N

News

Australia’s Proposed 72-Hour Breach Reporting Rule: Is Your Organisation Ready?

What happens when the breach reporting clock starts while the investigation is still moving?

Australia may soon find out under the Attorney-General’s Department’s exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, part of a broader package of proposed Tranche 2 privacy reforms. The draft would give entities covered by the Privacy Act 72 hours to notify the Information Commissioner once they have reasonable grounds to believe an eligible data breach has occurred.

The proposal is not yet law. Consultation closed on 18 September 2026, and the exposure draft remains subject to further consideration by government before the reforms are finalised. Its details may therefore still change. Even so, it raises an immediate operational question for Australian organisations: can evidence, legal advice and accountable decisions move quickly enough to support a defensible notification while the investigation continues?


The clock starts before the full picture is clear

The clock would not start when a security alert first appears. It would begin once an entity becomes aware that there are reasonable grounds to believe an eligible data breach has occurred.

An initial investigation may be needed to determine whether personal information was accessed, disclosed or lost, and whether serious harm is likely.

Once that threshold is met, the entity would have 72 hours to notify the Office of the Australian Information Commissioner, even if the investigation is still unfolding. The draft would replace the current requirement to notify “as soon as practicable” with a fixed deadline.

If complete information could not be assembled in time, the draft would allow an incomplete statement accompanied by written notice identifying what is missing and why supplying it was impossible or impracticable. That offers some flexibility, but it would not allow notification to wait until every detail is confirmed.

The draft would also require the entity to notify affected individuals at the same time it gives the statement to the Commissioner, where practicable, or otherwise as soon as practicable afterwards.

Failing to submit a statement within 72 hours could attract an infringement notice or compliance notice.


The 30-day assessment obligation remains for suspected breaches

Under the current Notifiable Data Breaches framework, an entity that has reasonable grounds to suspect, but not yet reasonable grounds to believe, that an eligible data breach occurred must conduct a reasonable and expeditious assessment, taking all reasonable steps to complete it within 30 days. The exposure draft does not repeal or amend that assessment obligation.

The two timeframes would apply at different stages:

  • Assessment period: Applies while the entity has reasonable grounds to suspect an eligible data breach but has not yet reached the belief threshold.

  • Notification period: Begins once the entity becomes aware that there are reasonable grounds to believe an eligible data breach occurred, giving it 72 hours to notify the OAIC.

The 30-day period would not operate as a waiting period or extend the notification deadline. If the evidence supports the belief threshold earlier, the 72-hour clock starts earlier. Organisations will need a clear record of when and how that threshold was reached.


A legal deadline exposes operational gaps

Meeting the proposed deadline would depend on the quality and coordination of the response behind it. Legal assessments are only as sound as the technical evidence behind them, while timely decisions depend on that evidence reaching the right people quickly. A delay at any point can consume valuable time within the reporting window.

For an Australian critical infrastructure operator, one breach may start several reporting clocks at once. The proposed reform would sit alongside reporting periods already used elsewhere in Australian cyber regulation. Privacy, cyber security, contractual and sector-specific obligations do not necessarily share the same threshold or deadline.

That creates a practical test for security operators and business leaders. Capable teams and documented procedures are not enough if evidence, advice and decisions move through the organisation too slowly.

The 72-hour deadline would test whether the organisation can operate as one response function. It is not simply a test of how quickly its legal team can prepare a notification.


Seven Questions Can Expose the Gap

The quickest way to find out whether the first 72 hours will work is to rehearse them. A response plan can look complete until evidence is missing, an approver is unavailable or the breach happens outside business hours.

A useful tabletop exercise should answer seven questions:

  1. How quickly can the breach be classified and escalated?

  2. Can the evidence needed for a defensible decision be retrieved in time?

  3. Who decides when the notification threshold has been reached?

  4. How is the start of the 72-hour period recorded?

  5. Who prepares, approves and submits the notification when information is incomplete?

  6. How are overlapping privacy, cyber and sector-specific obligations coordinated?

  7. Does the process still work at 2 am on a Sunday, outside business hours?

These questions test more than the written plan. They show whether evidence, authority and communication can move quickly enough when the facts are incomplete.

If the answers are unclear, the readiness gap already exists. It simply has not been tested yet.


Readiness Starts Before the Reform Becomes Law

At Secure ISS, we see the proposed 72-hour rule as a test of the whole response chain, because a notification can only move as quickly as the evidence, advice and decisions behind it.

Through Lumara, our Australian SOC provides 24/7 threat detection and response, real-time visibility across existing security tools, and reporting that helps organisations investigate incidents, preserve evidence and make faster, more defensible decisions. This gives security, legal and leadership teams clearer information to work from while the facts are still emerging and the reporting clock is running.

The proposal may still change, but organisations already need to know whether their detection, escalation and reporting processes can work together under pressure.

Let’s talk about how Lumara can strengthen visibility, incident response and reporting across the first 72 hours of a breach.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.