Your bank, insurer or telco says your information was exposed. The NDB scheme can require notification — but it does not automatically guarantee cash compensation or reimbursement for every replacement document.
The NDB Scheme Is About Serious Harm — Not Every Security Incident
An entity covered by the Privacy Act must notify affected individuals and the OAIC when a data breach results in, or is likely to result in, serious harm and the breach is not otherwise covered by an exception.
"Serious harm" is assessed on the circumstances, including the kind of information involved, whether it can be misused, how easy it is to identify the person and what safeguards existed.
What the Notification Should Tell You
Where the NDB scheme applies, the notification should identify the eligible data breach, the kind or kinds of information concerned and the steps individuals should take in response.
The organisation should also take reasonable steps to contain and remediate the incident. The OAIC's NDB guidance emphasises practical assistance and mitigation, especially where identity information is involved.
Are Companies Legally Required to Reimburse Your Replacement Passport or Licence?
Not automatically under the NDB scheme. There is no blanket NDB rule saying every organisation must immediately reimburse every consumer's passport or driver's licence replacement cost.
A business may choose to offer identity-protection services, replacement-document support or reimbursement as part of its remediation. Whether it is legally liable for particular costs depends on the circumstances, applicable law, contract, negligence or other legal rights.
What to Ask After a Serious Breach
- What categories of information were exposed?
- When did the breach occur and when was it discovered?
- Was my identity information included?
- Was government ID exposed and, if so, what should I replace?
- What monitoring or identity-support service is being offered?
- What steps have been taken to contain the breach?
- Who should I contact for further remediation?
Keep the Notification and Evidence
- Original breach notification.
- Follow-up emails and SMS messages.
- Evidence of the data categories involved.
- Costs incurred in mitigation.
- Evidence of identity theft or attempted fraud.
- Any offer of remediation or reimbursement.
What if the Company Does Not Notify You Properly?
If you believe a covered entity failed to comply with the NDB scheme, you can make a privacy complaint to the organisation and, if unresolved, complain to the OAIC. The OAIC can investigate regulatory compliance; it does not act as a claims adjuster and does not automatically award individual compensation.
What This Means Practically
- NDB notification is triggered by serious-harm criteria, not every incident.
- Read the notification for the data categories and recommended mitigation.
- Ask for identity-protection and remediation support, but do not assume reimbursement is legally automatic.
- Document actual costs and risks.
- Escalate unresolved privacy-compliance concerns to the OAIC.
Related Kibbo Tools
Sources
- OAIC — Notifiable data breaches. oaic.gov.au
- OAIC — Data breach preparation and response guidance. oaic.gov.au
- OAIC — Notifiable Data Breaches scheme guidance. oaic.gov.au