This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your business uses AI tools and you've never thought about what happens to your data if something goes wrong, you're not behind. Most Australian SMBs haven't. But the rules around data breaches apply to AI platforms just as they apply to any other software your business uses. If a breach involving an AI tool exposes personal information, you may have a legal obligation to report it to a government regulator and to the people affected, within a strict timeline.
This guide explains the Notifiable Data Breaches scheme in plain English, walks through the specific types of AI-related incidents that can trigger reporting obligations, and gives you a practical process for assessing and responding to a breach. No legal background needed to follow it.
In short: Under the Notifiable Data Breaches (NDB) scheme, covered businesses must complete their assessment of a suspected breach within 30 days of becoming aware of it, then notify the OAIC and affected individuals as soon as practicable once an eligible breach (one likely to result in serious harm) is confirmed — this is normally much faster than the 30-day mark, not a 30-day filing window. This applies whether the breach happened on your own systems, through an AI vendor's platform, or via a shared workspace or document uploaded to an AI tool. See the OAIC's NDB scheme guidance at oaic.gov.au.
What Is the NDB Scheme?
The Notifiable Data Breaches scheme sits within the Privacy Act 1988 and came into effect in February 2018. It requires organisations covered by the Act to notify affected individuals and the OAIC when an eligible data breach occurs. An eligible data breach is one that is likely to result in serious harm to any individual whose information was involved.
The scheme applies to most businesses with an annual turnover of $3 million or more, all private health service providers regardless of turnover, certain government agencies, and other organisations that handle specific categories of sensitive information. If your business is covered by the Privacy Act, the NDB scheme applies to you. If you're unsure whether you're covered, the OAIC's website provides a plain-English guide to thresholds.
The 30-day clock is for your assessment, not for notification itself. It starts the moment your organisation becomes aware that there are reasonable grounds to believe an eligible breach has occurred, and it is a ceiling on how long you can take to assess: not 30 days from when the breach happened, but 30 days from when you knew or should have known about it. Once you conclude an eligible breach has occurred, notification must happen as soon as practicable, which is normally well inside that 30-day window, not a separate 30-day allowance on top of it.
Small business exception: Businesses with annual turnover under $3 million are generally exempt from the Privacy Act and the NDB scheme, with some important exceptions. If your business handles tax file numbers, health information, or provides services to the Australian government, the exemption may not apply. The OAIC recommends smaller businesses review their specific situation rather than assuming the exemption covers them.
How AI Tools Create New Breach Risks
Most business owners think about data breaches as hacking events: someone gets into your server, steals a customer database, and you find out about it weeks later. AI tools have introduced a new set of breach pathways that don't fit that picture at all, and many businesses using AI platforms haven't mapped these risks at all.
Here are the four main categories of AI-related incidents that can trigger NDB obligations:
1. Vendor Breach on the AI Platform
When you use an AI platform, your data lives on that vendor's infrastructure. If the vendor suffers a security breach and personal information your business shared with their platform is accessed or exposed, that is a data breach that affects your customers and your business. The fact that the breach happened on someone else's system does not remove your obligations under the NDB scheme.
Your vendor contract matters here. It should specify how quickly the vendor should notify you of a breach involving your data, because your 30-day assessment clock starts running from when you knew or should have known, not from when the vendor tells you. A vendor who notifies you 25 days after their own breach leaves you only 5 days to complete your assessment, and notification to the OAIC and affected individuals still needs to happen as soon as practicable after that. Check your AI vendor contracts for breach notification clauses. For more on what those contracts should cover, see our guide to AI vendor contracts and the Privacy Act.
2. Accidental Prompt Exposure
Prompt exposure happens when a staff member pastes personal information into an AI tool's chat interface, often without realising the implication. Common examples: copying a client's name, address, and financial details into a ChatGPT prompt to draft a letter; uploading a spreadsheet of employee records to ask the AI to summarise it; pasting a patient's notes into an AI tool to generate a referral summary.
If the AI platform stores that prompt history and it is later accessed by an unauthorised party, or if the platform's terms allow the vendor to use your prompts to train future models, you have disclosed personal information in a way that was probably not intended or authorised. Whether this constitutes an eligible breach under the NDB scheme depends on the nature of the information and the risk of harm, but the question needs to be assessed, not assumed away.
