Law / Australia

Privacy Act 1988 (Cth), Notifiable Data Breaches Scheme

Privacy Act 1988 (Cth), Part IIIC, ss. 26WE, 26WK, 26WL

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 22 February 2018.

A breach notification rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Prepare a statement about an eligible data breach and give a copy to the Information Commissioner as soon as practicable after becoming aware of reasonable grounds to believe the breach happened.
  • Notify the contents of that statement to each individual to whom the relevant information relates, or to each individual at risk, or, if neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it.

If you get it wrong

Private right of actionNo

Who enforces it

Enforcement body

Office of the Australian Information Commissioner (OAIC)

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

An entity holding personal information that is required to comply with Australian Privacy Principle 11.1 (security of personal information) must notify an eligible data breach, meaning unauthorised access to or disclosure of information that a reasonable person would conclude is likely to result in serious harm.

The entity must give a copy of a statement about the breach to both the Information Commissioner and the affected individuals as soon as practicable after becoming aware of reasonable grounds to believe the breach occurred.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics

Read the law

official consolidated Act text, Federal Register of Legislation

Back to the example  ·  Lint your app