Is it a data breach? The first twenty four hours.
Someone pasted the wrong file into an AI tool, or a recorder captured a conversation it should not have, or a former staff member still has a login. Here is how to decide whether it is a breach, what to do in order, and when the regulator has to hear about it.
The one-minute version
- Under the Notifiable Data Breaches scheme, a business covered by the Privacy Act must notify the OAIC and affected people when personal information is lost or accessed without authorisation and that is likely to result in serious harm and the business cannot prevent that harm with remedial action.
- If you are unsure whether it is notifiable, the OAIC expects the assessment to be completed within 30 calendar days of becoming aware of the grounds for suspicion. Start the clock and write down when.
- Not every mistake is a notifiable breach. A client's name pasted into a business AI account with training off is usually not. A spreadsheet of patient records pasted into a free tool may well be. The difference is the information, the tool, and the harm.
- The damage in these incidents is usually done by the hiding, not the mistake.
The first twenty four hours, in order
- Stop it spreading. Delete the conversation or file from the tool. Revoke the login or connection. Change the password if the account was shared. Do this first, and write down the time.
- Work out what went where. Which information, about whom, into which tool, on which account, and what that account's terms say about retention and training. This is the assessment the scheme asks for, and it is also what a client will ask.
- Decide who owns the decision. One person decides whether clients are told and whether the OAIC is notified. In a business your size that is the owner. Name them in advance.
- Judge the harm. Financial loss, identity theft, physical safety, embarrassment or discrimination for the people involved. Health, financial and identity information rate high. A first name and an email address rate low. If serious harm is likely and you cannot undo it, it is notifiable.
- Tell the people who need telling. If notifiable: the OAIC, through its online form, and the affected individuals, with what happened, what information was involved, and what they can do. If not notifiable, consider telling the client anyway. A quiet, early "here is what happened and what we did" keeps clients. Silence loses them when they find out later.
- Write it down. A one-page record: what, when, who, what was done, what was decided and why. This is what protects you if the question comes up in a year.
The scheme does not apply, but your client does. The order above is still the right order, because it is the order that keeps the relationship. Skip the OAIC step; keep everything else.
Write the plan on a calm Sunday
One page: who to tell, what to delete, who decides whether a client is told, and the OAIC link. Print it. Put it somewhere physical. The plan written before the bad day is the difference between a quiet fix and a client finding out from someone else.
The one thing to do next
The Exposure Check ends with a first-fix for exactly this. If question ten was a yes, write the one-page plan this week.
Where to check for yourself
2 Sep 2026: first published. Thresholds and timeframes are set by the OAIC. Confirm them on the OAIC page before acting on an incident.