Take a medical practice with six GPs and a part-time practice manager, Priya. A receptionist used to paste patient referral letters into a free AI chatbot to tidy up the wording before sending them to specialists, without telling anyone. When Priya ran a routine check of what AI tools staff were using, she found the chat history held patient names, Medicare details, and clinical notes on a platform with no enterprise data agreement in place. Instead of assuming it was fine because nothing had obviously gone wrong, she treated it as a potential eligible breach: she suspended the account, documented the timeline, and worked through the three-step assessment below. Now she checks every new AI tool before staff are allowed near it, and that's the difference between catching an exposure in week one and explaining it to a patient six months later.
3. Shared Workspace Leak
Many AI platforms offer team or enterprise workspaces where multiple users can access shared projects, conversation histories, or documents. If workspace permissions are misconfigured or if someone's account is compromised, a shared AI workspace can expose the conversations and uploaded documents of every user in that workspace.
This is particularly relevant to businesses that use AI tools for client-facing work, such as accounting practices, legal firms, or consultancies. If a colleague's AI workspace contains client records and someone gains unauthorised access to that workspace, the information of every client referenced in those conversations or documents is potentially exposed.
4. Training Data Exposure
Some AI platforms, particularly consumer-grade or free-tier tools, use customer inputs to improve or retrain their models. This means information you share with the platform may persist in a form that influences model outputs for other users. This is less a discrete breach event and more a systemic privacy risk, but it can constitute a breach of the Australian Privacy Principles if personal information is disclosed beyond what the individual consented to.
Enterprise tiers of most major AI platforms explicitly exclude your data from training. If you or your team are using a free or consumer version of an AI tool with business data, check the vendor's terms carefully. The shadow AI problem, where staff use unsanctioned AI tools without IT or management oversight, is one of the most common sources of this risk. For more, see our guide to conducting a shadow AI audit for Australian businesses.
The Three-Step Breach Assessment Process
When you become aware of a potential breach involving an AI tool, the NDB scheme requires a structured assessment before you decide whether to notify. Skipping straight to notification, or skipping assessment entirely, can both create problems. The OAIC's guidance outlines three steps:
Step 1: Contain the Incident
Stop the breach from continuing or expanding where you can. In an AI context this might mean revoking API keys, suspending access to a shared workspace, asking the vendor to delete specific data, or disabling a staff member's account. Document every action you take and when you took it. This record is important for both your OAIC notification and any internal review.
Step 2: Assess the Breach
You have 30 days from the date you became aware to complete your assessment. The assessment answers three questions: What information was involved? Who could access it? Is it likely to result in serious harm to the individuals affected?
Serious harm includes financial harm, physical harm, reputational harm, and emotional distress. The more sensitive the information (health records, financial details, tax file numbers), the more likely a breach meets the serious harm threshold. For AI-related incidents, consider whether the information was in a prompt, a document, or stored conversation history, and who or what systems could have accessed it.
Step 3: Notify If Required
If the assessment concludes that the breach is likely to result in serious harm, the NDB scheme requires notification to the OAIC and the affected individuals. The OAIC notification is made through their online portal. Notification to affected individuals must contain: the organisation's identity and contact details, a description of the breach, the kinds of information involved, and the steps the OAIC recommends individuals take to protect themselves. See the OAIC's NDB notification guide at oaic.gov.au.
If all affected individuals cannot be identified or contacted, the OAIC's guidance indicates that a notice published on the organisation's website and other reasonable steps to reach them may be required. The OAIC can also require a public notification statement in some circumstances. See the OAIC's guidance on indirect notification at oaic.gov.au.
Decision Flowchart: Is This a Notifiable Data Breach?
NDB Scheme Decision Flowchart for AI Incidents
This flowchart is a general guide only. Legal advice is recommended for complex or high-risk breach situations. Source: OAIC Notifiable Data Breaches scheme guidance.
