Skip to content
  • About
  • Accolades
  • Practices
    • China Desk
    • Corporate & Commercial
    • Employment & Industrial Relations
    • India Desk
    • International Trade
    • Probate, Wills & Estate
    • Real Estate & Construction
    • Restructuring & Insolvency
    • Vietnam Desk
    • White Collar Crime
    View all
    China Desk
    Corporate & Commercial
    Employment & Industrial Relations
    India Desk
    International Trade
    Probate, Wills & Estate
    Real Estate & Construction
    Restructuring & Insolvency
    Vietnam Desk
    White Collar Crime
  • People
  • Careers
  • Insights
  • Countries
    Offices
    • Singapore
    • Thailand
    • Malaysia
    • Australia
    Regional Desks
    • China
    • India
    • Vietnam
Enquiries
Data Breach and Cybercrime Laws in Australia: Legal Risks and Privacy Act Compliance
  • Blog
  • | 15 July 2026

Data Breach and Cybercrime Laws in Australia: Legal Risks and Privacy Act Compliance

Australian businesses with annual turnover above AUD 3 million must notify the OAIC and affected individuals within 30 days of a data breach likely to cause serious harm. Failure to comply with risks civil penalties of up to AUD 2.5 million for individuals and significantly higher for corporations. Cybercrime offences under the Criminal Code Act 1995 carry separate criminal sanctions, including imprisonment. Organizations facing investigation should seek legal advice in Sydney from lawyers with experience in privacy compliance and white collar crime defense.

Three pieces of legislation carry the most legal weight here. The Privacy Act 1988 (Cth), as substantially amended in December 2024, governs how organizations collect, store, and disclose personal information. The Criminal Code Act 1995 (Cth) criminalizes unauthorized access to computer systems and data. The Cyber Security Act 2024 (Cth) added mandatory ransomware payment reporting obligations, with a 72-hour window from the time a payment is made or discovered. PD Legal Australia advises clients across all three risk dimensions, including where cross-border exposure is involved.

Which Australian Businesses Are Required to Comply with the Privacy Act NDB Scheme?

Not every business falls under the federal Notifiable Data Breaches scheme, so the coverage rules are worth understanding clearly. Organizations required to comply include:

  • Businesses with annual turnover exceeding AUD 3 million
  • Private sector health service providers, regardless of turnover
  • Credit reporting bodies, credit providers, and tax file number recipients
  • Entities that trade in personal information
  • Accredited entities under the Digital ID Act 2024, including small businesses operating within that system

Queensland and Western Australia have both recently passed state-level legislation introducing their own mandatory data breach notification schemes, adding compliance layers for businesses operating across multiple jurisdictions.

What Are the Penalties for Failing to Notify a Data Breach in Australia?

The financial exposure is real and rising. For failure to notify when required, the OAIC can issue penalties of up to AUD 2.5 million for individuals. For corporations, the maximum penalty under section 13G of the Privacy Act is the greater of AUD 50 million, three times the value of any benefit obtained from the contravention, or 30% of the body corporate’s annual turnover during the period in which the contravention occurred. In September 2025, Australian Clinical Labs agreed to pay AUD 5.8 million after a 2022 breach exposed sensitive health information of 223,000 customers, marking the first civil penalty of its kind under the Privacy Act.

How Does the Criminal Code Act Treat Cybercrime Offences in Australia?

Civil penalties under the Privacy Act are one risk. Criminal exposure under the Criminal Code Act 1995 is another, and the two can apply simultaneously. The criminal provisions cover unauthorized access to or modification of computer data, with serious offences carrying up to 10 years imprisonment. An insider who facilitates a breach, or a director who deliberately conceals one, can face criminal charges entirely separate from any OAIC enforcement action.

What Steps Must Australian Businesses Take After Discovering a Data Breach?

Response speed determines a great deal of the legal outcome. The 30-day notification clock starts when an organization has reasonable grounds to believe a notifiable data breach has occurred. Required steps include:

  • Contain the breach immediately by revoking compromised credentials and isolating affected systems
  • Assess whether the breach is likely to result in serious harm to individuals
  • Notify the OAIC via their online form, and notify affected individuals directly in plain language
  • Report ransomware payments to the designated body within 72 hours under the Cyber Security Act 2024

The OAIC expects specificity in notifications, meaning organizations should name the data categories involved such as names, dates of birth, and financial records, rather than vague statements about personal information being accessed.

