Data Breach Lawyer Brisbane: What the Law Requires in the First Days
When personal information your business holds has been accessed, taken or lost, the Privacy Act 1988 (Cth) (Privacy Act) imposes two duties in sequence. Where there are reasonable grounds to suspect an eligible data breach, a reasonable and expeditious assessment must follow, with all reasonable steps taken to complete it within 30 days. Where there are reasonable grounds to believe one has happened, a statement goes to the Office of the Australian Information Commissioner (OAIC) and the people affected are told, each as soon as practicable rather than on day 30.
Those duties fall on businesses with annual turnover above $3 million, on health service providers and some other businesses whatever their size, and, for tax file number information only, on any business that holds tax file numbers. If a ransom is paid and the business's turnover in the previous financial year exceeded $3 million, a separate report under the Cyber Security Act 2024 (Cth) (Cyber Security Act) is due within 72 hours.
Astris Law is a Brisbane firm run by one senior lawyer, Jamie Nuich, who deals with the business herself from the first conversation and works through the incident with it from that point: containment, the assessment, the statement, the notifications, the insurer and the board. If the incident is live, the number is (07) 3519 5616.
What to do before anyone drafts a notice
None of these steps waits for the forensic report, and each is a decision with a legal consequence whose timing is part of the answer if the OAIC later asks what the business did and when.
Contain the incident and keep the evidence. Revoke the credentials, isolate the systems and close the route in, but wipe nothing while doing it. Under s 26WF, if the business acts before any serious harm occurs and, as a result, a reasonable person would no longer conclude that serious harm is likely, the incident is taken never to have been an eligible data breach, so fast containment can change the legal answer.
Preserve the record: the logs, the images of the affected systems and a timeline of who learned what and when. Tell staff to delete nothing, including the phishing email. An early question in any later inquiry is the date on which the business had grounds to suspect.
Start the written assessment on the day suspicion arises, because the 30 days under s 26WH runs from it. Record what information is involved, whose it is, how sensitive it is, what protected it and who is likely to have it now, which are among the matters s 26WG says to weigh.
Work out which laws reach this entity. Turnover and activity decide whether the Privacy Act applies, as set out below, and a business outside it may still hold tax file numbers, hold Queensland Government data under contract or run a critical infrastructure asset, each of which can carry a reporting duty of its own.
Read the insurer's notification condition. Check whether the policy makes prompt notice a condition and whether the insurer has a say in who investigates, and do that before the forensic firm is engaged rather than after, because a response run outside the cover is hard to bring back inside it.
Decide who is told inside the business: a small group with one decision-maker, a line to the board and a rule that nothing goes to customers, staff or the media until the assessment supports it. A statement that later proves wrong is read back against the business by everyone who relied on it.
From suspicion to notification under the Privacy Act
What counts as an eligible data breach
Under s 26WE there is an eligible data breach where personal information is accessed or disclosed without authorisation, or lost in circumstances where unauthorised access or disclosure is likely to occur, and a reasonable person would conclude the result is likely to be serious harm to any of the people concerned. The test is objective. Harm to one person is enough, and the Act does not define serious harm.
The 30-day assessment under s 26WH
Where the business suspects an eligible data breach but cannot yet say it believes one has occurred, s 26WH requires a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 days of the suspicion. The 30 days is a limit on the assessment, not a period in which notification can be deferred, and the OAIC's published position is that it is a maximum rather than a target. Failing to take all reasonable steps to complete the assessment in time is itself an interference with privacy under s 13(4A).
The statement to the Commissioner under s 26WK
Once there are reasonable grounds to believe an eligible data breach has happened, s 26WK requires a statement to the Commissioner as soon as practicable, giving the business's identity and contact details, a description of the breach, the kinds of information involved and the steps it recommends people take. The OAIC can later test it against what the business knew when it was lodged.
Telling the people affected under s 26WL
As soon as practicable after the statement is prepared, s 26WL requires one of three routes: notify its contents to each person whose information was involved; notify only those at risk from the breach; or, where neither is practicable, publish the statement on the business's website and take reasonable steps to publicise it. Under s 26WQ the Commissioner can declare that notification is not required or vary its timing.
Whether your incident clears the serious harm threshold, which route fits and what the statement should say cannot be settled from a description of the law. Those answers come from the data, the logs and the people involved, and that is a question for advice on your incident rather than for this page.
