Skip to content

Notifiable data breaches for Australian businesses: when a client database is compromised

26 March 2026

Businesses can hold extensive personal information about vendors, purchasers, landlords and tenants. A look at when a data incident may become a Notifiable Data Breach in Australia and how Cyber Insurance may respond.

Australian livestock and property businesses can hold significant personal information. A single residential file may include identification documents, bank account details, tenancy history, employment information, references and rental ledger data. A sales file may include identification, financing details and contract documents. A rural file may include business information, land titles and personal financial information. Across a rent roll or a sales register, the business is holding the personal information of thousands of individuals.

When that information is compromised through a phishing attack on staff email, unauthorised access to the business's trust accounting software, a lost device or a vendor portal vulnerability, the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner may need to be considered.

When a data incident becomes a Notifiable Data Breach

Not every data incident is a Notifiable Data Breach. The scheme is engaged where there is unauthorised access to or disclosure of personal information, or a loss of personal information, that is likely to result in serious harm to one or more individuals, and the business has not been able to take action to prevent that harm. The OAIC generally expects an organisation or agency to assess within 30 days whether a data breach is likely to result in serious harm.

The question is whether the personal information involved is enough to enable identity theft, financial fraud or other serious harm. For an Agent's file, the threshold needs careful assessment. Identification documents, bank details and tenancy history can all increase the risk profile, and the combination of them may be enough to trigger notification obligations depending on the circumstances.

What the response involves

Where the eligible data breach threshold is met, the business may need to notify the OAIC and affected individuals, or publish the notification where individual notification is not practicable. The notification must include what happened, what information was involved and what the affected individuals can do in response.

Most businesses underestimate how much personal information they hold per file. By the time you add ID documents, bank details and tenancy history, even one record may require careful assessment.

Behind the notification sits a substantial amount of work – forensic investigation to determine the scope, legal advice to assess the threshold and prepare the notification, communications work to manage the message to affected individuals, the OAIC engagement itself, and often the provision of credit monitoring or identity protection services to the affected individuals.

How Cyber Insurance may respond

Some Cyber Insurance policies may respond to these costs under breach response, legal costs, notification costs or credit monitoring sections. These may sit inside the overall limit and may also be sub-limited individually, depending on the wording.

Where the breach gives rise to a regulator investigation or privacy complaint, the policy may respond to covered legal representation, depending on the wording and circumstances. Where individuals subsequently bring a claim against the business for misuse of their information, the policy may respond to covered defence costs and settlement, subject to the privacy-related insuring clause.

Where the harder questions arise

The harder questions in any business Cyber claim are usually about scope. How far does the breach extend – one mailbox, the trust accounting software, the entire client database. How many individuals are affected. Whether the breach is contained or ongoing. Whether the personal information was accessed or only potentially exposed. The cost of the response is largely driven by the answers to these questions, and early engagement with the insurer's breach response panel can affect how the incident is contained, assessed and managed.

What we look at when we review the policy

When we review a Cyber program for an agency, the data breach conversation focuses on a few specific items. Whether the Breach Response insuring clause responds to the full notification process under the Australian scheme, not only an equivalent overseas scheme. Whether the Notification Cost limit is meaningful against the size of the client database. Whether the policy responds to regulator investigation by the OAIC and by state-based privacy regulators where applicable. Whether the wording may respond to personal information held by the business on behalf of third parties such as landlords and vendors, not only the business's own data. And whether the breach response panel is accessible 24/7, since the first 48 hours of a breach materially affect the cost of the rest.

Personal information is part of everyday business work. The policy designed to respond when it is compromised should be structured for the possibility of a breach.

If you would like a review of how data breach exposures are arranged in your business Cyber Insurance program, including breach response, notification costs, privacy claims and sub-limits, RMA Insurance Brokers can walk through it with you before renewal.

Share this article
Talk to us

Need help understanding how this may affect your cover?

Contact the RMA Insurance Brokers team before making changes to your insurance arrangements.

Disclaimer

Any financial product advice in this content is provided by Insura Broking Group T/as RMA Insurance Brokers AR No. 1267581. This material is general in nature and has been prepared without taking into account your objectives, financial situation or needs. Accordingly, before acting on it, you should consider its appropriateness to your circumstances. RMA Insurance Brokers is an AR of McCormick Harris Insurance AFSL No. 238979.

Information is current as at the date the article is written as specified within it but is subject to change. RMA Insurance Brokers make no representation as to the accuracy or completeness of the information. Various third parties may have contributed to the production of this content. All information is subject to copyright and may not be reproduced without the prior written consent of RMA Insurance Brokers.

Stay informed

Receive insurance updates worth reading.

Receive broker-led insurance updates covering rural, business and emerging risk issues affecting Australian clients.

We only use your details to send relevant updates from RMA Insurance Brokers. You can unsubscribe at any time. View our Privacy Policy.