OAIC releases Notifiable Data Breaches Scheme 12-month insights report
The Office of the Australian Information Commissioner has released a report which provides interesting and helpful insights into the first year of the Notifiable Data Breaches Scheme.
Within the NDB Report, the OAIC:
- examines trends that have emerged under the NDB Scheme, including the common causes of data breaches;
- reflects on the purposes of the NDB Scheme;
- provides guidance on proactive steps that can be taken for better prevention of data breaches in the future; and
- outlines the OAIC’s expectations for the second year of operation of the NDB Scheme.
Some of the key statistics and trends identified in the NDB Report include:
- 964 eligible data breaches have been notified under the NDB Scheme from 1 April 2018 to 31 March 2019;
- there has been a 712 percent increase in notifications since the introduction of the NDB Scheme;
- in respect of cyber incidents, 153 breaches were attributed to phishing;
- health service providers are the top reporting sector; and
- in terms of the causes of data breaches:
- 60 percent of data breaches were malicious or criminal attacks;
- 35 percent of data breaches were attributed to human error; and
- the remaining 5 percent of data breaches were caused by system error.
Importantly, the OAIC indicates that as the NDB Scheme moves into its second year, the OAIC, amongst other things:
- expects entities to understand the underlying causes of data breaches and take proactive steps to prevent them from occurring;
- encourages entities to move beyond compliance to support consumers (such as supporting affected individuals to take steps to minimise or prevent harm in a meaningful way); and
- will ‘take a proportionate and evidence‑based regulatory approach in relation to the NDB scheme, including by exercising our enforcement powers where necessary’.
It’s not possible to cover all of the matters dealt with in the report within this post, so you may wish to take a look at the report for yourself.
Need guidance on data issues?
Contact the Cyber & Data Resilience team.
By Jack Evansand Stanley Yu
Keep up to date with our legal insights and events
Sign upRecent articles
Reform to Australia’s merger clearance regime
By Ron Smooker, Shaun Temby, Jacqueline Picone, and Oliver Wahlstrom
A new mandatory, suspensory merger review system conducted by the ACCC comes into effect in Australia on 1 January 2026.
Important changes to the Workplace Injury Rehabilitation and Compensation Act 2013 concerning workers’ compensation in Victoria
By Catherine Dunlop, Jessica Mourney
From 31 March 2024, amendments to the Victorian workers’ compensation scheme took effect
A step closer to mandatory climate-related disclosure
By Ron Smooker, Rosamond Sayer, Samantha Murphy, and Joseph Fox
The Treasurer introduced the Treasury Laws Amendment (Financial Market Infrastructure and Other Measures) Bill 2024.
Gomeroi v Santos: New guidance on good faith negotiation, and the relevance of climate change
By Susanne Rakoczy, and Larissa Svetlov
We explore Gomeroi People v Santos NSW Pty Ltd and Santos NSW (Narrabri Gas) Pty Ltd [2024] FCAFC 26 (Gomeroi Appeal).
Consultant
Sydney