Skip to content

Data-breach response plans for real estate agencies: what the NDB scheme requires

A data-breach response plan is a written plan for detecting, containing, assessing and notifying a data breach. Agencies need one because they hold tenant, landlord and buyer ID and financial data, and the Notifiable Data Breaches scheme requires notifying the OAIC and affected people of eligible breaches.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What is a data-breach response plan?

A data-breach response plan is a short, written document that sets out what your agency will do when personal information is lost, accessed or disclosed without authorisation. It names who is responsible, how staff report a suspected breach, how you contain and assess it, and how you decide whether you must notify anyone.

The point of writing it down in advance is speed. When a laptop goes missing or a rent roll lands in the wrong inbox, you do not want to be inventing a process under pressure. A plan means anyone in the office knows the first three phone calls to make and who owns the decision.

Having a documented plan is also part of taking the "reasonable steps" to protect personal information that Australian Privacy Principle (APP) 11 expects of you.

When does the NDB scheme apply?

The Notifiable Data Breaches (NDB) scheme sits in Part IIIC of the Privacy Act 1988 (Cth). It applies when you have an eligible data breach.

An eligible data breach is:

The "serious harm" test is the pivot. Serious harm can be financial, physical, psychological, reputational or emotional: for example identity theft from exposed ID documents, or a person put at risk of harm because their new home address became public. If quick remedial action removes the likelihood of serious harm (say, you recall an email before it is opened, or a lost device was encrypted), the breach may not be "eligible" and notification may not be required.

The suspect-then-assess rule matters here. If you only suspect there may be an eligible breach but are not sure, you must carry out a reasonable and expeditious assessment, and take all reasonable steps to complete that assessment within 30 days. You do not get to wait and see.

The four steps: contain, assess, notify, review

StepWhat it means for your agency
ContainStop the breach and limit the damage. Recall the email, disable the compromised login, reset passwords, secure or remotely wipe the lost device, take a public spreadsheet offline.
AssessWork out what information was involved, who is affected, and whether serious harm is likely. This is the reasonable and expeditious assessment; aim to finish it well inside 30 days.
NotifyIf the breach is eligible, notify the OAIC and the affected individuals as soon as practicable. Tell people what happened and what they should do to protect themselves.
ReviewOnce the immediate response is done, work out how it happened and fix the gap (training, a system setting, or a process change) so it does not recur.

Assign each step an owner before anything goes wrong. In a small agency that might all be the principal or licensee; the important thing is that it is decided in advance, not argued over on the day.

What a court has actually said about getting this wrong

There is now one judgment on this, and it is worth knowing because it is the only one.

The Court was explicit about why it matters that there is only one:

"APP 11.1(b) has not been the subject of any previous judicial consideration." · AIC v Australian Clinical Labs (No 2) [2025] FCA 1224 at [45]

At [51] the Court set out what it weighs in deciding whether steps were reasonable: the sensitivity of the information, the potential harm to individuals, the size and sophistication of the APP entity, the cybersecurity environment, and any previous threats. The size-and-sophistication limb is the one that matters to a small agency: what is reasonable for you is measured against your size, not against a national laboratory network. In Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (AustLII) the Federal Court imposed a A$5.8 million civil penalty over a breach affecting more than 223,000 people. It was the first civil penalty proceeding brought under the Privacy Act in the Act's history, and the Court noted that APP 11.1(b) had never previously been considered judicially.

Two of the three contraventions were not the breach itself. They were the response:

"As soon as practicable" is measured in days, not weeks. That is the clearest guidance available on a phrase the Act does not define.

"Our IT provider handles that" is not an answer

The most useful part of the judgment for a small agency is what it says about outsourcing. The Court held that a reasonable-steps obligation is "not capable of being discharged simply by delegating it to another entity and doing nothing more" (at 52(b)), and found that the company's "overreliance … on third party service providers and its failure to have in place adequate procedures to detect and respond by itself" was central to the breach (at 53(g)).

The company had engaged a specialist cybersecurity firm. That firm reviewed 3 of at least 127 affected computers, told the company the ransom threat was probably "merely a scare tactic", and closed its investigation. The company relied on that advice and concluded there was no eligible breach. The national cyber agency then told them twice that there had been one.

If your agency's answer to "who assesses a suspected breach" is the name of your IT contractor or your CRM vendor, that is the arrangement the Court described. You still need your own process for deciding whether an assessment has actually been done properly.

The reassuring part

The Court set out what informs "reasonable steps" (at [51]): the sensitivity of the information, the potential harm to individuals, the size and sophistication of the entity, the cybersecurity environment, and any previous threats. A small agency is not held to the standard of a company with a A$995 million turnover and 5,400 staff, which is what this respondent was. The standard is proportionate, but having no process at all is not proportionate to anything.

What does a breach look like in a real-estate agency?

Breaches are rarely dramatic hacks. In an agency they usually look like:

Each of these involves exactly the kind of information that can cause serious harm: full names, addresses, dates of birth, driver licences, passport details, bank details. That is why property is a sector the regulator watches. The OAIC has been active here: it took enforcement action over unfair data collection in Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 (22 November 2024). That case was about unfair collection rather than a data breach, but it is a clear sign the OAIC is willing to enforce against property-sector operators. You can read it on AustLII.

Who do you notify, and when?

If an assessment confirms an eligible data breach, there are two notifications, and both should happen as soon as practicable:

If it is not practicable to contact each affected person individually, there are other permitted ways to notify, but the default is to tell the people whose information was exposed, promptly and in plain language.

How do you get ready?

A little preparation makes the difference between a contained incident and a reportable disaster.

If you are not sure where your agency's exposure sits, a short self-audit of where personal information lives and who can reach it is a sensible place to start.

Common questions

When does the Notifiable Data Breaches scheme apply to a real estate agency?

It applies when you have an eligible data breach: unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to any affected individual, and the agency has not been able to prevent that likely harm through remedial action.

How long do I have to assess a suspected breach?

If you only suspect there may be an eligible breach but are not sure, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. You do not get to wait and see.

What does a data breach usually look like in an agency?

Usually a lost or stolen laptop or USB holding tenancy files, a hacked CRM or email account, an email with a rent roll or ID documents sent to the wrong recipient, exposed AML identity documents, or a trust-account or rental-application spreadsheet left publicly accessible.

Who do I have to notify, and when?

If an assessment confirms an eligible data breach, you notify both the OAIC (through a statement prepared for the Commissioner) and the affected individuals (the tenants, landlords, buyers, vendors or applicants whose information was involved) as soon as practicable.