INSIGHT · PRIVACY & DATA

The 30-day clock starts at suspicion.
The day you became aware is the first record.

Under the Notifiable Data Breaches (NDB) scheme, the Office of the Australian Information Commissioner (OAIC) states that an entity which suspects an eligible data breach must take all reasonable steps to complete its assessment within 30 calendar days after the day it became aware of the grounds for that suspicion. The 30 days is an assessment window, not a notification deadline: once there are reasonable grounds to believe a breach is eligible, notification is due as soon as practicable. For a construction business, the first record that matters is the date someone became aware.

An open expanding file box full of paper documents on a desk

Analysed 28 September 2026 · OAIC Data breach preparation and response guide, Part 4 (updated February 2025) · OAIC Quick reference guide for responding to data breaches (published 29 June 2026) · OAIC NDB data for July to December 2025 on data.gov.au · all pages read 28 September 2026.

Key takeaways

  • Thirty days to assess, not thirty days to notify: The Office of the Australian Information Commissioner (OAIC) states that an entity must take all reasonable steps to complete an assessment within 30 calendar days after the day it became aware of the grounds that caused it to suspect an eligible data breach. Once there are reasonable grounds to believe a breach is eligible, the OAIC says the entity must promptly notify, whether that point is reached during the assessment or when it is complete.
  • Awareness is a question of fact, not of rank: The OAIC describes whether an entity is aware as a factual matter in each case, and says an entity should not unreasonably delay an assessment by waiting until its CEO or board is aware. A business would need to be able to show when the information first reached someone, and when it reached the person running the assessment.
  • Coverage turns on turnover and a list of exceptions: The OAIC describes the scheme as applying to businesses with an annual turnover of more than $3 million, and to some smaller businesses, including those related to an entity the Privacy Act covers and tax file number recipients. Whether any particular business is covered is a question for its advisers.
  • Construction does not appear in the published top five: The most recent period in the OAIC's published data, as read on 28 September 2026, is July to December 2025: 670 notifications. The five sectors the file lists are health, finance, business and professional associations, Australian Government and personal services. In the OAIC's July to December 2024 report, the unknown category for time to notify covers entities unable to advise the date they became aware.
  • We would record awareness as a dated event: Our system-design recommendation: store the moment of awareness, the person who became aware, and each assessment step as dated entries, next to a register of what personal information the business holds and where. That is a design choice, not a statement of what the law requires.

What starts the clock,
and what the clock is for.

The guidance of the Office of the Australian Information Commissioner (OAIC) separates two states of knowledge. If an entity has reasonable grounds to believe it has experienced an eligible data breach, it must promptly notify individuals and the Commissioner, unless an exception applies. If it only suspects that it may have, it must quickly assess the situation. The 30 days attaches to the second state, not the first.

The OAIC suggests an assessment could run in three stages: initiate (decide whether an assessment is needed and who is responsible), investigate (gather what personal information is affected and who may have had access), and evaluate (decide whether the breach is eligible). The OAIC notes that the Privacy Act does not specify how an assessment should occur.

  • The trigger: The OAIC states that the requirement for an assessment is triggered if an entity is aware that there are reasonable grounds to suspect that there may have been a serious breach, citing s 26WH(1) of the Privacy Act 1988.
  • The window: An entity must take all reasonable steps to complete the assessment within 30 calendar days after the day it became aware of the grounds (or information) that caused it to suspect an eligible data breach (s 26WH(2), as the OAIC cites it). The Commissioner expects entities, wherever possible, to treat 30 days as a maximum and to complete the assessment in a much shorter timeframe.
  • If it runs over: Where an assessment cannot reasonably be completed within 30 days, the Commissioner recommends documenting this so the entity can demonstrate that all reasonable steps were taken, the reasons for the delay, and that the assessment was reasonable and expeditious. The Commissioner also recommends that entities document the assessment process and outcome.
  • What makes a breach eligible: The OAIC lists three conditions: unauthorised access to, unauthorised disclosure of, or loss of personal information the entity holds; that this is likely to result in serious harm to one or more individuals; and that the entity has not been able to prevent the likely risk of serious harm with remedial action. The OAIC says likely means more probable than not, assessed from the perspective of a reasonable person in the entity's position.

