Glossary / practitioner au-compliance IR privacy

NDB statement contents

What the Privacy Act requires in an eligible-data-breach statement to the OAIC and to individuals. Identity, description, kind of information, recommendations.

Once you have reasonable grounds to believe an eligible data breach has happened, the Notifiable Data Breaches scheme requires you to prepare a statement and give it to the OAIC as soon as practicable, then notify individuals at risk of serious harm. The serious-harm test and the NDB clock sit upstream of this page. This page is the statement itself.

Section 26WK of the Privacy Act 1988 sets the minimum contents. The statement must identify the entity (and any other entity the notifier believes may have been involved), describe the eligible data breach to the extent known, say the kinds of information concerned, and set out recommendations about the steps individuals should take in response. Put a contact point on it. Vague 'systems were accessed' without kinds of information fails the statute.

Notify individuals by a direct channel that is reasonably likely to reach them — email to a current address, post, or another method you already use for important notices. If direct notice is not reasonably practicable, publish a copy of the statement (or the required content) in a way that is reasonably likely to reach the people at risk, and keep evidence of why direct notice failed.

Do not wait for perfect forensics before the statement. Notify on what you reasonably believe, then update when facts change. A statement that over-claims certainty is as bad as one that hides the kinds of data. Keep the board pack, the assessment record, the statement as sent, the OAIC acknowledgement, and the individual-notice log together.

Primary sources: Privacy Act ss 26WK–26WL; OAIC Part 4 NDB scheme guidance and the quick reference for responding to data breaches. SOCI Part 2B and ransomware-payment reporting can run on the same incident with different clocks and different content — do not assume one statement covers all of them.

See also:

Fact source: OAIC, Notifiable Data Breaches.