NDB serious harm test
The Privacy Act gate for an eligible data breach. Reasonable person, more probable than not, s 26WG factors, then remedial action.
An eligible data breach under the Notifiable Data Breaches scheme is not every leak. Section 26WE of the Privacy Act 1988 needs three things together: unauthorised access to, disclosure of, or loss of personal information (or loss in circumstances where unauthorised access or disclosure is likely); a reasonable person would conclude that serious harm to one or more individuals is likely; and you have not been able to prevent that likely serious harm with remedial action.
Serious harm is not defined as a single dollar figure. OAIC guidance treats it as serious physical, psychological, emotional, financial, or reputational harm. Likely means more probable than not, assessed from the perspective of a reasonable person in the entity’s position with the facts you have or can reasonably obtain — not from the victim’s hope or an attacker’s boast.
Section 26WG lists non-exhaustive relevant matters: the kind and sensitivity of the information; the persons who have obtained or could obtain it; whether security measures such as encryption, anonymisation, or other controls still hold against those persons; how long the information was exposed; and the nature of the harm that could follow, including identity theft or fraud. Assess holistically. Encrypted data with the key also taken is not “still encrypted” for this test.
Remedial action sits inside the definition. If you reset credentials, revoke tokens, recover devices, or otherwise remove the likelihood of serious harm before notification is due, the notification duty may not arise. Document why. Containment that leaves the risk standing does not buy silence.
Pair this page with the NDB clock. Thirty days is for assessing a suspicion (s 26WH). Once you have reasonable grounds to believe the breach is eligible, notify the OAIC and individuals at risk as soon as practicable. SOCI Part 2B and ransomware-payment reporting are different statutes with different clocks; one incident can trip more than one.
Primary sources: OAIC Part 4 NDB scheme guidance and the quick reference guide for responding to data breaches; Privacy Act ss 26WE–26WH and 26WG. This page is the serious-harm gate, not a substitute for legal advice on a live matter.
