Privacy Act draft: 72-hour OAIC eligible-breach notification (consultation)
iTnews (1 September 2026) reports the Attorney-General's Department released the Privacy Amendment (Personal Data Protection) Bill 2026 for consultation. The draft would replace the Notifiable Data Breaches scheme's "as soon as practicable" OAIC notification standard with a fixed 72-hour deadline once an entity has reasonable grounds to believe an eligible data breach has occurred, aligning NDB timing with 72-hour windows used under the Security of Critical Infrastructure Act 2018 and ransomware-payment reporting in the Cyber Security Act 2024. The existing 30-day window to assess a suspected breach would remain; entities unable to file a complete statement in time could lodge an incomplete one with written notice of what is missing. Failing to file within 72 hours could attract an infringement or compliance notice. The same package proposes a narrow erasure right limited to large digital platforms (Online Safety Act services clearing $500m gross revenue or 2.5 million average monthly Australian end users), not an economy-wide deletion duty. This is draft consultation legislation, not yet enacted.
Primary: iTnews ยท ACS Information Age
