Skip to content

A data-breach response plan for car dealers (the NDB scheme)

A dealership holds driver licences, income and bank details, and finance paperwork, which is precisely the identity and financial data that enables fraud if it leaks. Part IIIC of the Privacy Act 1988 (Cth) reaches you if you are an APP entity, so settle that question first. If it does reach you, then the moment you are aware of reasonable grounds to suspect an eligible data breach, s 26WH(2) says you must assess it and take all reasonable steps to finish within 30 days; if the assessment confirms one, a statement goes to the Office of the Australian Information Commissioner and your customers are notified. A plan you can run under pressure is the point.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Why a dealership is exposed

Whether a breach is notifiable turns on the serious-harm test, and s 26WG sets out what to weigh: the kind of information, its sensitivity, whether it was protected by security measures and how easily those could be overcome, and who could obtain it. A dealer's files rate high on the first two: licence images, dates of birth, and the income and bank details you take to broker finance. So the question is where yours are sitting right now. On a salesperson's phone? In a shared inbox? In an unlocked filing cabinet? Read: finance and insurance data

When a breach is notifiable

Section 26WE(2) makes an eligible data breach one of two things:

Remedial action is not part of that definition. It is a separate exception in s 26WF: if you act before the access or disclosure causes serious harm and, as a result, a reasonable person would conclude serious harm is no longer likely, the breach "is not, and is taken never to have been" an eligible data breach. Recovering the file, or wiping a lost phone before anyone opens it, is what s 26WF is for.

The trigger for assessing sits lower than that. Once you are aware of reasonable grounds to suspect there may have been an eligible data breach, s 26WH(2) says the entity must carry out a reasonable and expeditious assessment and take all reasonable steps to ensure it is completed within 30 days. That duty sits on you, not on the OAIC, and you do not get to wait and see.

The four-step plan

1. Contain. Stop the exposure: recover the data, revoke access, reset credentials, secure the system or the paperwork. Finance data leaking is the worst case, so contain it first.

2. Assess. Work out what data, whose, and the likelihood of serious harm against the s 26WG factors. Section 26WH(2) is a duty on you, not a guideline: a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 days of becoming aware. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court ordered A$800,000 for that failure alone. That was an ASX-listed company and 223,000 people, not a dealership, but s 26WH(2) is worded the same for both.

3. Notify, if it qualifies. Two notifications, two different rules. Section 26WK(2): prepare a statement and give it to the Commissioner as soon as practicable, setting out your identity and contact details, a description of the breach, the kinds of information involved and the steps customers should take. Section 26WL(2) is then a cascade, not simply "tell the customers": notify everyone the information relates to if that is practicable; if it is not, notify those at risk from the breach; and only if neither is practicable, publish the statement on your website and take reasonable steps to publicise it.

4. Review. Fix the cause, the phone full of licence photos, the shared finance inbox, the offshore provider's gap, so it cannot recur. Then review the plan itself. In Australian Clinical Labs (No 2) [2025] FCA 1224 the Court recorded at [53] that "the ACL cyber incidents playbooks did not clearly define roles and responsibilities for incident response". Does yours name who decides, who calls the bank, and when the 30 days start?

The dealer-specific traps

This is general information and document templates you tailor to your own business, not legal advice.

Common questions

A salesperson lost a phone with licence photos on it. Is that notifiable?

It is potentially the second limb, s 26WE(2)(b): loss of personal information in circumstances where unauthorised access or disclosure is likely to occur. Whether you notify turns on the s 26WG factors, including whether the phone was protected by security measures and how easily those could be overcome. A remote wipe that lands before anyone gets into it brings s 26WF(3) into play, under which the loss "is not, and is taken never to have been" an eligible data breach. Either way the s 26WH(2) clock has already started. It is also a reason not to keep licence photos on phones at all.

The breach was our finance software provider's, not ours. Are we on the hook?

Yes, for the customer data you hold, and s 6(1) makes "hold" a question of possession or control, not of whose server it sits on. In Australian Clinical Labs (No 2) [2025] FCA 1224 at [51] the Federal Court described the obligation as "not to be capable of being discharged simply by delegating it to another entity and doing nothing more", and at [52] counted "the overreliance that ACL placed on third party service providers" among the failures. So the contract is the control that matters: does yours require the provider to tell you about a breach, and by when?

How long do we have to act?

Section 26WH(2) says the entity must carry out a reasonable and expeditious assessment and take all reasonable steps to ensure it is completed within 30 days of becoming aware of the grounds to suspect. The 30 days is the outer limit, not the target: the duty is to be expeditious. If the assessment confirms an eligible breach, the statement goes to the Commissioner "as soon as practicable" (s 26WK(2)), and you notify individuals as soon as practicable after that statement is prepared (s 26WL(3)).


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether a particular incident is a notifiable data breach depends on the facts. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading