Data-breach response plan for buyers agents (the NDB scheme)
A buyers agent concentrates identity documents, bank statements, borrowing capacity and source-of-funds evidence on a small number of high-value clients, which is exactly the kind of information the Notifiable Data Breaches scheme is built around: an eligible data breach is one a reasonable person would conclude is likely to result in serious harm (Privacy Act 1988 (Cth) s 26WE(2)). A written plan is what lets you run the s 26WH(2) assessment inside the 30 days that section allows, prepare the s 26WK statement for the Commissioner, and notify under the s 26WL(2) cascade where the test is met.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
Why the breach scheme reaches you at all
Turnover under A$3 million is where the small-business exemption starts, but it is not the whole test. A business is a small business if its annual turnover for the previous financial year is A$3,000,000 or less (s 6D(1)), but s 6D(4) takes you outside small-business-operator status on any of several grounds, including disclosing personal information about an individual for a benefit, service or advantage, or providing a benefit to collect it (s 6D(4)(c) and (d)), and s 6D(4)(a) works one way: once a financial year has ended in which turnover exceeded A$3,000,000, a later fall in turnover does not restore the exemption. A small business operator can also opt in under s 6EA. What changes things for buy-side broking is becoming an AUSTRAC reporting entity. From 31 March 2026, "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business" is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)), and once you are a reporting entity Privacy Act s 6E(1A) applies the Act, as if you were an organisation, in relation to the activities you carry on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act, regardless of turnover.
The NDB scheme rides on that same carve-in, so it is worth being exact about what the carve-in catches. Section 6E(1A) is written by reference to activities, not to a category of record: the Act applies "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act. The question is therefore not whether a given file is an identity document, it is whether the handling sits within your reporting-entity activities. Information handled wholly outside those activities is not drawn in by s 6E(1A) on its own, but that boundary is a question of fact about your own systems rather than a clean line between CRM fields, and where one system carries both, the practical answer is to treat the system as in scope. Read: does the Privacy Act apply to buyers agents under $3 million?
Why a buyers agent breach is so likely to be "serious harm"
The NDB scheme only bites on an eligible data breach (s 26WE(2)): unauthorised access to, or unauthorised disclosure of, personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to; or loss of that information in circumstances where such access or disclosure is likely to occur and would be likely to result in serious harm. Section 26WG sets out what goes into that judgment, including the kind and sensitivity of the information, the security measures protecting it and the likelihood they could be overcome, and the persons who could obtain it. That "serious harm" test is what turns an incident into a notification.
Not all everyday business data would clear that bar. A buyers agent file sits at the other end of the range. You hold few files, but each one is unusually deep:
- Identity and verification documents (VOI) for the buyer.
- Financial-capacity evidence: mortgage pre-approvals, bank and savings statements, proof of deposit and borrowing capacity.
- Source-of-funds and source-of-wealth evidence, where a client is higher-risk under your customer due diligence. This is data you may hold, not every file.
- Beneficial-ownership, PEP and sanctions-screening results.
- The buyer brief, which often carries sensitive context such as a relocation, a divorce, an inheritance or an SMSF purchase.
A leak of a full identity set plus bank statements and proof of deposit engages the s 26WG factors head on: the kind and sensitivity of the information, and the nature of the harm that could result, are the raw material for identity theft, targeted fraud and financial loss. Whether a given incident is an eligible data breach is still the s 26WH(2) assessment on its own facts, but a breach of a live client file is the kind of incident that assessment exists for, not one to wave through. Read: VOI and source-of-funds privacy rules
What the scheme actually requires when something goes wrong
Part IIIC sets out two duties and one exception, and a plan exists so you are not reading them for the first time mid-incident.
- 1. Assess (s 26WH). Section 26WH(2) puts this on you, not on the regulator: where you are aware there are reasonable grounds to suspect there may have been an eligible data breach, and are not yet aware of reasonable grounds to believe one has occurred, "the entity must" carry out "a reasonable and expeditious assessment" and "take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware". The clock runs from that awareness, not from the day you finish investigating. Thirty days is the outer edge of what is reasonable, not an entitlement; contain the exposure and assess as fast as you sensibly can.
- 2. Prepare a statement, then notify (ss 26WK and 26WL). These are two steps, not one. Once you are aware there are reasonable grounds to believe an eligible data breach has occurred, s 26WK(2) requires you to prepare a statement and give a copy to the Commissioner "as soon as practicable", and s 26WK(3) sets its contents: your identity and contact details, a description of the breach, the particular kinds of information concerned, and recommendations about the steps individuals should take. Section 26WL(2) then sets notification as a three-way cascade rather than simply telling the clients: notify the contents of the statement to each individual the information relates to if that is practicable; or, if it is not, to each individual at risk from the breach if that is practicable; or, if neither is practicable, publish the statement on your website and take reasonable steps to publicise its contents.
