research
Published 2026-10-06
Verified 2026-10-06

Queensland OIC annual report: 82 public-sector data breach notifications in 2025–26, first year of the mandatory scheme (53 voluntary the year before); privacy complaints more than double to 353

ABC News (6 October 2026) reports that the Queensland Office of the Information Commissioner (OIC) received 82 data breach notifications from the state public sector in 2025–26, the first year of the mandatory notification of data breach (MNDB) scheme under chapter 3A of the Information Privacy Act 2009 (Qld), which started on 1 July 2025. The OIC's 2024–25 annual report records 53 voluntary notifications that year and 41 the year before. The OIC said most breaches came from accident or human error and involved unauthorised disclosure, such as an email, text or system notification sent to the wrong person or carrying unintended personal information, but some were malicious and intentional. The office also received a record 353 privacy complaints, more than double the previous year, and referred 16 to the Queensland Civil and Administrative Tribunal. Information Commissioner Joanne Kummrow wrote that demand for OIC services had reached unprecedented levels. Local governments came under the MNDB scheme on 1 July 2026, so 2026–27 numbers will include councils. Primary: ABC News reporting on the OIC 2025–26 annual report; scheme rules from OIC.

Exploited in Australia?
unknown
Patch to
Queensland agencies and councils: check your published data breach policy and eligible data breach register meet sections 72 and 73 of the IP Act, and that contracts make service providers report breaches promptly, since their breach can be yours. Practitioner page: /knowledge/qld-mndb.

Primary: ABC News — Data breaches and privacy complaints across Queensland's public sector on the rise (6 Oct 2026) · Vendor: OIC Queensland — Mandatory data breach scheme (agency obligations) · OIC Queensland Annual Report 2024–25 (tabled) — 53 voluntary notifications, MNDB start dates

australia