Skip to main content
All resources
Guide
10 min readUpdated 30 June 2026

Notifiable Data Breach Response Playbook

Your first 72 hours after a suspected breach, aligned to the Privacy Act 1988 Notifiable Data Breaches scheme and OAIC expectations — with a ready-to-use action checklist.

The obligation in plain English

Under the NDB scheme, if a data breach is likely to result in serious harm to any individual whose personal information is involved, you must notify the affected individuals and the OAIC as soon as practicable.

You have a maximum of 30 days to assess a suspected eligible data breach — but that is an outer limit, not a target. OAIC expects assessment to be expeditious and documented.

Who to call, and when

Report cybercrime to ReportCyber and, for significant incidents, notify the ACSC. Critical infrastructure operators have separate SOCI Act reporting timeframes of 12 and 72 hours.

Engage legal counsel and your cyber insurer early — most policies require notification before you engage responders.

Evidence discipline

Do not wipe or rebuild affected systems before forensic capture. Preserve endpoint telemetry, identity provider sign-in logs and email audit logs — Australian cloud tenants often have short default retention windows.

The checklist

Hour 0–4: Contain

  • Declare an incident and appoint an incident lead
  • Isolate affected endpoints without powering them off
  • Revoke sessions and reset credentials for implicated accounts
  • Start a timestamped decision log

Hour 4–24: Assess

  • Identify what personal information was involved and for how many individuals
  • Determine whether serious harm is likely (sensitivity, protections, who obtained it)
  • Preserve logs and forensic images before remediation
  • Notify cyber insurer and legal counsel

Hour 24–72: Notify and remediate

  • Submit ReportCyber report; notify ACSC if significant
  • Prepare OAIC statement: description, information involved, recommended steps
  • Notify affected individuals with clear, actionable guidance
  • Close the initial access vector and validate the fix

Post-incident

  • Run a blameless post-incident review within 2 weeks
  • Update the response plan with lessons learned
  • Track remediation actions to completion with owners and dates

Need this done, not just documented?

Fast Emu delivers the controls in this checklist as a managed service, monitored 24/7 from Australia.