Privacy Breaches Lawyers Brisbane
A privacy breach triggers legal obligations under Australian law — including mandatory reporting to the OAIC. EAGLEGATE advises businesses and individuals on privacy breach response, regulatory obligations and privacy dispute resolution across Brisbane and Queensland.
A privacy breach is not solely an IT problem. It is a legal event that triggers reporting obligations, creates regulatory exposure, generates potential civil liability, and requires a response that is both technically sound and legally precise. Under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme, eligible data breaches must be reported to the Office of the Australian Information Commissioner (OAIC) and, in most cases, to affected individuals — within a timeframe measured in days, not weeks.
EAGLEGATE advises businesses and individuals on privacy breach response — from the immediate steps following discovery of a breach through to regulatory interaction with the OAIC, managing potential civil claims from affected individuals, and implementing structural measures to reduce future privacy risk. Nicole Murdoch’s engineering and technology background means EAGLEGATE understands how privacy breaches occur technically — not just how the law responds to them.
Every hour after a privacy breach is an hour the obligation to act is mounting. The law is specific about what must be done, by when, and to whom.
Our Expertise
Key Privacy Breach Expertise — Respond, Report, Protect
EAGLEGATE advises on every stage of a privacy breach response.
The Privacy Act 1988 and the Australian Privacy Principles
The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) govern the collection, use, disclosure, and storage of personal information by APP entities — including businesses with annual turnover above $3 million and certain other categories. APP 11 requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure.
The Notifiable Data Breaches Scheme
Under Part IIIC of the Privacy Act 1988 (Cth), an APP entity that becomes aware of an eligible data breach must notify the OAIC and affected individuals. An eligible data breach occurs where there has been: unauthorised access to or disclosure of personal information; and a reasonable person would conclude that the access or disclosure is likely to result in serious harm to any of the affected individuals.
Where an entity believes an eligible data breach may have occurred, it must undertake an assessment within 30 days. If the breach is confirmed as eligible, the entity must notify the OAIC and affected individuals as soon as practicable.
What Constitutes Serious Harm
Serious harm under the NDB scheme is not defined exhaustively in the Privacy Act 1988 (Cth) but includes physical, psychological, emotional, financial, and reputational harm. The OAIC’s guidance indicates that breaches involving financial information, health information, identity documents, or information enabling fraud or identity theft are more likely to give rise to serious harm. EAGLEGATE assesses the serious harm question as a priority step in breach response.
Regulatory Interaction with the OAIC
Where a privacy breach is notified to the OAIC, the OAIC may undertake a regulatory assessment or investigation. EAGLEGATE advises businesses on their obligations during OAIC engagement — including what must be disclosed, what remediation steps are expected, and how to manage the investigation process. The Privacy Act 1988 (Cth) gives the OAIC broad investigative powers and the ability to issue determinations requiring remediation and awarding compensation.
Civil Liability for Privacy Breaches
Beyond the regulatory regime, individuals now have a direct civil remedy for privacy harm. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy, contained in Schedule 2 to the Privacy Act 1988 (Cth) and commenced on 10 June 2025. An individual may sue where another person has invaded their privacy — by intruding upon their seclusion or by misusing information about them — in circumstances where the individual had a reasonable expectation of privacy, the invasion was intentional or reckless, the invasion was serious, and the public interest in the individual’s privacy outweighs any countervailing public interest. The tort is actionable without proof of damage and is not confined to APP entities, but only individuals, not corporations, may bring a claim. Remedies include injunctions and damages, including damages for emotional distress, with damages for non-economic loss capped broadly in line with the cap that applies in defamation. A complaint to the OAIC, which may lead to compensation through its complaint resolution process, remains a separate avenue.
Our Approach
1. Contain and Assess
The immediate steps following discovery of a privacy breach are to contain the breach (stop the ongoing exposure of personal information) and assess its scope, nature, and likely harm. EAGLEGATE advises on this initial assessment in parallel with any IT response.