Reporting Timeline and Who to Notify
The 30-day assessment ceiling is firm, and it is measured from the date your organisation became aware, not the date the breach actually occurred. Notification itself is not on a fixed 30-day clock: the NDB scheme requires notification as soon as practicable once you conclude an eligible breach has occurred, which is usually days, not weeks. In practice this means your internal detection and escalation processes need to be fast. If a staff member notices something unusual on a Monday and doesn't flag it until Friday, you've already lost a working week of your 30-day assessment window.
The NDB scheme requires notification to two parties: the OAIC, using the online NDB notification form available on the OAIC website, and each individual whose personal information was involved. The OAIC's guidance indicates that notification to individuals should be direct wherever reasonably possible. Email or post. Not just a notice on the organisation's website. A website notice is only appropriate when it is not reasonably practical to contact individuals directly. See the OAIC's NDB guidance at oaic.gov.au.
The content of the notification to individuals must include: who you are and how to contact you, what happened, what kinds of personal information were involved, and what steps you recommend individuals take to protect themselves. For AI-related breaches, this might include advising individuals to change passwords if login credentials were exposed, or alerting them to the risk of phishing attempts if contact details were involved.
OAIC contact for NDB notifications: Notifications are submitted via the OAIC's online portal at oaic.gov.au. The OAIC does not offer a phone hotline for NDB reports. If your incident is serious, high-volume, or involves sensitive categories of information, consider engaging a privacy lawyer before submitting your notification.
The Australian Privacy Law Context
The NDB scheme is part of the Privacy Act 1988, which is the primary Australian law governing how personal information must be collected, used, stored, and disclosed. The Act is administered by the OAIC, which investigates complaints, issues guidance, and can take enforcement action against organisations that fail to comply.
For businesses using AI tools, the most relevant provisions are the Australian Privacy Principles (APPs), particularly APP 6 (use and disclosure of personal information) and APP 11 (security of personal information). APP 11 requires organisations to take reasonable steps to protect personal information from misuse, interference, and loss. Using a consumer AI platform that does not offer business-grade data security controls may not satisfy APP 11 for sensitive personal information.
The Privacy Act is also relevant when personal information is transferred to AI platforms based overseas, particularly in the United States. APP 8 requires that before disclosing personal information to an overseas recipient, you take reasonable steps to ensure the recipient handles the information in accordance with the APPs. For a deeper treatment of how the Privacy Act applies to AI tool use, see our guide to the Privacy Act and AI tools in Australia.
The OAIC has also published specific guidance on AI and privacy, including considerations for how organisations should assess AI tools before deploying them with personal information. That guidance is covered in detail in our article on the OAIC's AI guidance for Australian businesses.
Breach Response Plan Essentials
The biggest mistake most small businesses make with data breaches is not having a response plan before something goes wrong. When you're under the stress of a potential breach, trying to work out what to do while also managing the incident and communicating with affected parties is very difficult. A simple written plan makes the 30-day timeline achievable.
A basic breach response plan for an SMB using AI tools should cover:
- Who is responsible: Name a specific person (or role) who owns breach assessment and notification decisions. In a small business this is often the owner or operations manager.
- How incidents get reported internally: Staff need a clear, low-friction way to report a suspected breach without fear of blame. A simple email address or form is enough.
- A list of your AI tools and vendors: You cannot assess a breach involving an AI tool if you don't know which tools your business uses. This includes tools staff have started using on their own without formal approval. A shadow AI audit can help identify these.
- Vendor contact details for breach notification: Know in advance how to contact each AI vendor's security or privacy team, and what your contract requires them to tell you and when.
- The OAIC notification process: Know that the form is on the OAIC website and roughly what information you'll need to provide.
- A log template: Document every action taken, when, and by whom. This serves both your legal obligations and your internal post-incident review.
Breach response plan template: A simple one-page breach response plan template suited to Australian SMBs using AI tools is available as a free download from Need to Know AI. It covers the six elements above in a format you can fill in and keep on file. See the CTA at the end of this article.
What This Means for Your Business
If your business is covered by the Privacy Act and uses any AI tools that handle personal information, the NDB scheme applies to you. The scenarios that trigger NDB obligations are not edge cases: they include vendor breaches on AI platforms you use, staff accidentally sharing client data with AI tools, and misconfigured shared workspaces. These are realistic, everyday risks for a business using tools like ChatGPT, Microsoft Copilot, or any other AI assistant.
