The Privacy Act & Notifiable Data Breaches Scheme

The Privacy Act 1988 is Australia’s primary law governing how organisations handle personal information. It is built around the 13 Australian Privacy Principles (APPs), which cover everything from how you collect and use data to how you secure it and allow people to access it.

Who it applies to

The Act applies to Australian Government agencies and to businesses with an annual turnover of more than $3 million, as well as some smaller organisations regardless of size — including health service providers, businesses that trade in personal information, and contractors handling government data. Even where it doesn’t strictly apply, following the APPs is good practice and a growing customer expectation.

The Notifiable Data Breaches scheme

Under the Notifiable Data Breaches (NDB) scheme, organisations covered by the Act must notify both the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach occurs — that is, unauthorised access to or loss of personal information that is likely to result in serious harm. You need a process to assess suspected breaches quickly and notify within the required timeframe.

What you should have in place

Penalties for serious or repeated privacy breaches have increased significantly in recent years, making readiness more important than ever. CyberSafeCheck’s assessment includes Privacy Act and NDB readiness so you can spot gaps early. See also the Essential Eight and ISO 27001.

Go deeper: read our breakdown of all 13 Australian Privacy Principles — what each part means in plain English, and the risk of leaving it unaddressed.

Check your Privacy Act readiness

Take the free CyberSafeCheck assessment and see how your business measures up — instant score, compliance check and a prioritised action plan in about five minutes.