Who the scheme applies to,
as the OAIC words it.

The Office of the Australian Information Commissioner (OAIC) states that entities with existing obligations under the Privacy Act to secure personal information must comply with the Notifiable Data Breaches (NDB) scheme. Below are the routes the OAIC's pages describe that are most likely to be relevant to a construction business, in the regulator's wording.

Two OAIC pages give different start years for the turnover test: Part 4 of the data breach guide says any financial year since 2001; the small business checklist says since 2002. We report both as published and resolve neither.

RouteAs the OAIC states it
TurnoverBusinesses and not-for-profit organisations that have an annual turnover of more than AU$3 million.
Small business operatorAn individual, body corporate, partnership, unincorporated association or trust that has not had an annual turnover of more than $3 million in any financial year since 2001 (Part 4, citing s 6D). The OAIC's small business checklist asks about any financial year since 2002.
Related to a covered entityA small business operator must comply with the Australian Privacy Principles (APPs), and therefore with the NDB scheme, where it is related to an APP entity. The checklist points to the related body corporate test in the Corporations Act 2001.
Tax file numbers (TFNs)TFN recipients are listed among entities that must comply. Small businesses required to secure TFN information do not need to notify about breaches that affect other types of information outside the scope of their Privacy Act obligations.
Employee recordsThe Privacy Act does not cover employee records, but the OAIC says the exemption only applies where the act or practice is directly related to a current or former employment relationship, and does not apply to TFN information in an employee record.
AML/CTF reporting entitiesFrom 1 July 2026, the Privacy Act applies to tranche 2 entities once they become reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), for handling connected with those obligations. The OAIC lists real estate professionals among the businesses that typically provide the designated services.

What a construction business holds,
and why "where" is the slow question.

In our experience, personal information in a construction business arrives through onboarding and contracting, not through a single customer database. It is attached to email, saved into shared folders, photographed on site and forwarded between entities. None of that is unusual. It becomes a problem at the investigate stage of an assessment, when someone has to say which kinds of information were in the mailbox, folder or device that was affected.

  • Subcontractors: Licence copies, identity documents, insurance certificates and bank details for payment, commonly sent as email attachments and filed by project rather than by person.
  • Employees: Payroll and onboarding records, including tax file numbers (TFNs). The Office of the Australian Information Commissioner (OAIC) states that the employee record exemption does not apply to TFN information within an employee record.
  • Buyers and clients: Contracts, identity documents and bank details held for deposits, settlements and variations, often across a sales inbox, a shared drive and a finance system.
  • The statement has to be specific: The OAIC says an eligible data breach statement must include the particular kind or kinds of information involved, and gives an example: it should set out whether a driver's licence or passport was compromised rather than using a generic term like ID documents. A folder named by project answers that slowly.
  • Who became aware, and when: The OAIC's example of awareness is a person responsible for compliance, or personnel with appropriate seniority, being aware of information suggesting a breach. In a construction business the first person to notice a misdirected email or a missing site laptop is often neither, and the date they noticed is not always written down.

What the published statistics
can and cannot tell a builder.

The most recent report on the publications list of the Office of the Australian Information Commissioner (OAIC) is its July to December 2024 report, published 13 May 2025. Its statistics dashboard, published 4 November 2025, states that data for July to December 2025 is available on data.gov.au, and that updates to the dashboard will include July to December 2025 and January to June 2026. That data file, read on 28 September 2026, is the most recent period we found published.

The dashboard itself is an interactive report whose sector filters we could not read as text. We make no claim about how many construction businesses have notified the OAIC.

