Privacy Act and OAIC
Privacy Act 1988, APPs, and the OAIC. Who is an APP entity, how NDB sits beside IR, and which desk pages hold the clocks and the serious-harm test.
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set how APP entities collect, use, disclose, and secure personal information. The Office of the Australian Information Commissioner (OAIC) is the regulator. This page is the map. The clocks and the harm test live on their own pages so IR can open them under pressure.
APP entities include Australian government agencies, businesses and not-for-profits with annual turnover above $3 million, and smaller entities that are still in (health service providers, credit reporting, TFNs, and other carve-ins). If you are not sure you are in, get legal advice before an incident — the NDB scheme only binds APP entities, but state privacy regimes and contracts may still bite.
Notifiable Data Breaches (Part IIIC): when you have reasonable grounds to suspect an eligible data breach, take all reasonable steps to finish a reasonable and expeditious assessment within 30 calendar days (s 26WH). An eligible data breach is unauthorised access to, disclosure of, or loss of personal information where serious harm to an individual is likely and remedial action has not removed that likelihood. Once you have reasonable grounds to believe it is eligible, notify the OAIC and individuals at risk as soon as practicable. Detail: ndb-clock, serious-harm-test, ndb-statement.
APP 11 (security of personal information) is the cousin of your technical program: take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. A missing MFA on the mailbox that holds ID documents is an APP 11 fact, not just an IT ticket. Pair it with a written data breach response plan (OAIC guide) so containment, assessment, and notice are not invented at 2am.
Do not confuse regimes. SOCI Part 2B and the Cyber Security Act ransomware-payment report are separate clocks for critical infrastructure and reporting business entities. Paying a ransom does not pause NDB. Vendor breaches (email providers, shippers, RMM) still need your assessment if personal information you hold is involved — their incident is often your NDB suspicion.
Primary sources: Privacy Act 1988; OAIC Notifiable data breaches pages and Data breach preparation and response guide; OAIC APP guidelines. Cross-links on this desk: ndb-clock, serious-harm-test, ndb-statement, data-breach-response-plan, soci-clock, ransomware-payment-reporting.
Fact source: OAIC — Notifiable data breaches.
