Privacy Act and Notifiable Data Breaches Compliance | 4iT
If your business holds personal information, Australian privacy law applies, and the Notifiable Data Breaches (NDB) scheme makes data breach notification mandatory when a breach is serious. 4iT helps with the practical side: securing the personal information you hold, controlling who can reach it, and having a breach response ready, so you meet your obligations and lower the chance of a breach in the first place.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner
Ready
Breach response plan prepared before you need it

Key facts
- The Privacy Act 1988 sets out how businesses must handle personal information, and it was significantly reformed by the Privacy and Other Legislation Amendment Act 2024.
- The Notifiable Data Breaches scheme requires eligible breaches to be reported to the OAIC and to affected individuals.
- A statutory tort for serious invasions of privacy has applied since June 2025, so careless handling of personal information is a litigation risk regardless of business size.
- Since July 2026, businesses newly regulated under anti-money laundering law, including many accounting, real estate, legal, and conveyancing practices, have lost the small business exemption entirely.
- 4iT covers the IT and security controls that support compliance. For legal interpretation, seek legal advice.
What does the Privacy Act require?
The Act requires you to handle personal information in line with the Australian Privacy Principles, and to take reasonable technical and organisational steps to keep it secure. In practice that means knowing what personal data you hold, protecting it, and controlling who can access it. This sits alongside the broader compliance and cyber security work we do for Sydney businesses.
What is the Notifiable Data Breaches scheme?
If you have a data breach, you must assess it, and where it is likely to cause serious harm, notify the OAIC and the affected people as soon as practicable. Having a breach response ready is what lets you meet those timeframes instead of scrambling, which is exactly what our incident response service is built around.
Does the small business exemption still protect me?
The AU$3 million turnover exemption still exists for most businesses, but it is widely expected to be removed in a future reform tranche. It has also already been narrowed: since July 2026, businesses newly covered by anti-money laundering law, including many accounting, real estate, legal, and conveyancing practices, lost the exemption for that part of their data handling. The exemption also never applied if you handle health information, trade in personal information, or are a government contractor, and it does not shield anyone from the statutory tort. Building good practice now is cheaper than retrofitting under pressure later. For more detail on what changed, see our Australian Privacy Act 2024 changes article.
How 4iT helps
We map what personal data you hold and where it lives, tighten access control and encryption, add monitoring, and prepare a breach response plan. It is the same security work that protects the business, pointed at your privacy obligations, and it lines up with frameworks like ISO 27001 where that is also relevant to you.
Frequently Asked Questions
Many are currently exempt under the AU$3 million turnover threshold, but exceptions apply and the exemption is widely expected to be removed. The statutory tort applies regardless of size.
Assess it, and if serious harm is likely, notify the OAIC and the affected people as soon as practicable.
No. 4iT handles the IT and security controls that support compliance. For your specific legal obligations, seek legal advice.
With a review of what personal information you hold and how well it is secured, then a plan to close the gaps.
Protect the personal information you hold, and be ready if the worst happens. Call 4iT on 1800 367 448.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.




