Data-breach response plans for real estate agencies: what the NDB scheme requires
A data-breach response plan is a written plan for detecting, containing, assessing and notifying a data breach. Agencies need one because they hold tenant, landlord and buyer ID and financial data, and the Notifiable Data Breaches scheme requires notifying the OAIC and affected people of eligible breaches.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is a data-breach response plan?
A data-breach response plan is a short, written document that sets out what your agency will do when personal information is lost, accessed or disclosed without authorisation. It names who is responsible, how staff report a suspected breach, how you contain and assess it, and how you decide whether you must notify anyone.
The point of writing it down in advance is speed. When a laptop goes missing or a rent roll lands in the wrong inbox, you do not want to be inventing a process under pressure. A plan means anyone in the office knows the first three phone calls to make and who owns the decision.
Having a documented plan is also part of taking the "reasonable steps" to protect personal information that Australian Privacy Principle (APP) 11 expects of you.
When does the NDB scheme apply?
The Notifiable Data Breaches (NDB) scheme sits in Part IIIC of the Privacy Act 1988 (Cth). It applies when you have an eligible data breach.
An eligible data breach is:
- unauthorised access to, unauthorised disclosure of, or loss of, personal information; and
- that is likely to result in serious harm to any of the affected individuals; and
- the agency has not been able to prevent that likely harm through remedial action.
The "serious harm" test is the pivot. Serious harm can be financial, physical, psychological, reputational or emotional: for example identity theft from exposed ID documents, or a person put at risk of harm because their new home address became public. If quick remedial action removes the likelihood of serious harm (say, you recall an email before it is opened, or a lost device was encrypted), the breach may not be "eligible" and notification may not be required.
The suspect-then-assess rule matters here. If you only suspect there may be an eligible breach but are not sure, you must carry out a reasonable and expeditious assessment, and take all reasonable steps to complete that assessment within 30 days. You do not get to wait and see.
The four steps: contain, assess, notify, review
| Step | What it means for your agency |
|---|---|
| Contain | Stop the breach and limit the damage. Recall the email, disable the compromised login, reset passwords, secure or remotely wipe the lost device, take a public spreadsheet offline. |
| Assess | Work out what information was involved, who is affected, and whether serious harm is likely. This is the reasonable and expeditious assessment; aim to finish it well inside 30 days. |
| Notify | If the breach is eligible, notify the OAIC and the affected individuals as soon as practicable. Tell people what happened and what they should do to protect themselves. |
| Review | Once the immediate response is done, work out how it happened and fix the gap (training, a system setting, or a process change) so it does not recur. |
Assign each step an owner before anything goes wrong. In a small agency that might all be the principal or licensee; the important thing is that it is decided in advance, not argued over on the day.
What a court has actually said about getting this wrong
There is now one judgment on this, and it is worth knowing because it is the only one.
The Court was explicit about why it matters that there is only one:
"APP 11.1(b) has not been the subject of any previous judicial consideration." · AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [45]
At [51] the Court set out what it weighs in deciding whether steps were reasonable: the sensitivity of the information, the potential harm to individuals, the size and sophistication of the APP entity, the cybersecurity environment, and any previous threats. The size-and-sophistication limb is the one that matters to a small agency: what is reasonable for you is measured against your size, not against a national laboratory network. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (AustLII) the Federal Court imposed a A$5.8 million civil penalty over a breach affecting more than 223,000 people. It was the first civil penalty proceeding brought under the Privacy Act in the Act's history, and the Court noted that APP 11.1(b) had never previously been considered judicially.
Two of the three contraventions were not the breach itself. They were the response:
- A$800,000 for failing to carry out a reasonable and expeditious assessment within 30 days.
- A$800,000 for failing to notify the Commissioner as soon as practicable. The company learned on 16 June that data was on the dark web and notified on 10 July; the Court accepted it had been practicable to notify within two to three days.
"As soon as practicable" is measured in days, not weeks. That is the clearest guidance available on a phrase the Act does not define.