  • 670 notifications, July to December 2025: The file's by-month table totals 670. The five sectors it lists are health service providers (128), finance including superannuation (83), business and professional associations (72), Australian Government (51) and personal services (47). Construction is not among them, and the file does not list sectors outside the top five.
  • What was involved: Contact information appears in 537 notifications, identity information in 386, financial details in 253 and tax file numbers in 151. Breaches may involve more than one kind, so these do not sum to 670.
  • Two ordinary sources: Among specific sources, personal information sent to the wrong recipient by email accounts for 66 notifications, and social engineering or impersonation for 88.
  • Time to notify is measured from awareness: In its July to December 2024 report, the OAIC defines time taken to notify as the time between when an entity became aware of an incident and when it notified the OAIC, not from when it determined the incident to be eligible. For notifications in the unknown category, the entity was unable to advise the OAIC the date it became aware.
  • Our calculation: Adding the file's time-to-notify table across its three specific sources, 301 of 609 notifications were made more than 30 calendar days after awareness (70 human error, 213 malicious or criminal attack, 18 system fault). This is not a count of late assessments: the 30 days is an assessment window, and the figure measures a different interval.

What has changed since 2024.

The Office of the Australian Information Commissioner (OAIC) states that the Privacy and Other Legislation Amendment Act 2024 inserted a new Division 5 of Part IIIC of the Privacy Act, which commenced on 11 December 2024. It sets up a framework where the Minister may make a declaration permitting the collection, use and disclosure of personal information that would otherwise not be permitted under the Australian Privacy Principles (APPs), to prevent or reduce the risk of harm to individuals in the event of an eligible data breach. The OAIC says it is updating its data breach guide to reflect these changes.

  • The assessment window as the OAIC words it today: The 30-day wording quoted above is from Part 4 of the guide, which displays an update date of February 2025, and from the quick reference guide published 29 June 2026. Both carry the same trigger: the day the entity became aware of the grounds for suspicion. Neither page we read describes a change to it.
  • AML/CTF changes from 1 July 2026: A change outside the Privacy Act moves the coverage line for some small businesses. The OAIC states that from 1 July 2026 the Privacy Act applies to tranche 2 reporting entities, for personal information handled in connection with their anti-money laundering and counter-terrorism financing (AML/CTF) obligations, regardless of whether they fall within the definition of a small business. Whether a given business provides a designated service is answered by AUSTRAC's guidance and the business's advisers.
  • A separate change, covered separately: Privacy policy disclosure of automated decisions under Australian Privacy Principle (APP) 1.7 is a separate obligation, analysed in a separate article linked below.

What we would put in a system

The practical output is small. For a suspected breach, we would test for five fields, each dated and each with a named person against it.

Where agents help is narrow. An email review agent can check outbound drafts for recipient-boundary risk before they send, and a document intelligence agent can read an affected folder and draft a list of the kinds of personal information it holds, with locations. A person confirms both. No agent decides whether a business is covered, whether a breach is eligible, whether serious harm is likely, or whether to notify. Those are decisions for the business and its advisers.

FieldWhy it is load-bearing
Awareness eventThe date, the person, and the information that caused the suspicion. The Office of the Australian Information Commissioner (OAIC) measures the 30 days from the day of awareness, and its statistics treat an entity that cannot give that date as unknown.
Assessment stepsInitiate, investigate and evaluate, each with a date and an owner, with the day count shown against 30. The Commissioner recommends documenting the assessment process and outcome, and documenting the reasons if it runs over.
Holdings registerWhich kinds of personal information are held for subcontractors, employees and buyers, and in which mailbox, folder or system. This is what the investigate stage and the statement's particular kinds of information depend on.
Entity and coverage positionWhich entity holds the information, and the coverage position as confirmed by the business's advisers, with the date it was confirmed. In a group, related entities can sit in different positions.
Notification decisionThe date reasonable grounds to believe were reached, the decision and who made it, and the dates the OAIC and individuals were notified, or the reasons they were not.

Questions worth asking
of your own records

For a builder: if a subcontractor's onboarding email went to the wrong address last Tuesday, where would the date someone noticed be written down?

The Office of the Australian Information Commissioner (OAIC) measures the assessment window from the day the entity became aware of the grounds for suspicion. If that date lives only in someone's memory, the day count starts from a reconstruction.

