Notifiable data breaches: the 30-day assessment of a suspected breach
When a practice suspects an eligible data breach (unauthorised access, disclosure or loss of personal information likely to result in serious harm), it carries out a reasonable and expeditious assessment and takes all reasonable steps to finish it within 30 days of becoming aware of the grounds for suspicion.
Privacy Act s 26WE(2) to s 26WH
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
An eligible data breach is unauthorised access to or disclosure of personal information, or its loss where that is likely, that a reasonable person would conclude would be likely to result in serious harm to any person it relates to.
- A breach response procedure that defines an eligible data breach in the words of s 26WE
- A lost phone or misdirected report email not treated as a possible breach
A breach is not an eligible data breach if the practice takes action before serious harm results and, because of that action, a reasonable person would conclude serious harm is not likely (or, for a loss, no unauthorised access or disclosure occurs).
- A record of remedial action taken (for example recalling a misdirected email) and why harm is no longer likely
- Remedial action claimed with no record of what was done
In judging likely serious harm, have regard to the kinds and sensitivity of the information (health information is sensitive), any security measures and the chance they are overcome, who has or could obtain it, and the nature of the harm.
- A written serious-harm assessment against the s 26WG matters for each suspected breach
- Harm judged without writing down the s 26WG matters
Where there are reasonable grounds to suspect an eligible data breach, carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days after becoming aware.
- The breach register entry with the date the practice became aware and the date the assessment finished
- The 30-day clock started from discovery of the cause, not from awareness of the grounds
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| s 26WE(2) | |||||
| s 26WF | |||||
| s 26WG | |||||
| s 26WH |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records
- s 26WK(2), (3) to s 26WMNotifiable data breaches: notifying the Commissioner and the people affected
- APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed
- APP 10.1, APP 10.2APP 10: keeping client information accurate and up to date
- APP 9.1, APP 9.2APP 9: NDIS numbers, Medicare numbers and other government identifiers
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice