Notifiable Data Breach Report to OAIC (NDB Scheme)
Form number: OAIC-NDB
Mandatory online form for Australian Privacy Act-covered organisations and agencies to notify the OAIC of an eligible data breach under the Notifiable Data Breaches scheme, when personal information has been lost, accessed without authorisation, or disclosed in a way likely to cause serious harm.
Issuing authority
Office of the Australian Information Commissioner (OAIC)
Official source
oaic.gov.auCost
Free
Deadline
Notify the OAIC promptly once you have reasonable grounds to believe an eligible breach has occurred; a 30-day assessment window applies from when you first become aware of a potential breach
How to apply
- Determine whether the incident is an 'eligible data breach' under the Privacy Act 1988 (Cth) — there must be unauthorised access, disclosure, or loss of personal information that is likely to result in serious harm to one or more individuals.
- Conduct a timely assessment of the breach — you generally have 30 days from becoming aware of the incident to assess whether it is an eligible data breach before mandatory notification is triggered.
- Notify affected individuals promptly once you have reasonable grounds to believe an eligible breach has occurred, including a description of the breach and recommended steps they should take.
- Access the online Notifiable Data Breach notification form at: https://webform.oaic.gov.au/prod?entitytype=DBN&layoutcode=DataBreachWF
- Complete Part 1 of the form: provide your organisation or agency name and contact details, a description of what happened, the kinds of personal information involved, and steps individuals can take to protect themselves.
- Complete Part 2 of the form (held in confidence by the OAIC on request): provide additional detail about containment, remediation efforts, and how the breach occurred.
- Submit the completed form electronically via the OAIC web portal — no paper form is accepted for standard NDB notifications.
- Retain a copy of your submission and any supporting documentation for your organisation's records and for potential OAIC follow-up.
- Respond promptly to any OAIC follow-up enquiries — the OAIC may conduct an assessment or investigation following receipt of your notification.
Related topics
Related forms
FormFinder is not affiliated with any Australian government body. Always verify details on official websites. Not legal advice.
Get this form in FormFinder
Download the app to search, save, and get reminders for this form.
Get early access