Does my small business have to report a data breach in Australia?
Under Australia’s Notifiable Data Breaches scheme, whether you must report a breach depends on whether the Privacy Act covers you - and most very small businesses are carved out, but the exceptions are wide enough to catch many:
- The general carve-out - businesses with annual turnover of $3 million or less are usually exempt from the Privacy Act, and therefore from the scheme.
- The exceptions that override it - health service providers, businesses that buy or sell personal information, and contractors handling government data must comply regardless of turnover.
- What triggers a report - an eligible data breach likely to cause serious harm must be notified to affected individuals and the OAIC.
- Where to confirm - the OAIC’s data breach guidance sets out who is covered and what reporting involves.
Do not assume the small-business exemption applies - if you handle health data or trade in personal information, the scheme covers you no matter how small you are.