Does my small business have to report a data breach in Australia?

Under Australia’s Notifiable Data Breaches scheme, whether you must report a breach depends on whether the Privacy Act covers you - and most very small businesses are carved out, but the exceptions are wide enough to catch many:

  • The general carve-out - businesses with annual turnover of $3 million or less are usually exempt from the Privacy Act, and therefore from the scheme.
  • The exceptions that override it - health service providers, businesses that buy or sell personal information, and contractors handling government data must comply regardless of turnover.
  • What triggers a report - an eligible data breach likely to cause serious harm must be notified to affected individuals and the OAIC.
  • Where to confirm - the OAIC’s data breach guidance sets out who is covered and what reporting involves.

Do not assume the small-business exemption applies - if you handle health data or trade in personal information, the scheme covers you no matter how small you are.