Notifiable Data Breach scheme
The Australian Privacy Act scheme that obliges APP entities to assess suspected data breaches and notify the OAIC and affected individuals when serious harm is likely. The framework AI incident response runs into when personal information is involved.
What it is
The Notifiable Data Breach (NDB) scheme sits in Part IIIC of the Privacy Act 1988, introduced by the Privacy Amendment (Notifiable Data Breaches) Act 2017 and in force from 22 February 2018. It applies to APP entities and obliges them to assess suspected data breaches and to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals when an eligible data breach is likely to result in serious harm.
What counts as an eligible data breach
An eligible data breach is unauthorised access to or disclosure of personal information, or loss of personal information in circumstances where unauthorised access or disclosure is likely, where a reasonable person would conclude the breach is likely to result in serious harm to one or more individuals. All three elements have to be present. A breach that does not put information at meaningful risk, or one that does not reach the serious harm threshold, is not eligible.
The assessment window
From the moment an APP entity becomes aware that there are reasonable grounds to suspect an eligible data breach has occurred, the entity has thirty days to complete an assessment and determine whether the breach is eligible. The entity must take all reasonable steps to complete the assessment within that window. If the assessment confirms an eligible data breach, notification has to follow as soon as practicable.
What notification requires
The entity prepares a statement to the OAIC describing the identity of the entity, a description of the breach, the kinds of information involved, and the recommendations the entity is making to affected individuals about steps they can take. The same content goes to the affected individuals, either directly to those known to have been affected, or by publishing the statement publicly where direct contact is not practicable. The OAIC publishes statistics on notifications quarterly.
Exceptions and overlaps
There are a small number of exceptions. Remedial action that mitigates the likely serious harm before the assessment is complete can mean the breach does not become eligible. Where another agency or organisation is notifying on the same multi-party breach, the entity does not have to duplicate. Law enforcement and secrecy provisions can carve out certain notifications. The scheme also intersects with other obligations, including APRA's CPS 234 information security standard for regulated financial entities, the My Health Records Act for health information, and sector-specific notification rules.
Why it matters for AI incidents
The NDB scheme is well-established and most APP entities have an incident response capability built around it. AI incidents introduce a new shape of trigger. A model behaving in a way that leaks personal information into outputs, a vendor pushing a model update that exposes data to an unintended audience, an agent taking an action that discloses information beyond the authorised recipient. Each of these can constitute an eligible data breach, and the thirty-day assessment clock starts the moment the entity becomes aware. AI incident workflows that do not consider NDB obligations from the outset can find themselves running into the window late.
How Aicura supports work against it
Aicura uses the NDB scheme as a guidance source when reviewing incident response policies. The guidance the scanner returns is shaped by the scheme's obligations, including the eligibility threshold, the assessment timeline, the notification content, and the exception pathways. In Aicura's incident response workflow, where an incident involves personal information and the assessment indicates the threshold has been met, Aicura drafts the OAIC notification from the incident context and the AI Register entries for the affected systems. Your General Counsel and any external counsel still review and sign off the notification before it is sent. Aicura supports the work. The regulatory decision remains with your team.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.