insights

What is the Notifiable Data Breaches (NDB) Scheme, and What Does It Mean for You?

For Australian businesses, the introduction of the Notifiable Data Breaches (NDB) scheme in 2018 has significantly raised the stakes of experiencing a cyber-attack. This scheme creates obligations for your company that could result in severe legal and financial consequences. Understanding these rules, as well as how to respond to a cyber-attack, is more critical than ever to protect your business.

What Is the Notifiable Data Breaches (NDB) Scheme?

The NDB Scheme is a framework introduced under the Privacy Act (1988), to promote transparency and accountability when handling data breaches. It requires businesses to notify affected individuals, as well as the Office of the Australian Information Commissioner (OAIC), of breaches that are likely to result in serious harm.

Why Is the NDB Scheme Important?

According to the Annual Cyber Threat Report (2023 – 2024), a cyber threat was reported every six minutes during this period. Many businesses assume that cyber-attacks are a small risk, but this report proves otherwise – they are a very real threat. In this environment, the NDB Scheme is vital for protecting businesses and their customers as well as for building trust.

Who Needs to Comply With the NDB Scheme?

The NDB Scheme applies to any organisation covered by the Privacy Act, which the OAIC defines as:

  • An individual, including a sole trader
  • A body corporate
  • A partnership
  • Any other unincorporated association, or
  • A trust
  • A government agency

The organisation must also have an annual turnover of over $3 million. Some smaller businesses are included, as well – particularly those in healthcare, education, or that otherwise trade in sensitive data.

The Scheme does not typically apply to individuals acting in a personal capacity, and may not apply to small businesses that don’t handle sensitive data. If you are uncertain whether your business must comply with the NDB Scheme, it is always better to check.

Read more: IT Consulting: A Comprehensive Guide

How to Respond to a Cyber-Attack Under the NDB Scheme

When a cyber-attack occurs, you must take the following steps:

1. Detect and Contain the Cyber Breach

Identify and isolate affected systems to limit the breach’s impact. This includes:

  • Shutting down compromised servers or networks.
  • Securing backups and initiating disaster recovery protocols.
  • Documenting every action for compliance and future audits.
2. Assess Whether Notification Is Required

Not all breaches require notification under the NDB Scheme. To determine if it is necessary, consider the severity and the likelihood of serious harm to individuals. Criteria include:

  • Your business
  • The type of information breached.
  • Whether the data is encrypted or accessible.
 

If the breach meets the threshold, you are obligated to report the incident.

3. Notify Affected Individuals and the OAIC

If a breach is notifiable, you must:

  • Notify affected individuals promptly, explaining what occurred, the potential impact, and actions they can take.
  • Notify the OAIC using the prescribed form, within 30 days of becoming aware of the breach.

Failure to notify can result in penalties, including fines and reputational damage.

4. Prevent Future Breaches

Once the immediate crisis is resolved, it’s time to reinforce your defenses. This includes:

  • Conducting thorough security audits.
  • Updating software and hardware to address vulnerabilities.
  • Providing staff with regular cyber security training.

A well-written data breach response plan will make this process easier, and remind you to notify when necessary.

NDB Scheme Penalties - A Real-World Example

In November 2023, the OAIC brought civil charges against Australian Clinical Labs Limited (ACL), a pathology service provider. ACL experienced a data breach that occurred in February 2022, but wasn’t reported until July that year. The OAIC determined that the company failed to correctly identify whether the NDB Scheme applied to them, and did not notify of the breach within the 30 day window. This led to a larger investigation of their compliance with the Privacy Act, where further issues were raised.

The ACL’s actions are believed to have resulted in the data of over 100,000 individuals being put at risk. If they are found to be in breach of the NDB Scheme, or any other part of the Privacy Act, the consequences could include a fine equal to:

  • $50 million, or
  • three times the value of any benefit obtained through the misuse of information, or
  • 30 per cent of their adjusted turnover in the relevant period.
 

They may also face class action lawsuits. This example demonstrates how severe NDB Scheme penalties can be, and the importance of avoiding them.

Tools and Resources to Help You Comply

There are several tools and resources that can help you comply with the NDB Scheme:

Recommended Tools
  • Incident Detection and Response Platforms: Quickly identify and address breaches.

  • Breach Notification Templates: Available through the OAIC, to allow clear communication.

External Resources

Understand Your Obligations With Expert Support

The NDB Scheme is a legal requirement, but it is also a commitment to transparency and customer trust. Taking the time to understand your obligations, and preparing your business to uphold them, will help you prevent fines. This will, in turn, protect your financial stability in the long run.

iCare Cyber are compliance experts, with experience helping our clients understand and meet various regulatory standards. We conduct comprehensive audits to identify areas for improvement, and then provide actionable insights that you can actually use – no vague wording or confusion. If you’re concerned about how the NDB Scheme affects your business, consult our compliance team today to find out more.

FAQs

The NDB scheme applies to all personal information, regardless of how it is stored. While we often think about hackers and computers, a breach can also happen in the physical world. For example, if a briefcase full of printed customer files is left on a train, or if a staff member throws sensitive documents into a public trash bin without shredding them, this could be considered a reportable breach. You must protect physical files with the same care as digital ones. 

If a company you hire to handle your data has a breach, both of you are technically responsible. However, the law says only one of you needs to notify the authorities and the affected people. To handle this properly, you should: 

Check your contracts: Ensure your agreement requires them to tell you immediately if they have a security issue. 

Coordinate the message: Decide which company will send the notification so that customers don't get confused by receiving two different letters. 

Verify the fix: Make sure the vendor has actually fixed the problem before you continue sending them more data.

Yes, there is a "remedial action" exception. If you lose data but manage to fix the situation before any "serious harm" can happen, you may not need to report it. For example, if you accidentally email a spreadsheet to the wrong employee within your own company, and you confirm they deleted it immediately without reading it, the risk of harm is gone. In this case, you should document what happened internally, but you won't need to notify the government. 

Many cyber insurance policies in Australia now require you to prove you are following NDB rules before they will pay out a claim. If you have a breach and the government finds you didn't have a proper response plan in place, your insurance company might refuse to cover your legal fees or fines. Staying compliant with the NDB scheme is often a "must-have" to keep your insurance coverage valid and to help lower your monthly premiums. 

When you send a notification to a customer about a breach, you can't just send a vague email. The law requires you to include very specific information to help them stay safe. Your notification must include: 

Your contact details: So, they know exactly who is calling or emailing them. 

A description of the breach: Explaining what happened in simple, clear language. 

The types of information involved: Telling them if it was just their name, or if it included credit card numbers or home addresses. 

Steps they should take: Giving them clear advice, such as "change your bank password" or "monitor your credit report."