A data-breach response plan for recruitment agencies (the NDB scheme)
A recruitment agency holds a concentrated pool of identity and background data, exactly the material that causes real harm if it leaks. Under the Notifiable Data Breaches scheme, the moment you have reasonable grounds to suspect an eligible data breach of candidate personal information, s 26WH(2) puts the assessment duty on you, and if it is eligible you give a statement to the Office of the Australian Information Commissioner and notify the affected people. A plan you can run under pressure is the point.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
Why recruiters are unusually exposed
The serious-harm test is anchored in the data itself. Section 26WG makes "the kind or kinds of information" and "the sensitivity of the information" express matters a reasonable person must have regard to. A recruiter's files are dense with the kinds that score badly: identity and right-to-work documents, dates of birth, contact details, and often sensitive information like police checks or medicals. A single compromised inbox or misdirected candidate list can expose enough to enable identity theft or real distress. Read: police checks and medicals as sensitive information
When a breach is notifiable
Under s 26WE(2) an eligible data breach has just two limbs. Either:
- there is unauthorised access to, or unauthorised disclosure of, personal information you hold, and a reasonable person would conclude it is likely to result in serious harm to any of the individuals the information relates to, or
- the information is lost in circumstances where such access or disclosure is likely to occur and would likely cause that serious harm.
Remedial action is not a third limb. It is the separate exception in s 26WF: act before the access or disclosure causes serious harm, so that a reasonable person would conclude serious harm is no longer likely, and the breach is not, and is taken never to have been, an eligible data breach. That is why fast containment matters.
The four-step plan
1. Contain. Stop the exposure: revoke access, reset credentials, recover or delete misdirected data, isolate the affected system. The faster you contain, the more likely remedial action removes the "likely serious harm".
2. Assess. Work out what data, whose, and the risk of serious harm. This is a duty on you, not an expectation: s 26WH(2) says the entity must assess reasonably and expeditiously, and take all reasonable steps to complete the assessment within 30 days of becoming aware there are grounds to suspect. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court imposed A$800,000 for the slow assessment alone. That was an ASX-listed company and 223,000 people, not an agency, so read it as the shape of the duty rather than the size of your exposure.
3. Notify, if it qualifies. Prepare the s 26WK(3) statement (who you are, what happened, the kinds of information, the steps individuals should take) and give it to the OAIC as soon as practicable. Then s 26WL(2) runs as a cascade, not one instruction:
- notify each individual the information relates to, if practicable; or
- if not, notify each individual at risk from the breach; or
- if neither is practicable, publish the statement on your website and take reasonable steps to publicise it.
Holding current candidate contact details usually keeps you in the first tier. In Clinical Labs the notification failure drew a further A$800,000.
4. Review. Fix the cause: the shared inbox, the export habit, the offshore provider's control gap, and update your process so the same breach cannot recur. In Clinical Labs the Court noted at [53] that the company's "cyber incidents playbooks did not clearly define roles and responsibilities for incident response". Does yours name who decides the breach is notifiable, and by when?
The recruitment-specific traps
- Offshore-held data still counts. Section 26WC(1) deems the data to be held by you: where you disclosed candidate information to an overseas recipient under APP 8.1 and they hold it, Part IIIC operates as if the information were held by you. Their breach is your assessment and your notification. Read: offshore recruiters and overseas screening
- Sensitive data escalates it. Section 26WG(d) makes "the sensitivity of the information" an express factor in the serious-harm test, so a breach touching police checks or medicals is assessed on that footing. Does your plan flag those files first?
- Referees and third parties. The test asks about serious harm to any of the individuals the information relates to, not just candidates. Referees and their contact details can be caught up, so factor them into the assessment and into who you notify.
This is general information and document templates you tailor to your own business, not legal advice.
Common questions
A recruiter emailed a candidate list to the wrong person. Is that notifiable?
It is a potential eligible data breach (unauthorised disclosure), and the suspicion alone starts the s 26WH clock. Whether you must notify turns on the data and on whether s 26WF applies: you must act before the disclosure results in serious harm, and the action must be enough that a reasonable person would conclude serious harm is no longer likely. A recipient confirming deletion is evidence towards that, not an automatic answer.
How long do we have?
Section 26WH(2) requires a reasonable and expeditious assessment, and all reasonable steps to complete it within 30 days of becoming aware there are grounds to suspect. That is an outer limit on the assessment, not a notification deadline: the statement goes to the Commissioner as soon as practicable (s 26WK(2)), and s 26WL(3) requires notification as soon as practicable after it is prepared.
Our cloud provider had the breach, not us. Are we still on the hook?
Generally yes, and for overseas-held data s 26WC(1) deems it to be held by you. Note Clinical Labs: the Court found it unreasonable to rely on a provider's conclusion that no eligible data breach had occurred when the company knew the provider had only done a limited assessment. Taking the vendor's word for it is not an assessment. Build provider breach-notification into your contracts, and run your own s 26WH assessment.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether a particular incident is a notifiable data breach depends on the facts. For advice on your specific circumstances, consult a qualified Australian legal practitioner.