"Our IT provider handles that" is not an answer
The most useful part of the judgment for a small agency is what it says about outsourcing. The Court held that a reasonable-steps obligation is "not capable of being discharged simply by delegating it to another entity and doing nothing more" (at 52(b)), and found that the company's "overreliance … on third party service providers and its failure to have in place adequate procedures to detect and respond by itself" was central to the breach (at 53(g)).
The company had engaged a specialist cybersecurity firm. That firm reviewed 3 of at least 127 affected computers, told the company the ransom threat was probably "merely a scare tactic", and closed its investigation. The company relied on that advice and concluded there was no eligible breach. The national cyber agency then told them twice that there had been one.
If your agency's answer to "who assesses a suspected breach" is the name of your IT contractor or your CRM vendor, that is the arrangement the Court described. You still need your own process for deciding whether an assessment has actually been done properly.
The reassuring part
The Court set out what informs "reasonable steps" (at [51]): the sensitivity of the information, the potential harm to individuals, the size and sophistication of the entity, the cybersecurity environment, and any previous threats. A small agency is not held to the standard of a company with a A$995 million turnover and 5,400 staff, which is what this respondent was. The standard is proportionate, but having no process at all is not proportionate to anything.
What does a breach look like in a real-estate agency?
Breaches are rarely dramatic hacks. In an agency they usually look like:
- a lost or stolen laptop or USB stick holding tenancy files;
- a hacked CRM or email account;
- an email with a rent roll or ID documents sent to the wrong recipient;
- identity documents collected for AML customer due diligence being left exposed;
- a trust-account or rental-application spreadsheet accidentally left publicly accessible.
Each of these involves exactly the kind of information that can cause serious harm: full names, addresses, dates of birth, driver licences, passport details, bank details. That is why property is a sector the regulator watches. The OAIC has been active here: it took enforcement action over unfair data collection in Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 (22 November 2024). That case was about unfair collection rather than a data breach, but it is a clear sign the OAIC is willing to enforce against property-sector operators. You can read it on AustLII.
Who do you notify, and when?
If an assessment confirms an eligible data breach, there are two notifications, and both should happen as soon as practicable:
- The OAIC: through a statement prepared for the Commissioner setting out the breach, the information involved, and the steps affected people should take.
- The affected individuals: the tenants, landlords, buyers, vendors or applicants whose information was involved, so they can act to protect themselves (for example, watch for identity theft or change passwords).
If it is not practicable to contact each affected person individually, there are other permitted ways to notify, but the default is to tell the people whose information was exposed, promptly and in plain language.
How do you get ready?
A little preparation makes the difference between a contained incident and a reportable disaster.
- Write the plan down and keep it somewhere staff can find it fast: names, roles and the first steps for each of contain, assess, notify and review.
- Reduce what you hold: the fewer ID documents and financial records sitting in inboxes and shared drives, the smaller any breach. This is squarely within the "reasonable steps" APP 11 expects.
- Train the team to recognise and report a suspected breach quickly, so the 30-day assessment clock is on your side rather than against you.
- Review the plan once a year and after any near-miss.
If you are not sure where your agency's exposure sits, a short self-audit of where personal information lives and who can reach it is a sensible place to start.
Common questions
When does the Notifiable Data Breaches scheme apply to a real estate agency?
It applies when you have an eligible data breach: unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to any affected individual, and the agency has not been able to prevent that likely harm through remedial action.
How long do I have to assess a suspected breach?
If you only suspect there may be an eligible breach but are not sure, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. You do not get to wait and see.
What does a data breach usually look like in an agency?
Usually a lost or stolen laptop or USB holding tenancy files, a hacked CRM or email account, an email with a rent roll or ID documents sent to the wrong recipient, exposed AML identity documents, or a trust-account or rental-application spreadsheet left publicly accessible.
Who do I have to notify, and when?
If an assessment confirms an eligible data breach, you notify both the OAIC (through a statement prepared for the Commissioner) and the affected individuals (the tenants, landlords, buyers, vendors or applicants whose information was involved) as soon as practicable.