The ransomware payment report under the Cyber Security Act
Paying is not prohibited in general, but making or facilitating a payment to a person designated under Australia's autonomous sanctions laws is a criminal offence, and named ransomware operators have been designated. The Australian Government's advice is never to pay.
If a payment is made, Part 3 of the Cyber Security Act requires a ransomware payment report, lodged through cyber.gov.au to the Australian Signals Directorate and the Department of Home Affairs (Home Affairs), within 72 hours of the payment or of learning that one was made on the business's behalf. The obligation binds a business whose turnover in the previous financial year exceeded $3 million, the threshold set by the Cyber Security (Ransomware Payment Reporting) Rules 2025, and every responsible entity for a critical infrastructure asset, with no minimum payment.
The maximum civil penalty is 60 penalty units, which at the $364 penalty unit for conduct from 1 July 2026 is $21,840 for an individual. For a body corporate the maximum is five times that, $109,200. The obligation has been enforceable since 30 May 2025, and Home Affairs' education-first period ended on 31 December 2025.
Whether the report is owed turns on turnover, or on whether the business runs a critical infrastructure asset, and has a definite answer. Whether to pay at all is a separate question that carries sanctions, insurance and reporting consequences, and it is not one to decide without advice and without the insurer having been notified.
OAIC powers and penalties
The OAIC received 1,205 data breach notifications in 2025, the most since the scheme began in 2018. Its tools run from enforceable undertakings and compensation determinations to civil penalty proceedings in the Federal Court, with infringement notices and compliance notices for lower-level contraventions since 11 December 2024.
For a serious interference with privacy, s 13G sets the maximum for a body corporate at the greatest of $50 million, three times the benefit obtained or 30 per cent of adjusted turnover over the relevant period, and $2.5 million for anyone else. Two lower tiers sit beneath it, s 13H for an interference that is not serious and s 13K for a list of specific contraventions such as a non-compliant privacy policy or collection notice, both measured in penalty units and, at the $364 penalty unit, reaching about $3.64 million and $364,000 for a body corporate.
The first penalty under the Act came in Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224: $5.8 million over the February 2022 Medlab Pathology breach, made up of $4.2 million for failing to protect the information of more than 223,000 people, $800,000 for a late assessment and $800,000 for a late statement to the Commissioner, with $400,000 towards costs. That breach predated the December 2022 increase, so the old maximum applied; the same facts today would be measured against s 13G as it now stands.
The small business exemption and its exceptions
A business with annual turnover of $3 million or less is a small business operator under s 6D and, as a rule, outside the Act. The exemption is still in force. The Government agreed in principle in 2023 to remove it. That has not happened, and our guide to Privacy Act compliance tracks where the reform stands.
In practice the exceptions catch many businesses under the line. A business of any size is covered if it provides a health service and holds health information, which takes in medical, dental and allied health practices; if it discloses personal information about someone to anyone else for a benefit, service or advantage, or provides a benefit, service or advantage in order to collect it; if it holds a Commonwealth contract, for that contract; if it is a credit reporting body; if it is related to a covered company; or if it has opted in under s 6EA. A small business that holds tax file numbers must notify breaches of that information, and of that information only.
Suppliers to Queensland agencies have a further layer. Chapter 3A of the Information Privacy Act 2009 (Qld) has required agencies to notify eligible breaches since 1 July 2025 and local governments since 1 July 2026, and agencies must take reasonable steps to bind their contracted service providers to the privacy principles, so a government contract can carry reporting duties of its own. A responsible entity for a critical infrastructure asset reports cyber security incidents under the Security of Critical Infrastructure Act 2018 (Cth) within 12 hours where the incident has a significant impact and within 72 hours where it has a relevant impact.
Whether turnover is above or below $3 million is a matter of arithmetic. Whether one of the exceptions pulls a business across anyway is a question about what it does with the information it holds, and it is one to ask before the first notification is drafted rather than after.
The statutory tort for serious invasions of privacy
Since 10 June 2025, Schedule 2 to the Privacy Act has given individuals a direct cause of action for a serious invasion of privacy, including the misuse of information about them. The claim does not require proof of damage, and it must be brought within one year of the person becoming aware of the invasion and no later than three years after the invasion itself, though a court has a limited power to extend the time.
