Notifiable Data Breaches: What Your SMB Must Do in the First 72 Hours
In Australia, the Notifiable Data Breaches (NDB) scheme sets clear rules for businesses experiencing a data breach. For Australian small and medium businesses, knowing your responsibilities within the first 72 hours is critical to minimise harm and comply with the law. Failing to act promptly can lead to significant penalties, reputational damage, and loss of customer trust. This article will guide you through the essential steps.

What is a notifiable data breach for an Australian small business?
A notifiable data breach occurs when personal information held by your business is lost or accessed without authorisation, and it's likely to result in serious harm to individuals. This includes situations like a lost laptop containing customer data or an employee's email account being compromised. Understanding the criteria for 'serious harm' is crucial for determining if notification is required. If you're unsure, it's always best to err on the side of caution and investigate thoroughly.
Why is immediate action critical within 72 hours?
The NDB scheme mandates that you notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, and generally within 72 hours of becoming aware of an eligible data breach. Prompt action helps mitigate potential harm to individuals whose data was compromised. It also demonstrates your commitment to data protection, which can protect your business's reputation. Don't delay; every hour counts in a data breach scenario.
What are the first steps an SMB must take?
Upon discovering a potential data breach, your immediate focus should be to contain it and assess the damage. This means isolating affected systems, changing compromised passwords, and stopping further unauthorised access. Document everything you do, including who you've spoken to and when. This initial response is crucial for reducing the breach's impact and preparing for reporting. If you need help preparing your incident response plan, you can book a free 15-minute audit chat with Neil.
How do you assess the risk of serious harm to individuals?
Assessing the risk of serious harm involves considering the type of personal information involved, the sensitivity of that information, and the circumstances of the breach. For example, a breach involving medical records or financial details is likely to pose a higher risk than a breach of only names and addresses. This assessment guides your decision on whether the breach is eligible for notification under the NDB scheme. The OAIC provides clear guidance on what constitutes 'serious harm'.
When and how do you notify the OAIC and affected individuals?
If your assessment concludes that a breach is likely to result in serious harm, you must notify the OAIC using their online form and inform affected individuals directly. Your notification should include a description of the breach, the type of information involved, and steps individuals can take to protect themselves. Transparency and clear communication are vital here. Remember, proactively communicating can help maintain trust even in challenging circumstances. For personalised advice on managing your Microsoft 365 security after a breach, book a free 15-minute audit chat with Neil today.
For Australian small and medium businesses, understanding and swiftly acting on Notifiable Data Breaches within the first 72 hours is not just a legal obligation but a cornerstone of maintaining customer trust and protecting your business reputation.
Frequently asked questions
- What specifically triggers a Notifiable Data Breach in Australia?
- A Notifiable Data Breach is triggered when personal information held by your organisation is accessed or disclosed without authorisation, or lost, and it's likely to result in serious harm to one or more individuals. This 'serious harm' assessment is key.
- Who do Australian small businesses need to notify if a data breach occurs?
- If an eligible data breach occurs, Australian small businesses must notify the Office of the Australian Information Commissioner (OAIC) and all individuals whose personal information is involved in the breach.
- What information should be included in a data breach notification to individuals?
- Notifications to individuals should describe the breach, the type of personal information involved, and practical steps individuals can take to reduce their risk of harm, such as changing passwords or monitoring accounts.
- How quickly must an Australian SMB report a data breach?
- An eligible data breach must be reported to the OAIC and affected individuals as soon as practicable after your business becomes aware of it, and generally within 72 hours of becoming aware.
- What are the penalties for not reporting a Notifiable Data Breach in Australia?
- Failing to comply with the NDB scheme can lead to significant penalties under the Privacy Act, including financial penalties, reputational damage, and loss of customer trust for Australian businesses.
Sources
Every reference below was link-checked when this article was published.
- 1.Data breach preparation and responseOffice of the Australian Information Commissioner
- 2.Notifiable Data Breaches schemeOffice of the Australian Information Commissioner
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


