Australian businesses with annual turnover above AUD 3 million must notify the OAIC and affected individuals within 30 days of a data breach likely to cause serious harm. Failure to comply with risks civil penalties of up to AUD 2.5 million for individuals and significantly higher for corporations. Cybercrime offences under the Criminal Code Act 1995 carry separate criminal sanctions, including imprisonment. Organizations facing investigation should seek legal advice in Sydney from lawyers with experience in privacy compliance and white collar crime defense.
Three pieces of legislation carry the most legal weight here. The Privacy Act 1988 (Cth), as substantially amended in December 2024, governs how organizations collect, store, and disclose personal information. The Criminal Code Act 1995 (Cth) criminalizes unauthorized access to computer systems and data. The Cyber Security Act 2024 (Cth) added mandatory ransomware payment reporting obligations, with a 72-hour window from the time a payment is made or discovered. PD Legal Australia advises clients across all three risk dimensions, including where cross-border exposure is involved.
Which Australian Businesses Are Required to Comply with the Privacy Act NDB Scheme?
Not every business falls under the federal Notifiable Data Breaches scheme, so the coverage rules are worth understanding clearly. Organizations required to comply include:
- Businesses with annual turnover exceeding AUD 3 million
- Private sector health service providers, regardless of turnover
- Credit reporting bodies, credit providers, and tax file number recipients
- Entities that trade in personal information
- Accredited entities under the Digital ID Act 2024, including small businesses operating within that system
Queensland and Western Australia have both recently passed state-level legislation introducing their own mandatory data breach notification schemes, adding compliance layers for businesses operating across multiple jurisdictions.
What Are the Penalties for Failing to Notify a Data Breach in Australia?
The financial exposure is real and rising. For failure to notify when required, the OAIC can issue penalties of up to AUD 2.5 million for individuals. For corporations, the maximum penalty under section 13G of the Privacy Act is the greater of AUD 50 million, three times the value of any benefit obtained from the contravention, or 30% of the body corporate’s annual turnover during the period in which the contravention occurred. In September 2025, Australian Clinical Labs agreed to pay AUD 5.8 million after a 2022 breach exposed sensitive health information of 223,000 customers, marking the first civil penalty of its kind under the Privacy Act.
How Does the Criminal Code Act Treat Cybercrime Offences in Australia?
Civil penalties under the Privacy Act are one risk. Criminal exposure under the Criminal Code Act 1995 is another, and the two can apply simultaneously. The criminal provisions cover unauthorized access to or modification of computer data, with serious offences carrying up to 10 years imprisonment. An insider who facilitates a breach, or a director who deliberately conceals one, can face criminal charges entirely separate from any OAIC enforcement action.
What Steps Must Australian Businesses Take After Discovering a Data Breach?
Response speed determines a great deal of the legal outcome. The 30-day notification clock starts when an organization has reasonable grounds to believe a notifiable data breach has occurred. Required steps include:
- Contain the breach immediately by revoking compromised credentials and isolating affected systems
- Assess whether the breach is likely to result in serious harm to individuals
- Notify the OAIC via their online form, and notify affected individuals directly in plain language
- Report ransomware payments to the designated body within 72 hours under the Cyber Security Act 2024
The OAIC expects specificity in notifications, meaning organizations should name the data categories involved such as names, dates of birth, and financial records, rather than vague statements about personal information being accessed.
What Does Regulatory Enforcement for Data Breaches Look Like in Australia Right Now?
Enforcement posture has shifted meaningfully since 2024. Between July and December 2024, the OAIC received 595 data breach notifications, with malicious or criminal attacks accounting for 69% of the total, a 17% increase on the previous six-month period. In 2025, ASIC also initiated proceedings against FIIG Securities for systemic and prolonged cybersecurity failures, signaling that regulators now treat inadequate security governance as potential corporate misconduct. For businesses already under scrutiny, engaging a regulatory enforcement lawyer early is not cautious, it is practical.
Why Go to PD Legal for Data Breach and Cybercrime Legal Advice in Australia?
PD Legal Australia operates at the intersection of privacy compliance, regulatory enforcement, and white collar crime defense, covering the full range of legal risks a data breach can trigger. The Sydney-based team handles matters from proactive compliance advisory through to representing clients in active investigations by the OAIC, ASIC, and the AFP. With a regional network spanning Singapore, Thailand, and Malaysia, PD Legal is particularly well-placed for businesses facing cross-border cyber incidents where multiple regulatory regimes apply simultaneously.
Conclusion
Australia’s data breach and cybercrime legal landscape has moved fast over the past two years, and the penalties now reflect that seriousness. Businesses that treat Privacy Act compliance as a background obligation rather than an active operational priority are the ones most likely to face OAIC enforcement, not just regulatory inconvenience.
PD Legal Australia brings together privacy compliance, regulatory enforcement, and white collar crime defense under one roof, which matters when a single incident triggers obligations across multiple regimes. If you are facing a data breach investigation, regulatory inquiry, or need clarity on your Privacy Act obligations, reach out to PD Legal now to get the right legal advice before the 30-day clock runs out!