Australia flag

Australia

Data Breach in Australia: What to Do If Your Information Is Affected

By Recording Law Editorial Team11 min read
Data Breach in Australia: What to Do If Your Information Is Affected

Frequently Asked Questions

What is an eligible data breach in Australia?

It is unauthorised access to, unauthorised disclosure of, or loss of personal information held by an organisation or agency, where this is likely to result in serious harm and the entity has not been able to prevent that likely harm through remedial action.

How long does an organisation have to tell me about a data breach?

An organisation generally has up to 30 calendar days under section 26WH of the Privacy Act 1988 (Cth) to assess whether a suspected breach is an eligible data breach. Once it concludes there has been one, it must notify affected individuals and the OAIC.

Should I pay for a credit monitoring service after a data breach?

Start with the free options: a credit ban with the credit reporting bodies, a free credit report, and IDCARE's free advice line. Many breach responses already include a period of free monitoring; a paid product should only be considered after you understand what the free protections do not already cover.

What is IDCARE and is it free?

IDCARE is Australia's national identity and cyber support service. It is free to use and can be reached on 1800 595 160 for expert, one-on-one advice specific to your situation.

How long does a credit ban last and can I extend it?

A ban lasts 21 days from when you first request it. You can ask for an extension at any time, and a credit reporting body must extend it if it believes you have been, or are likely to be, a victim of fraud. There is no limit on the number of extensions and no charge to request one.

What should a data breach notification include?

The organisation's name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for what you should do in response.

What if the organisation can't contact me directly about the breach?

It must publish the notification on its website and take reasonable steps to bring it to affected individuals' attention, such as through social media, news coverage or advertising.

What should I do if I think I was affected but wasn't told?

Contact the organisation or agency directly and ask whether your information was involved. If it doesn't respond within a reasonable time, generally 30 days, or you're not satisfied with the answer, you can complain to the OAIC.

Can identity theft from a data breach affect my credit report?

Yes, identity theft is one of the examples of serious harm the OAIC points to, since stolen information can be used to open accounts or apply for credit in your name. This is exactly what a credit ban is designed to prevent while you assess the situation.

Sources and References

  1. OAIC, Notifiable data breaches(oaic.gov.au).gov
  2. OAIC, When to report a data breach(oaic.gov.au).gov
  3. OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) scheme (30-day assessment period under s 26WH)(oaic.gov.au).gov
  4. OAIC, What is a notifiable data breach?(oaic.gov.au).gov
  5. OAIC, Identity fraud(oaic.gov.au).gov
  6. OAIC, Data breach support and resources(oaic.gov.au).gov
  7. OAIC, Fraud and your credit report(oaic.gov.au).gov
  8. OAIC, Make a data breach complaint(oaic.gov.au).gov
Share: