---
title: "Applicable notifiable data breach and privacy obligations for accredited entities"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2024-11/digital_id_guidance_7_-_applicable_notifiable_data_breach_and_privacy_obligations_for_accredited_entities.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

Applicable notifiable data breach and privacy
obligations for accredited entities

Contents
NDB obligations                                                         0
    APP entities                                                        1
    State or Territory government entities                              1
    Small business operators                                            2

Privacy Act NDB scheme                                                  2
Additional notification obligations                                     2
Table: applicable privacy and NDB obligations for accredited entities   3
                                                                                     November 2024


NDB obligations
In Australia’s Digital ID System, all accredited entities providing accredited services have data
breach notification obligations, including small business operators under the Privacy Act 1988
(Cth) (the Privacy Act).

These obligations arise from either the Notifiable Data Breaches (NDB) scheme in Part IIIC of
the Privacy Act, or from state or territory legislation with a comparable data breach
notification scheme.

A data breach occurs when personal information is accessed or disclosed without
authorisation or is lost. For entities covered by the NDB scheme in the Privacy Act, it requires
the entity to notify affected individuals and the OAIC when a data breach involving personal
information is likely to result in serious harm to individuals.

All accredited entities providing accredited services also have obligations under the Digital ID
(Accreditation) Rules 2024 (rule 4.45) to have a data breach response plan, which includes a
communications plan. This plan should ensure clear lines of internal escalation and timely
notifications to affected individuals and third parties in the event of a data breach. See the
OAIC’s guidance on preparing a data breach response plan for further information.

The applicable data breach notification obligations for different entities are set out below.

APP entities
Accredited entities who are APP entities under the Privacy Act will need to comply with the
NDB scheme in the Privacy Act in relation to data breaches affecting their accredited services.
As APP entities, these entities are already subject to the NDB scheme for all their activities.

State or Territory government entities
The applicable data breach notification obligations for a State or Territory government entity
will depend on the entity’s existing obligations.
For accredited entities that are State or Territory agencies covered by a data breach
notification scheme that is comparable to the NDB scheme, that State or Territory scheme
will apply to the entity’s provision of accredited services. Accredited entities in this category
must comply with that State or Territory based notification scheme and should refer to their
State or Territory regulator for further guidance.
For accredited entities that are State or Territory agencies who are not covered by a data
breach notification scheme that is comparable to the NDB scheme, section 40 of the Digital ID
Act 2024 (Cth) (the Digital ID Act) extends the Privacy Act NDB scheme to apply to their
provision of accredited services.

Applicable notifiable data breach and privacy obligations for accredited entities            Page 1
oaic.gov.au
                                                                                      November 2024


Small business operators
For accredited entities who are small business operators under the Privacy Act, section 40 of
the Digital ID Act extends the Privacy Act NDB scheme to apply to their provision of
accredited services.


Privacy Act NDB scheme
As outlined above, the NDB scheme applies to the following entities in connection with their
provision of accredited services:
        -    APP entities
        -    small business operators
        -    State or Territory government agencies that are not already subject to a comparable
             data breach notification scheme.

These State or Territory government agencies and small business operators, who have not
previously been subject to the NDB scheme, must ensure their systems and procedures
comply with the NDB scheme.
The OAIC has detailed guidance on managing data breaches and complying with the NDB
scheme, including a data breach preparation and response guide. See
https://www.oaic.gov.au/privacy/notifiable-data-breaches for a range of resources.


Additional notification obligations
The Digital ID Act creates additional notification obligations where an accredited entity is
required to notify the OAIC or a State or Territory regulator of a data breach.
For entities covered by the NDB scheme in the Privacy Act who are required under s 26WK of
the Privacy Act to notify the OAIC of a data breach, the Digital ID Act requires the entity to give
a copy of that statement to the Digital ID Regulator at the same time as the notification is
given to the OAIC.1
For entities covered by a comparable State or Territory scheme who are required to notify
their State or Territory regulator of a data breach, the Digital ID Act requires the entity to give
a copy of that statement to both the OAIC and the Digital ID Regulator at the same time as the
notification is given to their regulator.2
Following accreditation, providers will be advised on how data breach notifications to the
Digital ID Regulator are to be made.


1
    ss 39(2) and 40(4) of the Digital ID Act.
2
    s 41(2) of the Digital ID Act.


Applicable notifiable data breach and privacy obligations for accredited entities            Page 2
oaic.gov.au
                                                                                                                                                                                    November 2024

     Table: applicable privacy and NDB obligations for accredited entities
                                General privacy obligations                     Additional privacy                 NDB scheme obligations                          General privacy
                                (when providing accredited                    safeguards (Digital ID             (when providing accredited                    obligations (for all other
1.
                                         services)                            Act: sections 44 – 56)                     services)3                            non-accredited services
                                                                                                                                                                 the entity provides)
           Accredited                        APPs                                Additional privacy                 Privacy Act 1988: Part IIIC                              APPs
            entity –               Part 4.3 of the Digital ID                    safeguards apply                            scheme
         Commonwealth             (Accreditation Rules) 2024
          Government
             entity
          Accredited                Relevant state/territory                     Additional privacy                Comparable state/territory                   Relevant state/territory
         entity – State              privacy law (providing                      safeguards apply                     notifiable data breach                      privacy law where
         and Territory            comparable protection to                                                                    scheme                                  applicable
         government                           APPs)                                                                             OR
             entity                            OR                                                                   Privacy Act 1988: Part IIIC
                                  APP equivalent agreement                                                         scheme (if not covered by a
                                 (see sections 34 and 36(2)(c)                                                     comparable state/territory
                                      of the Digital ID Act)                                                        scheme (see section 40 of
                                    Part 4.3 of the Digital ID                                                          the Digital ID Act
                                  (Accreditation Rules) 2024
           Accredited                        APPs                                Additional privacy                 Privacy Act 1988: Part IIIC                              APPs
         entity – private          Part 4.3 of the Digital ID                    safeguards apply                            scheme
           sector APP             (Accreditation Rules) 2024
              entity


     3
      In addition to the applicable data breach notification scheme, the Digital ID Act creates an additional obligation for accredited entities to give a copy of a data breach notification
     statement to the Digital ID Regulator at the same time as the statement is provided to the relevant privacy regulator – see ss 39, 40 and 41.


     Applicable notifiable data breach and privacy obligations for accredited entities                                                                                                          Page 3
     oaic.gov.au
                                                                                                                                               November 2024
   Accredited                     APPs (treated as                         Additional privacy   Privacy Act 1988: Part IIIC       Nil (only treated as
 entity – privacy            organisations as set out in                   safeguards apply     scheme (see section 40 of     organisations to the extent
 sector non-APP             section 35A of the Digital ID                                           the Digital ID Act)           they are providing
  entity (small                         Act)                                                                                     accredited services –
    business                  Part 4.3 of the Digital ID                                                                      section 33 of the Digital ID
    operator)                (Accreditation Rules) 2024                                                                                   Act)


Applicable notifiable data breach and privacy obligations for accredited entities                                                                     Page 4
oaic.gov.au