- 3. Remedial action is a separate exception (s 26WF), not part of the definition. Section 26WE(2) defines an eligible data breach, and s 26WE(3) then provides that "subsection (2) has effect subject to section 26WF", so the remedial-action exception lives in its own section rather than inside the serious-harm test. Where you take action in relation to an unauthorised access or disclosure before it results in serious harm, and as a result a reasonable person would conclude serious harm is no longer likely, the access or disclosure "is not, and is taken never to have been" an eligible data breach (s 26WF(1)). Section 26WF(3) does the same for information you lose and recover before any unauthorised access or disclosure occurs. That is a stronger outcome than being excused from notifying, which is why fast containment is worth building into the plan.
The point of a written response plan is to compress those first hours: who is called, what gets shut off, how you scope which client files were exposed, and who signs off on the serious-harm assessment. Read the cornerstone: privacy compliance for buyers agents
What a buyers agent breach plan should cover
A plan scoped to buy-side broking, rather than a generic template, addresses the specific ways your data leaks:
- The offshore VA and shared cloud tool. A misconfigured drive, a shared login or a virtual assistant's device is a common exposure route for the exact identity and financial files you hold.
- Email and misdirected attachments. Sending a client's bank statements or VOI to the wrong recipient is an unauthorised disclosure for the purposes of s 26WE(2)(a). In the OAIC's Notifiable Data Breach statistics for January to June 2025, human error accounted for 37% of all notified data breaches (193 notifications), up from 29% in the previous reporting period.
- A clear roles-and-timeline sheet so the 30-day assessment window never gets lost while you work out who is responsible.
- A client-notification template written in plain English, ready to tailor, so you are not drafting one under pressure.
- A link to your retention schedule, because data you have already securely destroyed cannot be breached. Holding client-identity files longer than you need to enlarges the target. Read: how long must a buyers agent keep client records?
Penalties, in proportion
Serious or repeated interferences with privacy can attract penalties, and the figures make headlines, so it is worth separating what the Act provides from the headline. A determination under s 52(1) can declare that conduct was an interference with privacy, require steps so it is not repeated and award compensation to the complainant, and it contains no penalty limb. A civil penalty is a separate track on which the Commissioner must apply to the Federal Court or the Federal Circuit and Family Court (Division 2) (ss 13G and 80U), and the maximums are ceilings expressed in penalty units, not amounts that attach to any particular breach. Part IIIC duties are enforceable in their own right: in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the total A$5.8 million penalty included A$800,000 for a slow s 26WH(2) assessment and A$800,000 for a failure to notify under s 26WK(2). Note that any AML/CTF reporting duties a breach might also trigger are separate, sit with AUSTRAC, and are outside what Privaproof covers.
Common questions
Do I have to report every data breach to the OAIC?
No. The NDB scheme only requires notification for an eligible data breach, which s 26WE(2) defines as unauthorised access, unauthorised disclosure or loss where a reasonable person would conclude serious harm to an affected individual is likely. Remedial action is not part of that definition: s 26WF is a separate exception which, where it applies, means the access or disclosure "is not, and is taken never to have been" an eligible data breach. Every incident still needs its own s 26WH(2) assessment, and the identity, financial-capacity and source-of-funds data a buyers agent holds goes directly to the s 26WG factors of the kind and sensitivity of the information and the nature of the harm that could result.
How long do I have to deal with a breach?
Section 26WH(2) requires you to take all reasonable steps to ensure the assessment is completed within 30 days after you become aware there are reasonable grounds to suspect an eligible data breach. That is an outer limit, not a target, and the clock runs from that awareness. If you then become aware of reasonable grounds to believe an eligible data breach has occurred, s 26WK(2) requires the statement to go to the Commissioner as soon as practicable, and s 26WL(2) requires notification to individuals under its cascade, not a wait until day 30.
My AML pack came with breach templates. Isn't that enough?
An AML pack is built around your AUSTRAC-facing obligations, not the Privacy Act. A generic breach template is rarely scoped to the concentrated financial-capacity data a buyers agent holds or to how that data actually leaks, such as offshore VAs and shared cloud tools. The NDB response plan is part of the privacy half the AML packs leave out. Read: AML kit vs privacy kit
Does the breach scheme cover my whole client database?
For a practice under A$3 million the NDB duty follows the s 6E(1A) carve-in, and that provision is written by activity rather than by data type: the Act applies, as if you were an organisation, to the activities you carry on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act. Information handled wholly outside those activities, such as a standalone property-alert list, is not drawn in by s 6E(1A) on its own. Where one system carries both your customer-due-diligence records and your general buyer data, the practical answer is that the system is in scope, and a separate trigger such as s 6D(4) or an s 6EA opt-in can bring the rest in anyway.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.