Governance Excellence Series · Article 106

Notifiable Data Breach: There Are Two Clocks, Not One

30 days is for assessing eligibility. Notification itself carries no second buffer once eligibility is confirmed

Tax, Structure & Compliance · 7 September 2027

A common and consequential misreading of Australia's data breach notification law is believing there is a single thirty-day window to handle the entire response. There are two separate clocks, and the second one, the notification itself, does not carry anything like the same buffer the first one does.

The Two-Clock Structure Most Organisations Misunderstand

Under the Notifiable Data Breaches scheme in the Privacy Act, an organisation that suspects a breach may have occurred, but does not yet know whether it qualifies as an eligible data breach, has up to thirty calendar days to conduct a reasonable and expeditious assessment to find out. The regulator treats this thirty days as a maximum, not a default timeframe to use in full, and expects organisations to move considerably faster wherever practically possible, since the risk of serious harm typically increases the longer a breach goes unaddressed. Once that assessment concludes an eligible data breach has occurred, an entirely separate notification duty applies immediately, on an as soon as practicable basis, with no second thirty-day window attached to it at all. An organisation that spends the full thirty days on assessment, then assumes it has another thirty days to actually notify, has fundamentally misunderstood the scheme. The notification duty begins the moment eligibility is established, and the expectation from that point is prompt action, not a second extended deadline.

The Genuine Escape Valve Worth Knowing Precisely

A specific, practical provision rewards fast incident response. If an organisation takes remedial action before any serious harm to individuals actually occurs, action sufficiently effective that serious harm is no longer likely as a result, the notification obligation may not apply at all. This creates a tangible incentive to treat the early hours after discovering a suspected breach as the period where containment and remedial action can meaningfully change the organisation's legal position, not merely the practical severity of the incident.

Why Documentation Matters As Much As The Decision Itself

The assessment of whether a breach is likely to result in serious harm, and any decision that remedial action has removed that likelihood, needs to be documented as it happens. The regulator can request an organisation's reasoning, and a decision not to notify made without a clear, contemporaneous record of why is considerably harder to defend after the fact than one supported by documented, real-time reasoning.

The Notifiable Data Breaches scheme rewards speed and honest documentation in roughly equal measure. An association that treats the thirty-day assessment period as an invitation to wait, rather than a maximum to beat, has misunderstood both the law and the practical incentive structure actually built into it.

This is one of the practical governance topics built into our Board Director course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →

— Annie

← Back to the Governance Excellence Series