What is a data breach?
A data breach (Data Breach) has been defined by the Office of the Australian Information Commissioner (OAIC) in its guide to developing a data breach response plan as occurring when:
“personal information held by an agency or organisation is lost or subjected to unauthorised access, use, modification, disclosure or other misuse”.
Broadly, a Data Breach can also be described as an interference with the privacy of an individual. An eligible Data Breach occurs when:
- there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity; and
- the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates.
What steps must be taken when there has been a suspected Data Breach?
If there are reasonable grounds to believe that there may have been an eligible Data Breach, an eligible entity (APP Entity) must:
- carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that there has been a Data Breach; and
- take all reasonable steps to have the assessment completed within 30 days after the entity becomes aware of the suspected Data Breach.
How to minimise the risk of a serious breach
Certain preventive measures can be taken by businesses to reduce the risk of a breach being a serious breach, including:
- protecting the information/data that is stored by one or more security measures that are not likely to be overcome;
- using a security technology or methodology designed to make the information unintelligible or meaningless to persons not authorised to obtain the information; and
- ensuring that if the unauthorised information was obtained, it would be unlikely that the unauthorised persons would also be able to circumvent the security technology or methodology that had been put in place.
What is a Data Breach Response Plan?
Whilst the phrase Data Breach Response Plan is descriptive of its anticipated contents, the OAIC has defined the term to mean:
“A data breach response plan is one tool to help you manage a data breach. It is a framework which sets out the roles and responsibilities for managing an appropriate response to a data breach as well as describing the steps to be taken by an entity in managing a breach if one occurs”.
To assist with managing a Data Breach, the OAIC has prepared the following two (2) guides:
- guide to developing a data breach response plan; and
- data breach notification — A guide to handling personal information security breaches.
The benefits of having a Data Breach Response Plan
A Data Breach Response Plan may:
- reduce the cost of the data breach to your organisation (Note: According to the 2017 Ponemon Institute Report, the Cost of Data Breach Study, the average cost of a data breach to an Australian organisation is $141 per record);
- reduce the average cost of a data breach by around 10% (Note: Actions within the first 24 hours can greatly reduce the damage done to affected individuals);
- limit your legal liability to the affected individuals and under the Privacy Act;
- assist in remedying a breach before it becomes an eligible data breach requiring notification of the OAIC and affected individuals;
- limit the damage to your business reputation; and
- minimise the likelihood of receiving a penalty.
Videos about data breach compliance by Dundas Lawyers®
Disclaimer
This page contains general commentary only about data breach compliance, you should not rely on the commentary as legal advice. Specific legal advice should be obtained to ascertain how the law applies to your particular circumstances.
Why choose Dundas Lawyers® to advise your business on a suspected Data Breach?
Having exerted Blood Sweat and Years® since April 2010 we are the team you want on your side for the long term to act as the ‘bodyguard’ for your business, to ensure you comply with the Privacy Act and act fast in the case of a suspected data breach. Some of the reasons client’s choose Dundas Lawyers® include:
- our Uncommon business acumen;
- our Uncommon expertise in transactional, compliance and litigious matters;
- our Uncommon expertise technology law;
- our Uncommon customer focus;
- the fact that we don’t just know law, we know business!
- how we leverage our Uncommon Nous® to provide client solutions.
Considering getting a lawyer to advise your business on a suspected data breach?
For a confidential, no obligation initial telephone call to find out how we can help your business in addressing a suspected data breach please phone our team on either 1300 386 529 or 07 3221 0013.

Malcolm Burrows B.Bus.,MBA.,LL.B.,LL.M.,MQLS.
Legal Practice Director
T: +61 7 3221 0013 (preferred)
M: +61 419 726 535
E: mburrows@dundaslawyers.com.au

Alternatively complete the form below and we will respond to your inquiry within one (1) business day from the moment you press Submit!
Data breach compliance enquiry
Legislation
- Privacy Act 1988 (Cth)
- Privacy Regulation 2013 (Cth)
- Competition and Consumer Act 2010 (Cth)
- Competition and Consumer Regulations 2010 (Cth)
Guidance by the OAIC:
- guide to developing a data breach response plan; and
- data breach notification — A guide to handling personal information security breaches.
Recent insights about data breaches
-
Federal parliament passes cyber security laws
On 25 November 2024, the Australian Parliament passed a suite of legislation, collectively referred to by the Australian Government as the Cyber Security Legislative Package 2024. The purported impetus for this legislation was a series of high-profile data breaches in 2022 and 2023.
-
Uber breaches Australian privacy laws
This article provides an overview of interesting decisions of Australian Courts in Corporate Law, Technology Law and Intellectual Property. With cases on Trade Marks, Copyright, Defamation, Negligence, Joint Ventures and Confidential Information, it is an invaluable resource for anyone interested in these areas.
-
Ransomware Payments Bill 2021 (Cth)
Australian government proposed the Ransomware Payments Bill 2021 (Cth) (Bill) to enforce mandatory reporting of ransomware payments. Penalties of up to $110,000 for non-compliance.
-
De-encryption laws to make tech giants cooperate with law enforcement
The Australian Government is introducing encryption-related legislation that could have significant implications. Get the full scoop on what this Bill could mean for companies and citizens before it is officially announced.
-
What is a data breach response plan and how do I get one?
Organizations must now comply with the Notifiable Data Breaches Scheme. Learn how to create a Data Breach Response Plan and why it is so important for compliance.
-
Notifiable Data Breach Scheme commences 23 Feb 2018
As of 23 February 2018, certain entities must notify affected individuals of eligible data breaches under the Privacy Act 1988 (Cth). Penalties for non-compliance can reach up to $420,000. Learn more about who’s affected, what constitutes serious harm, how to assess likelihood of harm, and how to prepare a response plan.
-
Legal issues for data loss
Organisations must protect confidential data from external and internal threats. Learn steps to secure data, potential data breach implications, and how a data breach notification bill may require affected entities to notify consumers.
-
How will the new Privacy laws affect your organisation?
What were the changes to the Privacy Act in 2014? Legislative changes to the Privacy Act 1988 (Cth) (Privacy Act) will come into effect on 12 March 2014. The Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth) (Amendments) amends the Privacy Act by introducing:
Recent Federal Court decisions regarding data breaches
-
Singtel Optus Pty Ltd v Robertson [2024] FCAFC 58
PRIVILEGE – legal professional privilege – third party report – investigation into cyber-attack – whether the report was created for the dominant purpose of legal advice – multiple purposes for commissioning report – unchallenged evidence – adverse inference – failure to adduce specific and focused evidence – time for assessing dominant purpose PRACTICE AND PROCEDURE…
-
Medibank Private Limited v Australian Information Commissioner [2024] FCA 117
PRIVACY – investigation by Australian Information Commissioner – breach of Australian Privacy Principles – own initiative investigation under s 40(2) of Privacy Act 1988 (Cth) – representative complaint under ss 36 and 38 of the Act – injunction to restrain investigation under representative complaint – separate Federal Court representative proceeding dealing with overlapping issues –…