The Notifiable Data Breaches Scheme: What It Is & Why It Matters
The Notifiable Data Breaches scheme requires covered organisations to assess and, where required, notify certain data breaches affecting personal information.
In this explainer
- Explain what the Notifiable Data Breaches scheme is in plain language
- Describe the general obligations to assess and notify at a conceptual level
- Clarify that specific thresholds and timeframes must be verified with the OAIC
- Show why breach readiness matters for a vendor handling debtor information
- Outline what good breach governance looks like in a provider
6 min read
What it is
The Notifiable Data Breaches scheme, often called the NDB scheme, is part of the Privacy Act framework dealing with what happens when personal information is compromised. In broad terms, it is designed so that, where a breach is likely to cause serious harm to affected individuals, those individuals and the regulator are told, so people can take protective steps.
The scheme reflects a simple expectation: organisations should not quietly absorb significant breaches. Where the impact on individuals could be serious, transparency and timely notification are part of handling information responsibly.
Because the precise triggers, criteria and timing are set by law and regulator guidance, and because that detail can change, this explainer describes the scheme at a general level only. The current rules should always be confirmed with the OAIC.
Key requirements
At a conceptual level, the scheme generally expects covered organisations to:
- Detect and assess suspected breaches involving personal information promptly.
- Judge the likely harm to affected individuals, considering the information involved and the circumstances.
- Notify affected individuals and the regulator where the relevant criteria are met.
- Contain and remediate the breach and take steps to reduce the risk of recurrence.
This explainer does not state specific legal thresholds or timeframes, because those are defined in law and guidance that can change. Organisations should verify the current criteria and any required timing directly with the OAIC.
Why it matters for debt recovery
Recovery providers hold contact details, financial information and matter records about many individuals, which makes breach readiness directly relevant. If a provider you engage suffers a breach affecting your customers' information, your organisation may also have obligations and reputational exposure.
A mature provider treats breaches as a 'when, not if' planning problem: it has a way to detect incidents, assess them against the law, notify where required, and learn afterwards. The absence of such a plan is a meaningful risk indicator.
Our Trust Centre covers related security and privacy topics, and breach readiness connects closely to our data-security material.
What to ask a provider
Useful questions include: Does the provider have a documented data-breach response plan? Who is responsible for assessing incidents? How and how quickly would the provider tell you if your customers' information were involved? And how does it confirm its obligations against current law?
It is reasonable to expect a provider to commit to prompt communication with you as the client, so you can meet any obligations of your own. Look for a clear assessment process rather than ad hoc handling.
How Merion approaches it
Merion aligns its incident handling with the principles of the Notifiable Data Breaches scheme. We aim to detect and assess suspected breaches promptly, judge the likely impact on affected individuals, escalate appropriately, and communicate with affected parties and the regulator where the relevant criteria are met, while confirming current obligations as they apply.
This is general information only and not legal advice, and it asserts no certification or specific timeframe. For the current triggers, criteria and timing, the OAIC is the authoritative source, and independent advice may help in a live incident.
Key takeaways
- The NDB scheme governs notification of certain breaches under the Privacy Act
- It centres on assessing likely harm and notifying where criteria are met
- Specific thresholds and timeframes must be verified with the OAIC
- Breach readiness is directly relevant to a recovery provider
Frequently asked questions
Does every data breach have to be notified?
No. Notification generally depends on criteria set in law, such as the likelihood of serious harm. The current triggers should be confirmed with the OAIC.
How quickly must a breach be reported?
Timing is set by law and regulator guidance and can change, so this explainer does not state a specific period. Verify the current timeframe with the OAIC.
Is this legal advice?
No. This is general information only. For advice, consult the OAIC or seek independent legal advice.
Security and compliance you can verify
Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.