Knowledge / au-compliance IR

Privacy Act and OAIC

Australian privacy law and the regulator. Eligible data breaches must be assessed and, if they meet the test, notified.

PRIVACY ACT / NDB SCHEMEHold dataAPP 11Assess30 daysNotifyOAIC + peopleEligible breach: unauthorised access/disclosure likely to cause serious harm.

The Privacy Act 1988 and Australian Privacy Principles set how APP entities handle personal information. The OAIC regulates.

The Notifiable Data Breaches scheme: if unauthorised access, disclosure, or loss is likely to cause serious harm and you cannot fix that with remedial action, notify affected people and the OAIC as soon as practicable. Suspect it, assess it, usually within 30 days.

APP 11 (security) is the cousin of your technical program. IR without a privacy lead is how you miss the statutory clock.