Glossary / practitioner au-compliance IR

Queensland mandatory data breach scheme (MNDB)

Chapter 3A of Queensland's Information Privacy Act 2009. Contain straight away, assess within 30 days, notify the Information Commissioner and people as soon as practicable, and keep a register and a published policy. Councils have been in since 1 July 2026.

Queensland runs its own breach scheme for the public sector, separate from the Commonwealth Notifiable Data Breaches scheme. Chapter 3A of the Information Privacy Act 2009 (Qld), added by the IPOLA reforms, created the mandatory notification of data breach (MNDB) scheme. It started on 1 July 2025 for departments, Ministers, statutory bodies and other agencies, and local governments joined on 1 July 2026. The Office of the Information Commissioner (OIC) Queensland administers it. In its first year the OIC received 82 notifications, against 53 under the old voluntary scheme the year before.

What counts. A data breach is unauthorised access to, or unauthorised disclosure of, personal information an agency holds, or loss of it where unauthorised access or disclosure is likely. It is an eligible data breach when that is likely to result in serious harm to someone the information is about. The OIC reads likely as more probable than not, not merely possible. Serious harm includes serious physical, psychological, emotional or financial harm and serious harm to reputation, and needs more than irritation or inconvenience. You do not have to identify which individuals will be harmed, and the OIC says to treat the breach as eligible when in doubt. A lost device is unlikely to be a breach if the data is encrypted, protected by a strong password or MFA, or confirmed destroyed.

The clock. As soon as an agency knows or reasonably suspects an eligible data breach, it must immediately take, and keep taking, all reasonable steps to contain it and mitigate the harm: recover the information, restrict or shut down affected systems, suspend the activity that caused it, and change passwords or access codes. Do not destroy evidence while you contain. Where the agency only suspects the breach is eligible, it has 30 days from becoming aware to assess whether there are reasonable grounds to believe it is. If it needs longer, section 49 lets it extend, but before the 30 days run out it must have started the assessment and told the Information Commissioner in writing that it has extended and when the extension ends. Record the assessment and reasons in writing against the section 47(2) factors.

Notifying. Once the agency knows or reasonably believes the breach is eligible, it must, as soon as practicable and unless an exemption applies, give the Information Commissioner a statement with the section 51(2) information through the OIC agency portal, and notify individuals with the section 53(2) information. Notice to people follows a ladder: tell every individual whose information was involved if that is reasonably practicable; otherwise tell each affected individual; otherwise publish the notice on the agency website for at least 12 months and tell the Commissioner where it is. If you do not yet know something, such as the number of people affected, send it to the Commissioner later. If the breach also affects another agency, give that agency written notice describing the breach and the kinds of information, without including the personal information itself.

Exemptions are narrow and named. They include ongoing investigations or proceedings, breaches involving more than one agency, remedial action that removes the likelihood of serious harm, notification that would create a serious risk to someone's health or safety, notification that would compromise or worsen the agency's cybersecurity or lead to further breaches, and conflict with confidentiality or secrecy provisions. The cybersecurity exemption (section 60) only delays notice to individuals and is temporary: tell the Commissioner in writing that you rely on it, when you expect it to end and how you will review it, review it every month and send the Commissioner a summary, and fix the weakness so you can notify. The OIC suggests State agencies talk to the Queensland Government Cybersecurity Unit before relying on it.

Paperwork that must exist before the incident. Section 72 requires an internal register of eligible data breaches, recording what happened, when the Commissioner was told and when extra information followed, and who was notified, when and how. Section 73 requires a published data breach policy that sets out how the agency will contain, assess, notify and review, with roles, escalation paths, recordkeeping and a testing schedule; it does not need to describe your security architecture. The OIC publishes templates for the policy, the register and a response plan, plus an online assessment tool.

Watch your contractors. The MNDB scheme is not passed to service providers the way the privacy principles are, but a breach at a contractor holding agency information can still be the agency's breach. The Commonwealth Privacy Act exempts acts done under a contract with a State authority (section 7B(5)), so do not assume a vendor's NDB obligations cover you. Put prompt breach reporting, containment and cooperation with your assessment in the contract. Non-eligible breaches can still be reported to the OIC voluntarily, and the OIC encourages it. Cross-links: ndb-clock, serious-harm-test, data-breach-response-plan, third-party-supply-chain, privacy-act-oaic.

See also:

Fact source: OIC Queensland — Mandatory data breach scheme (Information Privacy Act 2009 (Qld) chapter 3A); OIC Annual Report 2024–25.