You don't need to stop using AI tools to manage this risk. You need to know which tools your business uses, understand what personal information is being shared with each, check that your vendor contracts include breach notification obligations, and have a documented process for assessing and reporting breaches if one occurs.
If your business has staff using AI tools you haven't formally reviewed or approved, that is where the most immediate risk sits. A shadow AI audit is the practical first step before anything else. For guidance on how to run one, see our guide to shadow AI audits for Australian businesses.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: can staff upload customer data to AI tools, AI data residency in Australia, AI tools with Australian data centres, HR AI compliance in Australia, free AI staff policy template, Claude AI review for Australian business, Notion AI review for Australian business, and Microsoft Copilot pricing in Australia.
Related reading: our AI data breach response plan template and our what to do when an AI tool suffers a data breach.
Related reading: our what to do when AI goes wrong in your business.
Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.
Does the NDB scheme apply to small businesses under $3 million turnover?
Generally, no. The Privacy Act 1988 and the NDB scheme apply to businesses with annual turnover over $3 million. However, there are exceptions: if your business handles health information, operates as a health service provider, handles tax file numbers, or has entered into a contract with the Australian government, you may still be covered regardless of turnover. If in doubt, check the OAIC's small business guidance or seek legal advice.
What happens if I don't report a notifiable data breach?
Failing to report an eligible breach to the OAIC can result in enforcement action, including investigations, formal findings, and in serious cases, civil penalties under the Privacy Act. The OAIC can also require organisations to take remediation steps and publish public apologies. Beyond the regulatory consequences, failing to notify affected individuals can expose your business to complaints and reputational harm. The risk of not reporting when you should have is significantly higher than the risk of over-reporting.
Does uploading documents to an AI tool count as a data breach?
Not automatically. Uploading documents to an AI tool is a disclosure of information to a third party. Whether it constitutes a breach depends on whether the disclosure was authorised, whether personal information was involved, and what the AI vendor does with that data. If you upload a document containing personal information to an AI platform whose terms allow that data to be used for model training, and you did not have consent to disclose it in that way, you may have breached APP 6 even before any external incident occurs. Always check the vendor's data handling terms before uploading documents containing personal information.
What is 'serious harm' under the NDB scheme?
Serious harm includes physical, psychological, financial, and reputational harm to an individual, as well as harm to relationships or employment prospects. The assessment is based on what is likely, not certain. Factors that increase the likelihood of serious harm include the sensitivity of the information (health, financial, or identity documents carry higher risk), whether the information could be used for identity theft or fraud, the number of individuals affected, and whether the information is in the hands of a malicious actor. The OAIC provides a serious harm assessment tool on its website.
If our AI vendor is breached, are we responsible for notifying our customers?
Yes, in most cases. If personal information your business holds is accessed or exposed through a breach on your AI vendor's platform, your business still has the primary obligation to notify the OAIC and affected individuals. The vendor's breach notification to you starts your 30-day assessment clock, and once you conclude an eligible breach has occurred, you must notify as soon as practicable. This is why your vendor contracts need to include clear breach notification obligations with a defined timeline for vendor-to-client notification. Without a contractual notification requirement, you may not find out about a vendor breach in time to meet your own NDB obligations.
How long do we have to assess a potential breach before deciding whether to notify?
You have 30 days from when your organisation became aware of the potential breach to complete your assessment. That 30-day window is a ceiling on the assessment, not the notification deadline: once you conclude an eligible breach has occurred (one likely to result in serious harm), you must notify the OAIC and affected individuals as soon as practicable, which is normally much faster than the 30-day mark. The 30 days does not start from when the breach occurred, but from when you had reasonable grounds to suspect it. In practice, aim to complete the initial assessment within the first week and begin notification preparation in parallel if the breach looks serious, rather than treating day 30 as a safe deadline.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Download the free NDB Breach Response Plan template for Australian SMBs using AI tools. One page, plain English, covers all six essentials your business needs before an incident occurs.
Get the Breach Response Template