Notifiable data breaches: notifying the Commissioner and the people affected
Once a practice has reasonable grounds to believe there has been an eligible data breach, it prepares a statement, gives it to the Australian Information Commissioner as soon as practicable, and as soon as practicable after that notifies the affected people, or those at risk, or publishes the statement where neither is practicable.
Privacy Act s 26WK(2), (3) to s 26WM
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
As soon as practicable after becoming aware, prepare a statement setting out the practice's identity and contact details, a description of the breach, the kinds of information involved, and recommended steps for the people affected, and give a copy to the Commissioner.
- The statement to the Commissioner, with the date it was given
- Statement missing the recommended steps for individuals
- Delay between the decision and the statement with no reason recorded
As soon as practicable after preparing the statement, take reasonable steps to notify its contents to every person whose information was involved, or to every person at risk, or, if neither is practicable, publish it on the practice website and publicise it.
- Notification records per person, or the published statement and how it was publicised
- Website publication used when individual notice was practicable
A practice may notify a person by the method it normally uses to communicate with them.
- The method used for each person notified
- Notice sent to an old address the practice no longer uses for that client
Where the same breach is an eligible data breach of more than one entity (for example the practice and its software provider), one entity's statement and notification satisfy the duty for the others.
- A written agreement or record of which entity notified
- No one notified because each party assumed the other would
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| s 26WK(2), (3) | |||||
| s 26WL(2), (3) | |||||
| s 26WL(4) | |||||
| s 26WM |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach
- APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records
- APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed
- APP 10.1, APP 10.2APP 10: keeping client information accurate and up to date
- APP 9.1, APP 9.2APP 9: NDIS numbers, Medicare numbers and other government identifiers
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice