Skip to content

Data-breach response plan for buyers agents (the NDB scheme)

A buyers agent concentrates identity documents, bank statements, borrowing capacity and source-of-funds evidence on a small number of high-value clients, which is exactly the kind of information the Notifiable Data Breaches scheme is built around: an eligible data breach is one a reasonable person would conclude is likely to result in serious harm (Privacy Act 1988 (Cth) s 26WE(2)). A written plan is what lets you run the s 26WH(2) assessment inside the 30 days that section allows, prepare the s 26WK statement for the Commissioner, and notify under the s 26WL(2) cascade where the test is met.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Why the breach scheme reaches you at all

Turnover under A$3 million is where the small-business exemption starts, but it is not the whole test. A business is a small business if its annual turnover for the previous financial year is A$3,000,000 or less (s 6D(1)), but s 6D(4) takes you outside small-business-operator status on any of several grounds, including disclosing personal information about an individual for a benefit, service or advantage, or providing a benefit to collect it (s 6D(4)(c) and (d)), and s 6D(4)(a) works one way: once a financial year has ended in which turnover exceeded A$3,000,000, a later fall in turnover does not restore the exemption. A small business operator can also opt in under s 6EA. What changes things for buy-side broking is becoming an AUSTRAC reporting entity. From 31 March 2026, "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business" is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)), and once you are a reporting entity Privacy Act s 6E(1A) applies the Act, as if you were an organisation, in relation to the activities you carry on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act, regardless of turnover.

The NDB scheme rides on that same carve-in, so it is worth being exact about what the carve-in catches. Section 6E(1A) is written by reference to activities, not to a category of record: the Act applies "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act. The question is therefore not whether a given file is an identity document, it is whether the handling sits within your reporting-entity activities. Information handled wholly outside those activities is not drawn in by s 6E(1A) on its own, but that boundary is a question of fact about your own systems rather than a clean line between CRM fields, and where one system carries both, the practical answer is to treat the system as in scope. Read: does the Privacy Act apply to buyers agents under $3 million?

Why a buyers agent breach is so likely to be "serious harm"

The NDB scheme only bites on an eligible data breach (s 26WE(2)): unauthorised access to, or unauthorised disclosure of, personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to; or loss of that information in circumstances where such access or disclosure is likely to occur and would be likely to result in serious harm. Section 26WG sets out what goes into that judgment, including the kind and sensitivity of the information, the security measures protecting it and the likelihood they could be overcome, and the persons who could obtain it. That "serious harm" test is what turns an incident into a notification.

Not all everyday business data would clear that bar. A buyers agent file sits at the other end of the range. You hold few files, but each one is unusually deep:

A leak of a full identity set plus bank statements and proof of deposit engages the s 26WG factors head on: the kind and sensitivity of the information, and the nature of the harm that could result, are the raw material for identity theft, targeted fraud and financial loss. Whether a given incident is an eligible data breach is still the s 26WH(2) assessment on its own facts, but a breach of a live client file is the kind of incident that assessment exists for, not one to wave through. Read: VOI and source-of-funds privacy rules

What the scheme actually requires when something goes wrong

Part IIIC sets out two duties and one exception, and a plan exists so you are not reading them for the first time mid-incident.

The point of a written response plan is to compress those first hours: who is called, what gets shut off, how you scope which client files were exposed, and who signs off on the serious-harm assessment. Read the cornerstone: privacy compliance for buyers agents

What a buyers agent breach plan should cover

A plan scoped to buy-side broking, rather than a generic template, addresses the specific ways your data leaks:

Penalties, in proportion

Serious or repeated interferences with privacy can attract penalties, and the figures make headlines, so it is worth separating what the Act provides from the headline. A determination under s 52(1) can declare that conduct was an interference with privacy, require steps so it is not repeated and award compensation to the complainant, and it contains no penalty limb. A civil penalty is a separate track on which the Commissioner must apply to the Federal Court or the Federal Circuit and Family Court (Division 2) (ss 13G and 80U), and the maximums are ceilings expressed in penalty units, not amounts that attach to any particular breach. Part IIIC duties are enforceable in their own right: in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the total A$5.8 million penalty included A$800,000 for a slow s 26WH(2) assessment and A$800,000 for a failure to notify under s 26WK(2). Note that any AML/CTF reporting duties a breach might also trigger are separate, sit with AUSTRAC, and are outside what Privaproof covers.

Common questions

Do I have to report every data breach to the OAIC?

No. The NDB scheme only requires notification for an eligible data breach, which s 26WE(2) defines as unauthorised access, unauthorised disclosure or loss where a reasonable person would conclude serious harm to an affected individual is likely. Remedial action is not part of that definition: s 26WF is a separate exception which, where it applies, means the access or disclosure "is not, and is taken never to have been" an eligible data breach. Every incident still needs its own s 26WH(2) assessment, and the identity, financial-capacity and source-of-funds data a buyers agent holds goes directly to the s 26WG factors of the kind and sensitivity of the information and the nature of the harm that could result.

How long do I have to deal with a breach?

Section 26WH(2) requires you to take all reasonable steps to ensure the assessment is completed within 30 days after you become aware there are reasonable grounds to suspect an eligible data breach. That is an outer limit, not a target, and the clock runs from that awareness. If you then become aware of reasonable grounds to believe an eligible data breach has occurred, s 26WK(2) requires the statement to go to the Commissioner as soon as practicable, and s 26WL(2) requires notification to individuals under its cascade, not a wait until day 30.

My AML pack came with breach templates. Isn't that enough?

An AML pack is built around your AUSTRAC-facing obligations, not the Privacy Act. A generic breach template is rarely scoped to the concentrated financial-capacity data a buyers agent holds or to how that data actually leaks, such as offshore VAs and shared cloud tools. The NDB response plan is part of the privacy half the AML packs leave out. Read: AML kit vs privacy kit

Does the breach scheme cover my whole client database?

For a practice under A$3 million the NDB duty follows the s 6E(1A) carve-in, and that provision is written by activity rather than by data type: the Act applies, as if you were an organisation, to the activities you carry on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act. Information handled wholly outside those activities, such as a standalone property-alert list, is not drawn in by s 6E(1A) on its own. Where one system carries both your customer-due-diligence records and your general buyer data, the practical answer is that the system is in scope, and a separate trigger such as s 6D(4) or an s 6EA opt-in can bring the rest in anyway.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.