NDB clock
Thirty days to assess a suspicion; notify as soon as practicable once eligible. As of 17 Sep 2026 the AGD Exposure Draft consultation still closes 18 Sep 2026 — proposed 72-hour OAIC notify clock is not law yet.
The Notifiable Data Breaches scheme sits in the Privacy Act. APP entities that suspect an eligible data breach must take all reasonable steps to finish a reasonable and expeditious assessment within 30 calendar days of becoming aware of the grounds for that suspicion (s 26WH(2)). That is an assessment deadline, not a licence to sit on a breach you already know is eligible.
An eligible data breach is unauthorised access to, disclosure of, or loss of personal information where serious harm to an individual is likely, and remedial action has not prevented that likelihood. If the test is met, you notify the OAIC and individuals at risk of serious harm as soon as practicable, unless a statutory exception applies. Direct notice is the default; a public statement is the fallback when direct notice is not reasonably practicable.
Do not confuse the clocks. Thirty days is for the assessment of a suspicion. Notification, once you have reasonable grounds to believe the breach is eligible, is as soon as practicable — which may be well inside those thirty days. Containment and remedial action still come first. If remedial action removes the likelihood of serious harm, the notification duty may not arise. Document the reasoning either way.
Proposed reform (not yet law): the Attorney-General's Department Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and consultation paper propose that an entity must, within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred, notify the Information Commissioner. Incomplete statements would be allowed inside that window, with outstanding detail later. The assessment duty for a mere suspicion is described separately in the paper and is not replaced by the 72-hour notify clock. As of 17 September 2026 that consultation still closes Friday 18 September 2026 — last business day to lodge a submission on consultations.ag.gov.au. Until Parliament passes and commences amending legislation, the statutory notify standard remains as soon as practicable.
OAIC published 2025 scheme statistics on 6 July 2026: 1,205 notifications in the 2025 calendar year, up 8% on 1,112 in 2024. Malicious or criminal activity accounted for 716. Health service providers were the most commonly affected sector (225, 19%). Those figures are statistics, not an incident. They belong here, not on the breaches filter.
Practical desk: start the assessment clock in writing the hour you have grounds to suspect. Put legal and privacy in the same channel as containment. Use the OAIC form when you notify. If your playbook still assumes a leisurely as-soon-as-practicable drafting window, pressure-test it this week against a hard 72-hour Commissioner statement — the Exposure Draft is consultation-only on 17–18 September 2026, but redesign lead time is real. The OAIC quick reference guide and self-assessment checklist remain the how-to under current law.
A third-party breach still starts your clock if you are the APP entity that holds or controls the personal information. Quest Apartment Hotels' August 2026 statement described unauthorised access arising from a vulnerability through a third-party service provider, with OAIC and ACSC notified. Outsourcing the system does not outsource the assessment duty or the notify-as-soon-as-practicable duty once the breach is eligible. Map which vendors touch personal information before the incident, not after. Mathspace's September 2026 Metabase incident blog is the self-hosted analytics version of the same lesson: an unpatched internal reporting tool became the path to about 1.08 million AU/NZ education records, with OAIC and ASD's ACSC notified. The assessment clock does not wait for a neat root-cause deck.
See also:
Fact source: AGD — Privacy Reform Exposure Draft consultation (closes 18 Sep 2026), AGD consultation paper — proposed 72-hour eligible data breach notification.
