Skip to content

A data-breach response plan for recruitment agencies (the NDB scheme)

A recruitment agency holds a concentrated pool of identity and background data, exactly the material that causes real harm if it leaks. Under the Notifiable Data Breaches scheme, if candidate personal information is involved in an eligible data breach that is likely to result in serious harm, you must assess it and, if it qualifies, notify the Office of the Australian Information Commissioner and the affected people. A plan you can run under pressure is the point.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Why recruiters are unusually exposed

Most breaches turn on how harmful the exposed data is. A recruiter's files are dense with the harmful kind: identity and right-to-work documents, dates of birth, contact details, and often sensitive information like police checks or medicals. A single compromised inbox or misdirected candidate list can expose enough to enable identity theft or real distress. That makes a recruitment breach both more likely to be notifiable and more urgent to contain. Read: police checks and medicals as sensitive information

When a breach is notifiable

Broadly, an eligible data breach under the NDB scheme is where:

If those hold, you notify. If prompt remedial action means serious harm is no longer likely, notification may not be required, which is exactly why fast containment matters.

The four-step plan

1. Contain. Stop the exposure: revoke access, reset credentials, recover or delete misdirected data, isolate the affected system. The faster you contain, the more likely remedial action removes the "likely serious harm".

2. Assess. Work out what data, whose, and the risk of serious harm. The scheme expects you to assess expeditiously and, where needed, complete the assessment within 30 days. Recruitment data (identity, sensitive checks) skews toward serious harm, so assess on that footing.

3. Notify, if it qualifies. If it is an eligible data breach, notify the OAIC with a statement, and notify the affected candidates (and referees or others whose data was involved) about what happened, the information involved, and the steps they can take. Because you hold current contact details for candidates, you are usually well placed to reach them.

4. Review. Fix the cause: the shared inbox, the export habit, the offshore provider's control gap, and update your process so the same breach cannot recur.

The recruitment-specific traps

This is general information and document templates you tailor to your own business, not legal advice.

Common questions

A recruiter emailed a candidate list to the wrong person. Is that notifiable?

It is a potential eligible data breach (unauthorised disclosure). Whether you must notify depends on the data involved and whether it is likely to cause serious harm, and whether you can contain it (for example, the recipient confirms deletion) so serious harm is no longer likely. Assess it quickly rather than assuming either way.

How long do we have?

Assess expeditiously. Where an assessment is needed, the scheme expects it completed within 30 days, but you should move faster where you can, both to contain and because notification, if required, should not wait.

Our cloud provider had the breach, not us. Are we still on the hook?

Generally yes for the candidate data you are responsible for. Holding data with a third party, onshore or offshore, does not move the obligation off you. Build provider breach-notification into your contracts so you find out fast.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether a particular incident is a notifiable data breach depends on the facts. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading