Australia
Data Breach in Australia: What to Do If Your Information Is Affected

If an Australian organisation or agency tells you your personal information was in a data breach, free protections come first: a credit ban, IDCARE's free identity and cyber support line, and your own free credit report, before considering any paid service.
This article addresses what an individual in Australia should do after being told, or suspecting, that their personal information was involved in a data breach covered by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth), current as at 19 July 2026. It is written for consumers responding to a breach, not for organisations managing their notification obligations; the OAIC's dedicated guidance for entities is linked where relevant. This article does not address data-breach notification laws in other countries.
What Counts as an "Eligible" Data Breach
A data breach happens whenever personal information an organisation or agency holds is accessed without authorisation, disclosed without authorisation, or lost. It only becomes an eligible data breach, and triggers the notification obligations under the Privacy Act 1988 (Cth), where three things are true: there is unauthorised access to, or unauthorised disclosure of, personal information that an entity holds, this is likely to result in serious harm to one or more of the individuals involved, and the entity has not been able to prevent that likely risk of serious harm through remedial action. Examples of serious harm the OAIC points to include identity theft affecting your finances and credit report, financial loss through fraud, a likely risk of physical harm, serious psychological harm, and serious harm to reputation.
The 30-Day Clock: How Fast the Entity Must Assess
Once an organisation or agency is aware of reasonable grounds to suspect an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment. Section 26WH(2) of the Privacy Act 1988 (Cth) requires it to take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of the grounds for suspicion. The OAIC expects entities to treat 30 days as a maximum, not a target, and to move faster wherever possible, since the risk of harm to individuals generally increases the longer a breach goes unaddressed. If an assessment cannot reasonably be completed within 30 days, the OAIC expects the entity to document why, and a failure to conduct a reasonable and expeditious assessment within that period is itself treated as an interference with privacy that the OAIC can act on.
How You Will Be Told
If the assessment confirms an eligible data breach, the organisation or agency must notify affected individuals and the OAIC. Notification to you may come by email, text message or phone call, and should include the organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for the steps you should take in response. If the organisation cannot contact everyone affected, it must publish the notification on its website and take steps to promote it, for example through social media, news coverage or advertising, so that people who cannot be reached directly still have a chance to see it.

Step One (Free): Place a Ban on Your Credit Report
If you have been, or are likely to be, the victim of fraud, including identity fraud, and a credit reporting body holds a report on you, you can ask that body to place a ban on your consumer credit report. The OAIC recommends applying to all three Australian credit reporting bodies, Equifax, Experian and illion, since any of them may hold a file on you. The ban lasts 21 days from your request, during which the credit reporting body must not use or disclose your report except with your written consent or where the law requires it; if a credit provider requests your report during the ban, the credit reporting body will flag the ban to them, alerting the provider to possible fraud. Requesting a ban, or extending it, is free, and there is no limit on how many times you can extend it if you remain concerned. The credit reporting body must extend the ban if it believes you have been, or are likely to be, a victim of fraud, and it must notify you at least 5 business days before a ban is due to expire.
Step Two (Free): Get a Copy of Your Credit Report
You are entitled to a free copy of your credit report once every 3 months. Reviewing it lets you check for accounts, loans or credit checks you do not recognise, and shows you which organisations have recently accessed your file, so you know who to contact if something looks wrong.
Step Three (Free): Get Expert Help From IDCARE
IDCARE is Australia's national identity and cyber support service, and the OAIC directs individuals affected by identity fraud or a data breach to it for one-on-one advice from a specialist identity and cyber security counsellor. IDCARE can be reached on 1800 595 160. This support is free and is the appropriate first port of call for a step-by-step response plan tailored to what was actually exposed in the breach that affected you, rather than a generic checklist.

Step Four (Free): Log Out, Change Your Credentials and Check Your Accounts
Log yourself out of affected accounts on all devices, then log in from a device you trust and set a new, unique passphrase. Check your accounts for anything that looks out of place; scammers do not always act on stolen information immediately, so watching for unfamiliar transactions, emails or other contact over time matters as much as an immediate check. If you know or suspect your identity has been stolen, the OAIC also recommends reporting it to the Australian Cyber Security Centre through ReportCyber, contacting police for a report or reference number, and reporting scam-related fraud to the National Anti-Scam Centre through Scamwatch.
Free Protection Comes First, Not a Paid Product
Many data breach notifications, and many settlements arising from a breach, already include a period of free credit monitoring or identity protection for affected individuals. A credit ban, a free credit report and IDCARE's free advice line cover the practical steps most people need immediately. Treat any paid monitoring or identity-protection product as, at most, something to consider only after these free options, and only once you understand exactly what it adds that the free protections do not already cover.
Consider a Victims' Certificate If You Experienced Identity Crime
If identity crime caused ongoing problems in your personal or business affairs, for example debts or records wrongly attributed to you, a victims' certificate may help you resolve them. Certificates are available from the Commonwealth and from some states and territories, depending on the type of identity crime involved.