What Does Regulatory Enforcement for Data Breaches Look Like in Australia Right Now?

Enforcement posture has shifted meaningfully since 2024. Between July and December 2024, the OAIC received 595 data breach notifications, with malicious or criminal attacks accounting for 69% of the total, a 17% increase on the previous six-month period. In 2025, ASIC also initiated proceedings against FIIG Securities for systemic and prolonged cybersecurity failures, signaling that regulators now treat inadequate security governance as potential corporate misconduct. For businesses already under scrutiny, engaging a regulatory enforcement lawyer early is not cautious, it is practical.

Why Go to PD Legal for Data Breach and Cybercrime Legal Advice in Australia?

PD Legal Australia operates at the intersection of privacy compliance, regulatory enforcement, and white collar crime defense, covering the full range of legal risks a data breach can trigger. The Sydney-based team handles matters from proactive compliance advisory through to representing clients in active investigations by the OAIC, ASIC, and the AFP. With a regional network spanning Singapore, Thailand, and Malaysia, PD Legal is particularly well-placed for businesses facing cross-border cyber incidents where multiple regulatory regimes apply simultaneously.

Conclusion

Australia’s data breach and cybercrime legal landscape has moved fast over the past two years, and the penalties now reflect that seriousness. Businesses that treat Privacy Act compliance as a background obligation rather than an active operational priority are the ones most likely to face OAIC enforcement, not just regulatory inconvenience.

PD Legal Australia brings together privacy compliance, regulatory enforcement, and white collar crime defense under one roof, which matters when a single incident triggers obligations across multiple regimes. If you are facing a data breach investigation, regulatory inquiry, or need clarity on your Privacy Act obligations, reach out to PD Legal now to get the right legal advice before the 30-day clock runs out!

Legal Update (1)
  • Legal Update
  • | 21 July 2026

WeChat Messages as Evidence in Australian Courts: Navigating Authentication, Admissibility and Weight

WeChat is a popular Chinese developed messaging and social media software being widely used within the Chinese community around the (...)

More Insights
Find Us
  • Singapore

PDLegal LLC Singapore
1 Coleman Street 

#08-02 The Adelphi 

Singapore 179803

Tel: +65 6220 0325
Email: enquiry@pdlegal.com.sg

  • Thailand

PDLegal Asia (Thailand) Co., Ltd.
6th Floor, 6 O-NES Tower,
Sukhumvit Soi 6,
Khlong Toey, Bangkok 10110

Tel: +66 2 254 6415
Email: Thailand@pdlegal.com.sg

  • Malaysia

Tan, Siew & Lee (TSL Legal)
9-1, Level 9,
Wisma UOA Damansara II,
No. 6, Jalan Changkat Semantan,
Damansara Heights,
50490 Kuala Lumpur

Tel: +603 3009 7825
Email: enquiries@tsl-legal.com

  • Australia
PDLegal Australia
Level 3, Suite 12
58 Pitt Street
Sydney NSW 2000

Tel: +61 2 7813 7619
Email: enquiry@pdlegal.au

Offices
  • Singapore
  • Thailand
  • Malaysia
  • Australia
Regional Desks
  • China
  • India
  • Vietnam
Follow Us

Liability limited by a scheme approved under professional standards legislation.

PDLegal Australia is the Sydney-based office of PDLegal LLC.  © All rights reserved 2026.

  • Cookie Policy
Cookies on our website

We use cookies on our site to remember you, show you content we think you will like and help you to use this site. For more details, please see our cookies policy.

Click ‘Accept’ to consent to cookies other than strictly necessary cookies or ‘Reject’ if you do not. You can change your mind at any time by visiting our cookie policy page.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
  • About
  • Accolades
  • Practices
    • China Desk
    • Corporate & Commercial
    • Employment & Industrial Relations
    • India Desk
    • International Trade
    • Probate, Wills & Estate
    • Real Estate & Construction
    • Restructuring & Insolvency
    • Vietnam Desk
    • White Collar Crime
    View all
  • People
  • Careers
  • Insights
  • Countries
    Offices
    • Singapore
    • Thailand
    • Malaysia
    • Australia
    Regional Desks
    • China
    • India
    • Vietnam
Enquiries