For a developer: which kinds of buyer information sit in the sales inbox, and which in the shared drive?

The OAIC expects a statement to name particular kinds of information, such as a driver's licence or passport, rather than ID documents. That answer is quicker to give from a register than from a folder search.

For a construction group: which entity holds the subcontractor and buyer records, and has its coverage position been confirmed with advisers?

The OAIC lists being related to a covered entity as one route by which a small business operator must comply with the APPs. A group that holds records across entities needs to know which entity holds what before a question arrives.

For payroll and accounts: are tax file numbers stored separately from the rest of the employee file?

The OAIC states that the employee record exemption does not apply to TFN information within an employee record. It lists TFN recipients among entities that must comply with the Notifiable Data Breaches (NDB) scheme, and says small businesses required to secure TFN information do not need to notify about breaches affecting other information outside those obligations.

For a project or site manager: who on site knows that a lost laptop or misdirected email should be reported, and to whom?

The OAIC says an entity should not unreasonably delay an assessment by waiting until its CEO or board is aware. The route from site to the person running the assessment is part of the record.

What this analysis
does and does not show.

Evidence note

What it shows
That the Office of the Australian Information Commissioner (OAIC) measures the Notifiable Data Breaches (NDB) assessment window from the day an entity became aware of the grounds for suspicion, that the OAIC's own statistics treat an unknown awareness date as its own category, and what that implies for the records a construction business keeps.
Key facts quoted
30 calendar days after the day the entity became aware of the grounds (s 26WH(2), as the OAIC cites it); three conditions for an eligible data breach; annual turnover of more than $3 million; employee record exemption does not apply to TFN information; Division 5 of Part IIIC commenced 11 December 2024; Privacy Act applies to tranche 2 AML/CTF reporting entities from 1 July 2026; 670 notifications in July to December 2025; top five sectors with counts.
  • We did not read the Privacy Act itself. Section references are as the OAIC cites them, and we quote the regulator's guidance rather than the legislation.
  • We make no claim about how many construction businesses notify. Construction does not appear in the top five sector tables we read, and the dashboard's sector filters could not be read as text.
  • Two OAIC pages give different start years (2001 and 2002) for the small business turnover test. We report both and resolve neither.
  • The 301 of 609 figure (notifications made more than 30 days after awareness) applies the time-to-notify definition from the OAIC's July to December 2024 report to the July to December 2025 data file, which does not restate it. It measures notification timing, not assessment duration.
  • This covers the Commonwealth NDB scheme only. State, territory, international and contractual notification obligations are not considered.
  • Nothing here is legal advice. It does not determine whether any business is covered by the Privacy Act, whether any incident is an eligible data breach, or whether notification is required.

What to watch next

The Office of the Australian Information Commissioner (OAIC) has announced two updates without publishing dates for either.

  • The statistics dashboard: The dashboard page states that updates are forthcoming and will include data for July to December 2025 and January to June 2026. If a later release lists sectors beyond the top five, the construction observation above needs rewriting.
  • The data breach preparation and response guide: The OAIC states it is updating the guide to reflect changes made by the Privacy and Other Legislation Amendment Act 2024. The 30-day wording quoted here should be re-read when the updated guide is published.

Bring us one suspected incident.

A misdirected email, a lost phone, a phishing message that someone clicked. Tell us who noticed it, when, and where the affected information was stored. We will show you what a dated awareness record and a holdings register would have looked like for it.

This article is general information about published regulatory guidance. It is not legal advice, and it does not determine whether any business is covered by the Privacy Act 1988, whether any incident is an eligible data breach, or whether notification is required. It describes the Commonwealth Notifiable Data Breaches (NDB) scheme only. Pages read 28 September 2026.

Talk to us · How we approach AI

Sources

Suggested citation: Office of the Australian Information Commissioner, Notifiable Data Breaches scheme guidance and NDB data for July to December 2025, as read 28 September 2026. Derived figure: 301 of 609 notifications made more than 30 days after awareness, our calculation from the sum of the three specific-source rows in the data file's time-to-notify table.