A data breach is a legal event, not just an IT incident.

Regulatory obligations. Notification requirements. Liability.

Notifiable Data Breaches. Privacy Act. OAIC.

Every privacy law obligation addressed

Respond fast. Report correctly. Minimise liability.

EAGLEGATE. Privacy breach lawyers Brisbane.

Privacy Breaches Lawyers Brisbane

A privacy breach triggers legal obligations under Australian law — including mandatory reporting to the OAIC. EAGLEGATE advises businesses and individuals on privacy breach response, regulatory obligations and privacy dispute resolution across Brisbane and Queensland.

A privacy breach is not solely an IT problem. It is a legal event that triggers reporting obligations, creates regulatory exposure, generates potential civil liability, and requires a response that is both technically sound and legally precise. Under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme, eligible data breaches must be reported to the Office of the Australian Information Commissioner (OAIC) and, in most cases, to affected individuals — within a timeframe measured in days, not weeks.

EAGLEGATE advises businesses and individuals on privacy breach response — from the immediate steps following discovery of a breach through to regulatory interaction with the OAIC, managing potential civil claims from affected individuals, and implementing structural measures to reduce future privacy risk. Nicole Murdoch’s engineering and technology background means EAGLEGATE understands how privacy breaches occur technically — not just how the law responds to them.

Every hour after a privacy breach is an hour the obligation to act is mounting. The law is specific about what must be done, by when, and to whom.

Our Expertise

Key Privacy Breach Expertise — Respond, Report, Protect

EAGLEGATE advises on every stage of a privacy breach response.

The Privacy Act 1988 and the Australian Privacy Principles

The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) govern the collection, use, disclosure, and storage of personal information by APP entities — including businesses with annual turnover above $3 million and certain other categories. APP 11 requires APP entities to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure.

The Notifiable Data Breaches Scheme

Under Part IIIC of the Privacy Act 1988 (Cth), an APP entity that becomes aware of an eligible data breach must notify the OAIC and affected individuals. An eligible data breach occurs where there has been: unauthorised access to or disclosure of personal information; and a reasonable person would conclude that the access or disclosure is likely to result in serious harm to any of the affected individuals.

Where an entity believes an eligible data breach may have occurred, it must undertake an assessment within 30 days. If the breach is confirmed as eligible, the entity must notify the OAIC and affected individuals as soon as practicable.

What Constitutes Serious Harm

Serious harm under the NDB scheme is not defined exhaustively in the Privacy Act 1988 (Cth) but includes physical, psychological, emotional, financial, and reputational harm. The OAIC’s guidance indicates that breaches involving financial information, health information, identity documents, or information enabling fraud or identity theft are more likely to give rise to serious harm. EAGLEGATE assesses the serious harm question as a priority step in breach response.

Regulatory Interaction with the OAIC

Where a privacy breach is notified to the OAIC, the OAIC may undertake a regulatory assessment or investigation. EAGLEGATE advises businesses on their obligations during OAIC engagement — including what must be disclosed, what remediation steps are expected, and how to manage the investigation process. The Privacy Act 1988 (Cth) gives the OAIC broad investigative powers and the ability to issue determinations requiring remediation and awarding compensation.

Civil Liability for Privacy Breaches

Beyond the regulatory regime, individuals now have a direct civil remedy for privacy harm. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy, contained in Schedule 2 to the Privacy Act 1988 (Cth) and commenced on 10 June 2025. An individual may sue where another person has invaded their privacy — by intruding upon their seclusion or by misusing information about them — in circumstances where the individual had a reasonable expectation of privacy, the invasion was intentional or reckless, the invasion was serious, and the public interest in the individual’s privacy outweighs any countervailing public interest. The tort is actionable without proof of damage and is not confined to APP entities, but only individuals, not corporations, may bring a claim. Remedies include injunctions and damages, including damages for emotional distress, with damages for non-economic loss capped broadly in line with the cap that applies in defamation. A complaint to the OAIC, which may lead to compensation through its complaint resolution process, remains a separate avenue.

Our Approach

1. Contain and Assess

The immediate steps following discovery of a privacy breach are to contain the breach (stop the ongoing exposure of personal information) and assess its scope, nature, and likely harm. EAGLEGATE advises on this initial assessment in parallel with any IT response.

2. Determine Reporting Obligations

We advise on whether the breach is an eligible data breach requiring notification under the NDB scheme, and if so, prepare and submit the notification to the OAIC and prepare the communication to affected individuals.

3. Manage Regulatory Interaction

Where the OAIC investigates or requests information, EAGLEGATE manages the interaction — advising on what is required and how to respond appropriately.

4. Reduce Future Risk

We advise on the structural and contractual measures to reduce privacy risk — including data minimisation practices, privacy impact assessments for new projects, and supplier contract terms that address data handling obligations.

Why Choose EAGLEGATE

Privacy Act Expertise

EAGLEGATE advises on the Privacy Act 1988 (Cth) and the NDB scheme as a core part of its technology and digital business practice — not as an occasional add-on.

Technical Understanding

Understanding how a privacy breach occurred technically is essential to assessing the scope of the exposure, the harm caused, and the appropriate remediation. EAGLEGATE’s engineering background provides genuine depth in this analysis.

Speed in Crisis

A privacy breach is a crisis. EAGLEGATE responds at the pace the situation demands. The NDB scheme’s 30-day period is only the outer limit for assessing whether an eligible data breach has occurred — it is not a grace period. Once an entity has reasonable grounds to believe an eligible data breach has occurred, it must notify the OAIC and affected individuals as soon as practicable.

Brisbane & Queensland

We advise businesses and individuals across Brisbane, Queensland, and nationally on privacy breach matters.

Our Insights

Book a Consultation

Book a 30‑minute confidential consultation.

Book a Consultation

A privacy breach has a 30-day assessment window. Act immediately.

Book a Consultation