If You Weren't Notified But Think You Should Have Been
If you believe your personal information was involved in a data breach and you were not told, first contact the organisation or agency directly and ask for information, including whether your personal information was affected. Give it a reasonable period, generally 30 days, to respond. If it does not respond, or you are not satisfied with the response, you can lodge a written complaint with the OAIC. You can also complain to the OAIC if you think a data breach raises other privacy issues beyond a missed notification. See recordinglaw.com's guide to making a privacy complaint in Australia for the full complaint process, and the notifiable data breaches and Australian Privacy Principles pages for the underlying obligations, on recordinglaw.com's Australia data privacy laws hub.
| If you were notified of a data breach | Action | Cost |
|---|---|---|
| Protect your credit | Request a ban with Equifax, Experian and illion | Free |
| Check your file | Get a free copy of your credit report | Free (once every 3 months) |
| Get expert advice | Call IDCARE on 1800 595 160 | Free |
| Secure your accounts | Log out everywhere, change passphrases, check for suspicious activity | Free |
| Report suspected identity theft | ReportCyber, police, Scamwatch | Free |
| Consider ongoing problems | Apply for a victims' certificate if identity crime caused lasting issues | Free to apply |
| Weren't notified but think you should have been | Ask the organisation, then complain to the OAIC | Free |
This article provides general legal information about the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) and the free protective steps available to individuals, current as at 19 July 2026. It is not legal advice and does not account for your individual circumstances. For advice about a specific breach, consult a legal practitioner admitted in the relevant Australian state or territory.
Frequently Asked Questions
What is an eligible data breach in Australia?
It is unauthorised access to, unauthorised disclosure of, or loss of personal information held by an organisation or agency, where this is likely to result in serious harm and the entity has not been able to prevent that likely harm through remedial action.
How long does an organisation have to tell me about a data breach?
An organisation generally has up to 30 calendar days under section 26WH of the Privacy Act 1988 (Cth) to assess whether a suspected breach is an eligible data breach. Once it concludes there has been one, it must notify affected individuals and the OAIC.
Should I pay for a credit monitoring service after a data breach?
Start with the free options: a credit ban with the credit reporting bodies, a free credit report, and IDCARE's free advice line. Many breach responses already include a period of free monitoring; a paid product should only be considered after you understand what the free protections do not already cover.
What is IDCARE and is it free?
IDCARE is Australia's national identity and cyber support service. It is free to use and can be reached on 1800 595 160 for expert, one-on-one advice specific to your situation.
How long does a credit ban last and can I extend it?
A ban lasts 21 days from when you first request it. You can ask for an extension at any time, and a credit reporting body must extend it if it believes you have been, or are likely to be, a victim of fraud. There is no limit on the number of extensions and no charge to request one.
What should a data breach notification include?
The organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for what you should do in response.
What if the organisation can't contact me directly about the breach?
It must publish the notification on its website and take reasonable steps to bring it to affected individuals' attention, such as through social media, news coverage or advertising.
What should I do if I think I was affected but wasn't told?
Contact the organisation or agency directly and ask whether your information was involved. If it doesn't respond within a reasonable time, generally 30 days, or you're not satisfied with the answer, you can complain to the OAIC.
Can identity theft from a data breach affect my credit report?
Yes, identity theft is one of the examples of serious harm the OAIC points to, since stolen information can be used to open accounts or apply for credit in your name. This is exactly what a credit ban is designed to prevent while you assess the situation.
Sources and References
- OAIC, Notifiable data breaches(oaic.gov.au).gov
- OAIC, When to report a data breach(oaic.gov.au).gov
- OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) scheme (30-day assessment period under s 26WH)(oaic.gov.au).gov
- OAIC, What is a notifiable data breach?(oaic.gov.au).gov
- OAIC, Identity fraud(oaic.gov.au).gov
- OAIC, Data breach support and resources(oaic.gov.au).gov
- OAIC, Fraud and your credit report(oaic.gov.au).gov
- OAIC, Make a data breach complaint(oaic.gov.au).gov