Data-breach response plans for real estate agencies: what the NDB scheme requires
A data-breach response plan is a written plan for detecting, containing, assessing and notifying a data breach. Agencies need one because they hold tenant, landlord and buyer ID and financial data, and the Notifiable Data Breaches scheme requires notifying the OAIC and affected people of eligible breaches.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is a data-breach response plan?
A data-breach response plan is a short, written document that sets out what your agency will do when personal information is lost, accessed or disclosed without authorisation. It names who is responsible, how staff report a suspected breach, how you contain and assess it, and how you decide whether you must notify anyone.
The point of writing it down in advance is speed. When a laptop goes missing or a rent roll lands in the wrong inbox, you do not want to be inventing a process under pressure. A plan means anyone in the office knows the first three phone calls to make and who owns the decision.
Having a documented plan is part of the "steps as are reasonable in the circumstances" that APP 11.1(b) requires. In AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [53] the Court recorded, as part of the reasonable-steps failure, incident playbooks that "did not clearly define roles and responsibilities for incident response efforts" and contained "limited detail on containment processes". Roles and containment are the two things a response plan is for.
When does the NDB scheme apply?
The Notifiable Data Breaches (NDB) scheme sits in Part IIIC of the Privacy Act 1988 (Cth) (see the OAIC's NDB overview). Section 26WE(1) scopes it to APP entities: if the small-business exemption still covers your agency, Part IIIC does not reach you. If it does not, an eligible data breach triggers the scheme.
An eligible data breach is:
- unauthorised access to, or unauthorised disclosure of, personal information, where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to; or
- loss of personal information in circumstances where unauthorised access or disclosure is likely to occur and, if it did, would be likely to result in that serious harm.
The "serious harm" test is the pivot. Serious harm can be financial, physical, psychological, reputational or emotional: for example identity theft from exposed ID documents, or a person put at risk of harm because their new home address became public. Remedial action is not part of that definition. It is a separate exception in s 26WF: if you act before the access or disclosure causes serious harm and, as a result, a reasonable person would conclude serious harm is no longer likely, the breach "is not, and is taken never to have been" an eligible data breach. Recalling an email before it is opened, or wiping a lost device, is what s 26WF is for.
The suspect-then-assess rule matters here. Once you are aware of reasonable grounds to suspect an eligible breach, s 26WH(2) says the entity must carry out a reasonable and expeditious assessment and take all reasonable steps to ensure it is completed within 30 days. That duty sits on you, not on the OAIC, and you do not get to wait and see.
The four steps: contain, assess, notify, review
| Step | What it means for your agency |
|---|---|
| Contain | Stop the breach and limit the damage. Recall the email, disable the compromised login, reset passwords, secure or remotely wipe the lost device, take a public spreadsheet offline. |
| Assess | Work out what information was involved, who is affected, and whether serious harm is likely. Section 26WH(2) requires a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 days. |
| Notify | If the breach is eligible, notify the OAIC and the affected individuals as soon as practicable. Tell people what happened and what they should do to protect themselves. |
| Review | Once the immediate response is done, work out how it happened and fix the gap (training, a system setting, or a process change) so it does not recur. |
Assign each step an owner before anything goes wrong. In a small agency that might all be the principal or licensee; the important thing is that it is decided in advance, not argued over on the day.
What a court has actually said about getting this wrong
There is now one judgment on this, and it is worth knowing because it is the only one.
The Court was explicit about why it matters that there is only one:
"APP 11.1(b) has not been the subject of any previous judicial consideration." · AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [48]
In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (AustLII) the Federal Court imposed a A$5.8 million civil penalty over a breach affecting more than 223,000 people. At [6] the Court recorded it as the first civil penalty proceeding brought by the Commissioner in the history of the Act.
At [50] the Court set out the circumstances that inform whether steps were reasonable: the sensitivity of the information, the potential harm to individuals, the size and sophistication of the APP entity, the cybersecurity environment, and any previous threats. The size-and-sophistication limb is the one that matters to a small agency: what is reasonable for you is measured against your size, not against a national pathology network.
Two of the three penalty components were not the breach itself. They were the response:
- A$800,000 for the s 26WH(2) contravention: failing to take reasonable steps to ensure a reasonable and expeditious assessment was carried out within 30 days.
- A$800,000 for failing to notify the Commissioner as soon as practicable. The company learned on 16 June that data was on the dark web and notified on 10 July; the Court accepted it had been practicable to notify within two to three days.
The Act does not define "as soon as practicable." The only benchmark a court has accepted is the two to three days that company admitted was practicable on its own facts. How long would your agency take?