2. Determine Reporting Obligations
We advise on whether the breach is an eligible data breach requiring notification under the NDB scheme, and if so, prepare and submit the notification to the OAIC and prepare the communication to affected individuals.
3. Manage Regulatory Interaction
Where the OAIC investigates or requests information, EAGLEGATE manages the interaction — advising on what is required and how to respond appropriately.
4. Reduce Future Risk
We advise on the structural and contractual measures to reduce privacy risk — including data minimisation practices, privacy impact assessments for new projects, and supplier contract terms that address data handling obligations.
Why Choose EAGLEGATE
Privacy Act Expertise
EAGLEGATE advises on the Privacy Act 1988 (Cth) and the NDB scheme as a core part of its technology and digital business practice — not as an occasional add-on.
Technical Understanding
Understanding how a privacy breach occurred technically is essential to assessing the scope of the exposure, the harm caused, and the appropriate remediation. EAGLEGATE’s engineering background provides genuine depth in this analysis.
Speed in Crisis
A privacy breach is a crisis. EAGLEGATE responds at the pace the situation demands. The NDB scheme’s 30-day period is only the outer limit for assessing whether an eligible data breach has occurred — it is not a grace period. Once an entity has reasonable grounds to believe an eligible data breach has occurred, it must notify the OAIC and affected individuals as soon as practicable.
Brisbane & Queensland
We advise businesses and individuals across Brisbane, Queensland, and nationally on privacy breach matters.
Our Insights
- What is a privacy breach?
A privacy breach occurs when personal information held by an organisation is accessed, used, or disclosed without authorisation, or is lost. Under the Privacy Act 1988 (Cth), an eligible data breach occurs where: there has been unauthorised access, disclosure, or loss of personal information; and a reasonable person would conclude the access is likely to result in serious harm to affected individuals.
- What is the Notifiable Data Breaches Scheme?
The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth) requires APP entities to notify the OAIC and affected individuals where an eligible data breach has occurred. Where an entity suspects an eligible data breach may have occurred, it must carry out a reasonable and expeditious assessment — completed within 30 days — of whether an eligible data breach has occurred. If it has reasonable grounds to believe one has, it must notify the OAIC and affected individuals as soon as practicable.
- When must a privacy breach be reported?
An eligible data breach must be notified to the OAIC and to affected individuals as soon as practicable after the entity becomes aware of the breach. The assessment to determine whether a breach is eligible must be completed within 30 days of becoming aware of the potential breach, under section 26WH of the Privacy Act 1988 (Cth).
- What penalties apply for failing to notify?
Failure to comply with the NDB scheme is a breach of the Privacy Act 1988 (Cth). The OAIC can issue determinations and seek civil penalties. The Privacy and Other Legislation Amendment Act 2024 (Cth) strengthened the enforcement framework, increasing civil penalty amounts significantly. Serious or repeated breaches can result in substantial penalties.
- What is a Serious Invasion of Privacy?
A serious invasion of privacy is a statutory tort introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) and contained in Schedule 2 to the Privacy Act 1988 (Cth), which commenced on 10 June 2025. An individual (but not a corporation) may sue where another person intrudes upon their seclusion or misuses information about them, the individual had a reasonable expectation of privacy, the invasion was intentional or reckless and serious, and the public interest in the individual’s privacy outweighs any countervailing public interest (and no defences apply). The tort is actionable without proof of damage, and remedies include injunctions and damages, including damages for emotional distress. It applies whether or not the person responsible is an APP entity.
- When should legal advice be obtained?
Immediately upon discovering or suspecting a privacy breach. The 30-day period under the NDB scheme is the maximum time to assess whether an eligible data breach has occurred, not a window to delay; once the entity has reasonable grounds to believe an eligible data breach has occurred, it must notify the OAIC and affected individuals as soon as practicable. Legal advice shapes the response from the outset.
General information only. Not legal advice. For advice specific to your situation, contact EAGLEGATE Lawyers.
