Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Reporting obligations (the NDB scheme) The NDB scheme requires APP entities to notify both affected individuals and the OAIC where there are reasonable grounds to believe that an “eligible data breach” has occurred. In short, as per Section 26WE(2) of the Privacy Act, an “eligible data breach” occurs where: • there is unauthorised access to/disclosure of per - sonal information and a reasonable person would conclude that this “would be likely to result in serious harm to any of the individuals to whom the information relates”; or • personal information is lost in circumstances where a reasonable person would conclude that unau - thorised access to/disclosure of it is likely to occur and, were it to occur, it “would be likely to result in serious harm to any of the individuals to whom the information relates”. However, Section 26WF of the Privacy Act creates an exception to reporting such an incident, where the entity in question takes remedial action to ensure that the breach does not cause serious harm to the indi - viduals concerned. Notably, specific data breaches related to certain health records are excluded from this scheme and are to be addressed under Section 75 of the My Health Records Act (see 6.3 Cybersecurity in the Healthcare Sector ). The ACSC provides an overarching definition for cybersecurity events in its Guidelines for Cyber Security Incidents. In these Guidelines, a cybersecu - rity event is “an occurrence of a system, service or network state indicating a possible breach of security policy, failure of safeguards or a previously unknown situation that may be relevant to security”. While there is no general legislative definition of a cybersecurity event, the SOCI Act in Section 12M provides a limited, more complex definition. Statutory tort Since 2024, the Privacy Act has contained a statutory tort for serious invasions of privacy, giving individuals a route to seek redress for privacy harms in the courts.

At present, Australia does not operate mandatory, sector-specific cybersecurity certification schemes for industries such as the automotive sector, nor does cybersecurity certification generally operate as a con - dition of market access outside defined government procurement contexts. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection The Privacy Act Scope Federally, data containing personal information is protected under the Privacy Act, which regulates the handling of this information by “APP entities”. At this juncture, it is important to note two definitions. • “Personal information” under the Privacy Act is defined broadly as information or an opinion about an identified or reasonably identifiable individual. It is not required to be true or recorded in a material form. Personal information also includes “sensi - tive information”, which includes information or opinions on an individual’s race, ethnicity, politics, religion, sexual orientation, health, trade associa - tions, and criminal records. Sensitive information is often afforded a higher level of protection than other personal information. • “APP entities” are, subject to some exceptions, federal government agencies, private sector organ - isations with an annual turnover of over AUD3 million, and smaller entities with data-intensive business practices (including private health pro - viders, businesses that sell or purchase personal information, and service providers to the federal government). Schedule 1 of the Privacy Act contains 13 Austral - ian Privacy Principles, which are minimum standards for processing and handling personal information by APP entities. The Privacy Act also requires manda - tory reporting for certain APP breaches under the NDB scheme. Breaches of the Privacy Act may result in investigation and enforcement action by the OAIC.

23 CHAMBERS.COM

Powered by