"Our IT provider handles that" is not an answer
The most useful part of the judgment for a small agency is what it says about outsourcing. At [51], point (b), the Court adopted the reasonable-steps case law under which the obligation is "not capable of being discharged simply by delegating it to another entity and doing nothing more" (Clarke v Great Southern Finance [2014] VSC 516 at [543]), and at [52], point (g), it found the company's "overreliance … on third party service providers and its failure to have in place adequate procedures to detect and respond by itself" was one of the matters establishing the APP 11.1(b) breach.
The company had engaged a specialist cybersecurity firm. At [77] the Court found that firm monitored only 3 of the at least 127 computers hit by the ransomware; at [23] it had told the company the ransom threat was "merely a scare tactic"; at [27] it closed its investigation. By 21 March 2022 the company had determined there was no eligible data breach [30]. The national cyber agency then contacted it twice: in March to say Medlab may have been a ransomware victim and to remind it of the notification obligation [31], and in June to say the data had been published [35].
If your agency's answer to "who assesses a suspected breach" is the name of your IT contractor or your CRM vendor, that is the arrangement the Court described. You still need your own process for deciding whether an assessment has actually been done properly.
The reassuring part
The standard is proportionate. At [11] and [12] the Court recorded a respondent with about 5,400 staff and A$995.6 million in revenue for the year to June 2022; the size-and-sophistication limb at [50] means a suburban agency is not measured against that. Proportionate is not the same as nothing, though: having no documented process at all is not proportionate to anything.
What does a breach look like in a real-estate agency?
Breaches are rarely dramatic hacks. In an agency they usually look like:
- a lost or stolen laptop or USB stick holding tenancy files;
- a hacked CRM or email account;
- an email with a rent roll or ID documents sent to the wrong recipient;
- identity documents collected for AML customer due diligence being left exposed;
- a trust-account or rental-application spreadsheet accidentally left publicly accessible.
Each of these involves exactly the kind of information that can cause serious harm: full names, addresses, dates of birth, driver licences, passport details, bank details. The Commissioner has acted against a property-sector operator over how it collected that kind of data: in Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 (22 November 2024) she found breaches of APP 1.3, 3.5, 5.1 and 10.2 and ordered the business to stop collecting and distributing the leads, destroy its leads lists within 30 days, publish a written apology and update its privacy policy. That was unfair collection rather than a data breach, and the respondent was a property-education business rather than an agency. You can read it on AustLII.
Who do you notify, and when?
If an assessment confirms an eligible data breach, there are two notifications, and the Act sets a different starting gun for each:
- The OAIC: through a statement prepared for the Commissioner setting out the breach, the information involved, and the steps affected people should take.
- The affected individuals: the tenants, landlords, buyers, vendors or applicants whose information was involved, so they can act to protect themselves (for example, watch for identity theft or change passwords).
Section 26WL(2) is a cascade, not a single duty. If it is practicable to notify every individual the information relates to, you notify all of them. If that is not practicable but it is practicable to notify only those at risk from the breach, you notify that narrower group. Only if neither is practicable do you publish the statement on your website and take reasonable steps to publicise it.
How do you get ready?
A little preparation makes the difference between a contained incident and a reportable disaster.
- Write the plan down and keep it somewhere staff can find it fast: names, roles and the first steps for each of contain, assess, notify and review.
- Reduce what you hold: the fewer ID documents and financial records sitting in inboxes and shared drives, the smaller any breach. This is squarely within the "reasonable steps" APP 11 expects.
- Train the team to recognise and report a suspected breach quickly, so the 30-day assessment clock is on your side rather than against you.
- Review the plan once a year and after any near-miss.
If you are not sure where your agency's exposure sits, a short self-audit of where personal information lives and who can reach it is a sensible place to start.
Common questions
When does the Notifiable Data Breaches scheme apply to a real estate agency?
It applies when you have an eligible data breach: unauthorised access to or disclosure of personal information, or loss of it in circumstances where unauthorised access or disclosure is likely, where a reasonable person would conclude serious harm to any affected individual is likely (s 26WE(2)). Remedial action that removes that likelihood is a separate exception in s 26WF, under which the breach "is not, and is taken never to have been" eligible.
How long do I have to assess a suspected breach?
If you only suspect there may be an eligible breach but are not sure, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. You do not get to wait and see.
What does a data breach usually look like in an agency?
Usually a lost or stolen laptop or USB holding tenancy files, a hacked CRM or email account, an email with a rent roll or ID documents sent to the wrong recipient, exposed AML identity documents, or a trust-account or rental-application spreadsheet left publicly accessible.
Who do I have to notify, and when?
If an assessment confirms an eligible data breach, you give the Commissioner a statement as soon as practicable after becoming aware (s 26WK(2)), then notify individuals as soon as practicable after that statement is prepared (s 26WL(3)). Section 26WL(2) is a cascade: everyone the information relates to if practicable, otherwise only those at risk, otherwise publish the statement on your website and publicise it.