did the attacker reach, what data was exposed, for how long, and has the access been closed? Without those facts, organisations either over-notify in a panic or miss deadlines while they guess.

When something happens, we contain it, preserve evidence, find the way in and document what personal information the affected systems could access, so your advisers can make the call. Before anything happens, our audit finds the weaknesses and checks you could actually answer those questions.

We provide the technical facts. Decisions about notification belong to you and your legal advisers.

Smiling mature confident professional executive manager at office.

Be Ready

Before It

Happens

Be Ready Before

It Happens

Be Ready Before

It Happens

Know What You Hold

You can’t assess a breach if you don’t know what personal information each system holds. We map it before you need it.

Logs That Answer Questions

Access logs, file monitoring and backups decide whether you can tell who saw what. We check they exist and work.

A Plan for Day One

Who calls whom, who preserves evidence and who decides. A short, tested response plan saves days when it matters.

0

Data Breaches Notified to the OAIC in 2025

0

Days to Assess a Suspected Eligible Breach

0

Association Breaches Notified in 2025

0 %

Of Australians Concerned About Data Breaches (2026)

How It Works

We identify what personal information your website, portal and integrations hold, and where it flows.

Young African businessman looking at data on computer screen

Step 2: Test Your

Readiness

We check logging, monitoring, backups and access so a suspected breach can actually be assessed.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Close

the Gaps

You get a prioritised report, and we can fix the gaps and help write your response plan.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

What You Can Expect

When a Breach Hits

Prepared

Unprepared

First Hour

With Us

Clear roles and a call list

With Them

Scrambling for passwords

Evidence

With Us

Logs and backups preserved

With Them

Overwritten during clean-up

Scope

With Us

Known data flows to check

With Them

Guessing what was exposed

Access

With Us

Attacker locked out quickly

With Them

Still inside while you debate

Assessment

With Us

Facts ready within days

With Them

Weeks of uncertainty

Vendors

With Us

Contracts say who notifies whom

With Them

Finger-pointing

Notification

With Us

Accurate and timely

With Them

Late, or too broad

Members

With Us

Clear, honest communication

With Them

Rumours on social media

Regulator

With Us

Able to show reasonable steps

With Them

No record of what was done

Afterwards

With Us

Root cause fixed

With Them

Same hole, next month

Frequently Asked Questions

Unauthorised access, disclosure or loss of personal information that is likely to result in serious harm to any of the people it relates to, where remedial action hasn’t removed that likelihood.

You must take reasonable steps to complete an assessment within 30 days of becoming aware of grounds to suspect an eligible breach. If it is eligible, you notify as soon as practicable.

The OAIC and the individuals at risk of serious harm. Queensland government agencies and councils notify the Office of the Information Commissioner under the state scheme. Get legal advice on your obligations.

It can be. If personal information you hold was affected, you may have obligations even when a third party was at fault. Contracts should say who assesses and who notifies.

Yes. We contain the incident, preserve evidence, find how attackers got in and document what the affected systems could access, so your advisers can decide on notification.

Be Ready Before a Breach, Not After