Privacy & Data · Australia · Data Breaches

How the Australian Notifiable Data Breaches Scheme Works After a Cyberattack

Your bank, insurer or telco says your information was exposed. The NDB scheme can require notification — but it does not automatically guarantee cash compensation or reimbursement for every replacement document.

The NDB Scheme Is About Serious Harm — Not Every Security Incident

An entity covered by the Privacy Act must notify affected individuals and the OAIC when a data breach results in, or is likely to result in, serious harm and the breach is not otherwise covered by an exception.

"Serious harm" is assessed on the circumstances, including the kind of information involved, whether it can be misused, how easy it is to identify the person and what safeguards existed.

What the Notification Should Tell You

Where the NDB scheme applies, the notification should identify the eligible data breach, the kind or kinds of information concerned and the steps individuals should take in response.

The organisation should also take reasonable steps to contain and remediate the incident. The OAIC's NDB guidance emphasises practical assistance and mitigation, especially where identity information is involved.

Are Companies Legally Required to Reimburse Your Replacement Passport or Licence?

Not automatically under the NDB scheme. There is no blanket NDB rule saying every organisation must immediately reimburse every consumer's passport or driver's licence replacement cost.

A business may choose to offer identity-protection services, replacement-document support or reimbursement as part of its remediation. Whether it is legally liable for particular costs depends on the circumstances, applicable law, contract, negligence or other legal rights.

What to Ask After a Serious Breach

  1. What categories of information were exposed?
  2. When did the breach occur and when was it discovered?
  3. Was my identity information included?
  4. Was government ID exposed and, if so, what should I replace?
  5. What monitoring or identity-support service is being offered?
  6. What steps have been taken to contain the breach?
  7. Who should I contact for further remediation?

Keep the Notification and Evidence

What if the Company Does Not Notify You Properly?

If you believe a covered entity failed to comply with the NDB scheme, you can make a privacy complaint to the organisation and, if unresolved, complain to the OAIC. The OAIC can investigate regulatory compliance; it does not act as a claims adjuster and does not automatically award individual compensation.

What This Means Practically

Related Kibbo Tools

Sources