Tax, Structure & Compliance · 7 September 2027
A common and consequential misreading of Australia's data breach notification law is believing there is a single thirty-day window to handle the entire response. There are two separate clocks, and the second one, the notification itself, does not carry anything like the same buffer the first one does.
The Two-Clock Structure Most Organisations Misunderstand
Under the Notifiable Data Breaches scheme in the Privacy Act, an organisation that suspects a breach may have occurred, but does not yet know whether it qualifies as an eligible data breach, has up to thirty calendar days to conduct a reasonable and expeditious assessment to find out. The regulator treats this thirty days as a maximum, not a default timeframe to use in full, and expects organisations to move considerably faster wherever practically possible, since the risk of serious harm typically increases the longer a breach goes unaddressed. Once that assessment concludes an eligible data breach has occurred, an entirely separate notification duty applies immediately, on an as soon as practicable basis, with no second thirty-day window attached to it at all. An organisation that spends the full thirty days on assessment, then assumes it has another thirty days to actually notify, has fundamentally misunderstood the scheme. The notification duty begins the moment eligibility is established, and the expectation from that point is prompt action, not a second extended deadline.
The Genuine Escape Valve Worth Knowing Precisely
A specific, practical provision rewards fast incident response. If an organisation takes remedial action before any serious harm to individuals actually occurs, action sufficiently effective that serious harm is no longer likely as a result, the notification obligation may not apply at all. This creates a tangible incentive to treat the early hours after discovering a suspected breach as the period where containment and remedial action can meaningfully change the organisation's legal position, not merely the practical severity of the incident.
Why Documentation Matters As Much As The Decision Itself
The assessment of whether a breach is likely to result in serious harm, and any decision that remedial action has removed that likelihood, needs to be documented as it happens. The regulator can request an organisation's reasoning, and a decision not to notify made without a clear, contemporaneous record of why is considerably harder to defend after the fact than one supported by documented, real-time reasoning.
- Understand precisely that the thirty-day period applies to assessing eligibility, not to the entire response, since notification itself must happen as soon as practicable once eligibility is established.
- Treat the immediate hours after discovering a suspected breach as the window for remedial action that may avoid the notification obligation entirely, not simply as containment for its own sake.
- Document the serious harm assessment and any remediation reasoning contemporaneously, since this record is what actually protects a decision not to notify if the regulator later asks for the reasoning.
- Confirm your association's actual coverage under this scheme, connecting directly to the privacy threshold discussion discussed earlier in this series, since eligibility follows the same underlying Privacy Act coverage.
- Build incident response capability into your cyber security planning discussed earlier in this series, since the speed of the organisation's response in the first hours directly affects its legal position under this scheme.
The Notifiable Data Breaches scheme rewards speed and honest documentation in roughly equal measure. An association that treats the thirty-day assessment period as an invitation to wait, rather than a maximum to beat, has misunderstood both the law and the practical incentive structure actually built into it.
This is one of the practical governance topics built into our Board Director course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →
— Annie