Skip to content

Data-breach response plan for buyers agents (the NDB scheme)

Because a buyers agent concentrates identity documents, bank statements, borrowing capacity and source-of-funds evidence on a small number of high-value clients, a breach of that data is very likely to cause serious harm and be notifiable under the Notifiable Data Breaches scheme. That means you need a written plan that lets you assess a suspected breach within 30 days and notify affected clients and the OAIC where the test is met.

By Jon Oates, Founder of Privaproof · Last updated

General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Why the breach scheme reaches you at all

Below A$3 million turnover, most of your practice sits under the small-business exemption (s 6D). The Notifiable Data Breaches (NDB) scheme does not reach that data on its own. What changes things is becoming an AUSTRAC reporting entity. From 1 July 2026, brokering the purchase of real estate for a client is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)) under the AML/CTF Act, and once you are a reporting entity, Privacy Act s 6E(1A) brings the identity and customer-due-diligence data you collect for those checks under the Australian Privacy Principles, regardless of turnover.

The NDB scheme rides on that same carve-in. For a buyers agent under A$3 million, the breach-notification duty applies to the AML/KYC customer-due-diligence data pulled in by s 6E(1A), not to your whole buyer CRM, your newsletter list or your property alerts. The data at the centre of your file is exactly the data the scheme covers, which is why this is not a box to tick and forget. Read: does the Privacy Act apply to buyers agents under $3 million?

Why a buyers agent breach is so likely to be "serious harm"

The NDB scheme only bites on an eligible data breach: unauthorised access to, disclosure of, or loss of personal information that a reasonable person would conclude is likely to result in serious harm to an affected individual. That "serious harm" test is what turns an incident into a notification.

For most small businesses, a lot of everyday data would not clear that bar. A buyers agent is the opposite case. You hold few files, but each one is unusually deep:

A leak of a full identity set plus bank statements and proof of deposit is close to a worked example of serious harm: it is the raw material for identity theft, targeted fraud and financial loss. So the practical reality for a buyers agent is that a breach of a live client file will usually need to be treated as notifiable, not shrugged off. Read: VOI and source-of-funds privacy rules

What the scheme actually requires when something goes wrong

Three obligations sit at the core, and a plan exists so you are not reading them for the first time mid-incident.

1. Contain and assess. When you have reasonable grounds to suspect an eligible data breach may have happened, you must carry out a reasonable and expeditious assessment. The scheme sets an outer limit of 30 days to complete that assessment. Thirty days is a ceiling, not a target; contain the exposure and assess as fast as you sensibly can. 2. Notify, where the test is met. If you have reasonable grounds to believe an eligible data breach has occurred, you must notify affected individuals and the OAIC as soon as practicable. The notification sets out what happened, the kinds of information involved and the steps clients should take to protect themselves. 3. Where serious harm can be prevented, you may not have to notify. If you take remedial action quickly enough that the breach is no longer likely to result in serious harm, notification may not be required. That exception is exactly why fast containment is worth building into the plan.

The point of a written response plan is to compress those first hours: who is called, what gets shut off, how you scope which client files were exposed, and who signs off on the serious-harm assessment. Read the cornerstone: privacy compliance for buyers agents

What a buyers agent breach plan should cover

A plan scoped to buy-side broking, rather than a generic template, addresses the specific ways your data leaks:

Penalties, in proportion

Serious or repeated interferences with privacy can attract penalties, and the figures make headlines. In practice these are ceilings, not certainties, and most matters resolve with no fine, especially where a business has assessed a breach in good faith, notified promptly and cooperated with the OAIC. Having a plan and following it is itself evidence that you took reasonable steps. Note that any AML/CTF reporting duties that a breach might also trigger are separate, sit with AUSTRAC, and are outside what Privaproof covers.

Common questions

Do I have to report every data breach to the OAIC?

No. The NDB scheme only requires notification for an eligible data breach: one likely to result in serious harm that you have not been able to prevent through remedial action. The catch for a buyers agent is that the identity, financial-capacity and source-of-funds data you hold makes the serious-harm test easy to meet, so a breach of a live client file will often be notifiable.

How long do I have to deal with a breach?

If you suspect an eligible data breach, you have up to 30 days to complete a reasonable assessment of whether it is notifiable. That is an outer limit, not a target. If you form the belief that a notifiable breach has occurred, you must notify affected individuals and the OAIC as soon as practicable, not at the end of the 30 days.

My AML pack came with breach templates. Isn't that enough?

An AML pack is built around your AUSTRAC-facing obligations, not the Privacy Act. A generic breach template is rarely scoped to the concentrated financial-capacity data a buyers agent holds or to how that data actually leaks, such as offshore VAs and shared cloud tools. The NDB response plan is part of the privacy half the AML packs leave out. Read: AML kit vs privacy kit

Does the breach scheme cover my whole client database?

For a practice under A$3 million, the NDB duty follows the s 6E(1A) carve-in: it reaches the AML/KYC customer-due-diligence data you collect as a reporting entity, not your general buyer CRM, newsletter list or property alerts, unless a separate trigger brings those under the Privacy Act too.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.