The tort requires intentional or reckless conduct. On the wording of the fault element, a business whose only failing was inadequate security is unlikely to meet it; the attacker does, and so does anyone who deliberately or recklessly publishes or uses the stolen data. The point has not yet been decided. Where the breached business becomes exposed is in what it does afterwards: leaving stolen data accessible once it knows, or disclosing it to the wrong people in circumstances a court could call reckless. Our guide to the privacy tort covers the elements and the first decisions, and the OAIC's guidance on the tort sets out the regulator's view of it.
Whether a response has crossed from careless into reckless depends on the evidence of what the business knew and did at each step, which is a reason to take advice on the response itself and not only on the notification.
How Astris Law works on an incident
Jamie Nuich deals with the business herself from the first conversation and runs the matter to its end, so the containment decisions, the assessment and the statement are made with the same lawyer who later deals with the OAIC, the insurer and the board.
The investigation is set up so that legal professional privilege can be claimed over the advice and the material prepared for it. Privilege turns on the dominant purpose for which a document was brought into existence. A forensic report commissioned to fix the systems or reassure customers is not privileged because a lawyer signed the engagement, and in Robertson v Singtel Optus Pty Ltd [2023] FCA 1392 the Federal Court refused privilege over a forensic report obtained through lawyers for that reason. Privilege is not automatic and has to be built from the first engagement letter.
The statement to the Commissioner and the notifications are drafted here against the requirements of ss 26WK and 26WL, without asserting conclusions the facts do not yet support. Dealings with the OAIC run through the firm, as in the other regulatory investigations it handles, and the insurer is notified in the terms the policy requires.
The board receives a paper recording the incident, the decisions and the reasons for them, the notifications and the remediation. For a financial services licensee, the Federal Court has treated inadequate cyber risk management as a breach of s 912A of the Corporations Act 2001 (Cth), including a $2.5 million penalty in Australian Securities and Investments Commission v FIIG Securities Ltd [2026] FCA 92. For other companies the directors' exposure rests on the general duty of care and diligence, whose application to cyber security is so far commentary rather than decided authority, and the paper says so.
Frequently asked questions about data breach response
Do we have 30 days to notify the OAIC of a data breach?
No. The 30 days in s 26WH of the Privacy Act 1988 (Cth) is the outer limit for the assessment, and the Office of the Australian Information Commissioner (OAIC) describes it as a maximum rather than a target. Once there are reasonable grounds to believe an eligible data breach has occurred, the statement to the Commissioner and the notifications to individuals are each due as soon as practicable.
Our turnover is under $3 million. Does any of this apply to us?
Possibly. The small business exemption has exceptions for health service providers, businesses that trade in personal information, Commonwealth contractors, credit reporting bodies, companies related to a covered company and businesses that have opted in. A small business holding tax file numbers must notify breaches of that information. A Queensland Government contract or a critical infrastructure asset can carry reporting duties of its own.
Should we pay the ransom, and do we have to report it if we do?
There is no general ban on paying, but a payment to a person designated under Australia's autonomous sanctions laws is a criminal offence and the Australian Government's advice is never to pay. If a payment is made and your turnover in the previous financial year exceeded $3 million, the Cyber Security Act 2024 (Cth) requires a report through cyber.gov.au within 72 hours of the payment or of learning that one was made on your behalf.
Can the people whose information was taken sue the business?
They can complain to the OAIC, which can make a determination that includes compensation, and since 10 June 2025 they have had a direct cause of action under the statutory tort for serious invasions of privacy. The tort requires intentional or reckless conduct, and on that wording inadequate security on its own is unlikely to meet it, though the point has not been decided. The conduct most likely to meet the test is what a business does with the data after it knows the data is out.
The forensic firm is already investigating. Why involve a lawyer?
The forensic firm works out what happened, while the lawyer works out what the business must now do and records why. Whether the Act applies, when suspicion arose, whether containment has removed the likelihood of serious harm, what the insurer must be told and how the investigation is structured so that privilege can attach are legal questions from the first day.
Talk the incident through
Call Jamie Nuich on (07) 3519 5616 to talk through what has happened. That first conversation is about where the incident stands and what the next steps are, so the response can be scoped before anything is drafted.