Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, Part IIIC, and the OAIC pages cited below
s 26WH the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law
Who the scheme covers
The scheme applies to an APP entity that holds personal information it must keep secure under APP 11.1, and to credit reporting bodies, credit providers and tax file number recipients.1 s 26WE(1) A small business that is covered only because it is an AML/CTF reporting entity is covered for the personal information it handles for AML/CTF purposes.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to designated services of the kind real estate agencies, lawyers, conveyancers and accountants provide.
The test: an eligible data breach
There is an eligible data breach when either:1 s 26WE(2)
- there is unauthorised access to, or unauthorised disclosure of, the information, and a reasonable person would conclude that it would be likely to result in serious harm to any of the individuals it relates to; or
- the information is lost in circumstances where unauthorised access or disclosure is likely to occur, and a reasonable person would conclude that, if it did, it would be likely to result in serious harm.
Remedial action. If you act before serious harm results, and as a result a reasonable person would conclude serious harm is not likely, it is not an eligible data breach. For lost information, it is not an eligible data breach if you act before any unauthorised access or disclosure and, as a result, none happens.3 s 26WF
Serious harm. The Act does not define serious harm or list types of harm. It lists the matters to weigh: the kind and sensitivity of the information, whether it is protected by security measures and how likely those could be overcome, who has or could obtain it, the nature of the harm, and any other relevant matters.4 s 26WG The OAIC's guidance describes the possible harm as harm to physical or mental wellbeing, financial loss or damage to reputation.5 OAIC
The two clocks
| You are aware of | You must | Timing | Section |
|---|---|---|---|
| Reasonable grounds to suspect an eligible data breach | Carry out a reasonable and expeditious assessment | Take all reasonable steps to complete it within 30 days after you become aware | s 26WH(2) |
| Reasonable grounds to believe there has been one | Prepare a statement and give a copy to the Commissioner | As soon as practicable after you become aware | s 26WK(2) |
| A prepared statement | Notify its contents to the individuals concerned or at risk; if neither is practicable, publish it on your website and publicise it | As soon as practicable after the statement is prepared | s 26WL(2), (3) |
The statement must set out your identity and contact details, a description of the breach, the kinds of information concerned, and recommendations about the steps individuals should take.6 s 26WK(3) A statement that does not contain these is a low-tier contravention: up to 200 penalty units ($72,800), or $364,000 for a body corporate.7 s 13K(2) The OAIC asks entities to notify it using its online Notifiable Data Breach form.5 OAIC
Secrecy provisions. Where notifying would be inconsistent with a secrecy provision in another Commonwealth law, the notification duties do not apply to the extent of the inconsistency.8 s 26WP The OAIC's guidance for reporting entities gives the AML/CTF secrecy provisions and the tipping-off offence as examples, so a reporting entity might notify the Commissioner but not the individual.9 OAIC AML/CTF Act s 123
A response plan in six parts
The Act does not prescribe the form of a plan. This outline is ours, built around the steps the Act requires.
Roles
Name the response lead, who assesses, who decides on notification, who talks to clients, and a deputy for each. Include the contact details of your IT provider and insurer.
Detect and escalate
Every staff member reports a suspected breach to the lead at once: a lost laptop or phone, an email to the wrong client, a compromised mailbox, a phishing email that captured a staff login. Record the date and time the firm became aware; the 30-day period in s 26WH runs from then.
Contain
Stop the access or disclosure: revoke access, reset passwords, recall or ask for deletion of a misdirected email, isolate affected systems. Early action can bring the case within the remedial-action exception in s 26WF.
Assess
Work through the s 26WG matters in writing: what information, whose, how sensitive, whether encrypted, who has it, and the likely harm. Decide whether there are reasonable grounds to believe an eligible data breach has happened. Keep the reasoning.
Notify
Keep a draft statement with the four s 26WK(3) headings ready. Give it to the Commissioner, then notify individuals under s 26WL. Check secrecy and tipping-off limits before you notify.
Record and review
Keep a register of every incident, including the ones you decide are not eligible, with the assessment and outcome. Fix the cause and update the plan.
The first 72 hours
The law as it stands sets no 72-hour deadline. These are working steps to get the 30-day assessment and any notification done quickly:
- Contain the breach and preserve evidence such as logs and emails.
- Record when the firm became aware, and open the incident log.
- Assemble the response team; brief your IT provider and insurer.
- Scope it: what information, whose, how many people.
- Start the s 26WG assessment in writing.
- Draft the Commissioner statement in parallel, so it is ready if you form a belief.
- For a reporting entity: check whether any notice could tip off a customer.
Proposed, not law. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation on 31 August 2026, would require a statement to the Commissioner within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred. The consultation paper says the 30-day assessment rule would not change.10 AGD It is a draft, not a Bill before Parliament.
For AML/CTF reporting entities
The OAIC's guidance says entities holding AML/CTF information often hold large amounts of sensitive data for long periods, and should have a data breach response plan. It also says the AML/CTF Act does not require you to keep copies of identity documents: keep the details you need, and take reasonable steps to destroy or de-identify copies once no longer needed.9 OAIC Fewer copies mean less to lose. See AML tranche 2 and the Privacy Act.
For a sector's AML/CTF obligations, see the AML/CTF kit. More in the Privacy Act section. Every source we use: sources.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. Dollar amounts worked out from penalty units are our arithmetic. OAIC and Attorney-General's Department pages are guidance, not law, and open in a new window.
-
Privacy Act 1988 s 26WE, compilation No. 104 (C2026C00227). legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988 s 6E(1A).
-
Privacy Act 1988 s 26WF.
-
Privacy Act 1988 s 26WG.
-
OAIC, "About the Notifiable Data Breaches scheme", and "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", section K. Guidance, not law. oaic.gov.au
-
Privacy Act 1988 ss 26WH, 26WK and 26WL.
-
Privacy Act 1988 s 13K(2) and (4); Regulatory Powers (Standard Provisions) Act 2014 s 82(5)(a). Penalty unit $364 for conduct on or after 1 July 2026: Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424). Dollar amounts are our arithmetic.
-
Privacy Act 1988 s 26WP.
-
OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, sections I, J and K. Guidance, not law. oaic.gov.au
-
Attorney-General's Department, Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, Schedule 3, Part 1, and the accompanying Consultation Paper. An exposure draft is not law. consultations.ag.gov.au