Privacy Act 2026
Data Breach Response Plan: The Free Template Every Australian Business Needs in 2026
How to build a data breach response plan for the Australian Notifiable Data Breaches scheme — the 30-day assessment clock, the serious-harm test, who to notify, and a first-72-hours action list. Plain English, source-checked, free checklist inside.
A data breach is not an "if" for most businesses — it is a "when." Under Australia's Notifiable Data Breaches (NDB) scheme, what matters is whether you can respond fast and correctly. This guide walks through building a response plan, with the key deadlines you must meet.
(About Australia's privacy law, not the US Privacy Act of 1974.)
The rule you have to meet
If you suspect an eligible data breach, you must assess it expeditiously — within 30 days — and, if it is likely to result in serious harm to any affected individual, notify the OAIC and the affected individuals. This applies now, not just in 2026. (Source: OAIC — Notifiable Data Breaches.)
What counts as an "eligible data breach"
Broadly, there is an eligible data breach where there is unauthorised access to, or disclosure or loss of, personal information that you hold, and a reasonable person would conclude it is likely to result in serious harm to an individual. Serious harm can be physical, psychological, emotional, financial or reputational.
A response plan in six parts
1. Roles and responsibilities. Name who leads the response, who assesses, who notifies, and who communicates. Decide this before a breach, not during one.
2. Detection and escalation. How a suspected breach is reported internally and escalated to the response lead immediately.
3. The 30-day assessment workflow. Contain the breach, gather facts, and run the serious-harm assessment within the 30-day window. Document each step.
4. Serious-harm assessment. A worksheet covering: what information was involved, how sensitive it is, whether it was protected (e.g. encrypted), who might access it, and the likely harm.
5. Notification. Templates for notifying the OAIC (via its NDB form) and affected individuals, plus what each notice must contain.
6. Breach register. A log of incidents, assessments and outcomes — useful for demonstrating diligence and improving over time.
First 72 hours — a quick action list
- Contain — stop the leak (revoke access, isolate systems, recover data).
- Assemble the response team and start the clock and the log.
- Assess scope: what data, whose, how much.
- Evaluate likely serious harm using your worksheet.
- Prepare notifications in parallel so you can act quickly if required.
- Notify the OAIC and individuals if serious harm is likely.
- Review root cause and fix the gap.
Who needs this most in 2026
Any APP entity — and that increasingly includes Tranche 2 firms from 1 July 2026, who hold exactly the kind of identity and KYC data attackers want. See AML Tranche 2 and the Privacy Act.
Build this alongside your privacy policy (see how to write one) and the 2026 compliance checklist.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →