Skip to content

A data-breach response plan for recruitment agencies (the NDB scheme)

A recruitment agency holds a concentrated pool of identity and background data, exactly the material that causes real harm if it leaks. Under the Notifiable Data Breaches scheme, the moment you have reasonable grounds to suspect an eligible data breach of candidate personal information, s 26WH(2) puts the assessment duty on you, and if it is eligible you give a statement to the Office of the Australian Information Commissioner and notify the affected people. A plan you can run under pressure is the point.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Why recruiters are unusually exposed

The serious-harm test is anchored in the data itself. Section 26WG makes "the kind or kinds of information" and "the sensitivity of the information" express matters a reasonable person must have regard to. A recruiter's files are dense with the kinds that score badly: identity and right-to-work documents, dates of birth, contact details, and often sensitive information like police checks or medicals. A single compromised inbox or misdirected candidate list can expose enough to enable identity theft or real distress. Read: police checks and medicals as sensitive information

When a breach is notifiable

Under s 26WE(2) an eligible data breach has just two limbs. Either:

Remedial action is not a third limb. It is the separate exception in s 26WF: act before the access or disclosure causes serious harm, so that a reasonable person would conclude serious harm is no longer likely, and the breach is not, and is taken never to have been, an eligible data breach. That is why fast containment matters.

The four-step plan

1. Contain. Stop the exposure: revoke access, reset credentials, recover or delete misdirected data, isolate the affected system. The faster you contain, the more likely remedial action removes the "likely serious harm".

2. Assess. Work out what data, whose, and the risk of serious harm. This is a duty on you, not an expectation: s 26WH(2) says the entity must assess reasonably and expeditiously, and take all reasonable steps to complete the assessment within 30 days of becoming aware there are grounds to suspect. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court imposed A$800,000 for the slow assessment alone. That was an ASX-listed company and 223,000 people, not an agency, so read it as the shape of the duty rather than the size of your exposure.

3. Notify, if it qualifies. Prepare the s 26WK(3) statement (who you are, what happened, the kinds of information, the steps individuals should take) and give it to the OAIC as soon as practicable. Then s 26WL(2) runs as a cascade, not one instruction:

Holding current candidate contact details usually keeps you in the first tier. In Clinical Labs the notification failure drew a further A$800,000.

4. Review. Fix the cause: the shared inbox, the export habit, the offshore provider's control gap, and update your process so the same breach cannot recur. In Clinical Labs the Court noted at [53] that the company's "cyber incidents playbooks did not clearly define roles and responsibilities for incident response". Does yours name who decides the breach is notifiable, and by when?

The recruitment-specific traps

This is general information and document templates you tailor to your own business, not legal advice.

Common questions

A recruiter emailed a candidate list to the wrong person. Is that notifiable?

It is a potential eligible data breach (unauthorised disclosure), and the suspicion alone starts the s 26WH clock. Whether you must notify turns on the data and on whether s 26WF applies: you must act before the disclosure results in serious harm, and the action must be enough that a reasonable person would conclude serious harm is no longer likely. A recipient confirming deletion is evidence towards that, not an automatic answer.

How long do we have?

Section 26WH(2) requires a reasonable and expeditious assessment, and all reasonable steps to complete it within 30 days of becoming aware there are grounds to suspect. That is an outer limit on the assessment, not a notification deadline: the statement goes to the Commissioner as soon as practicable (s 26WK(2)), and s 26WL(3) requires notification as soon as practicable after it is prepared.

Our cloud provider had the breach, not us. Are we still on the hook?

Generally yes, and for overseas-held data s 26WC(1) deems it to be held by you. Note Clinical Labs: the Court found it unreasonable to rely on a provider's conclusion that no eligible data breach had occurred when the company knew the provider had only done a limited assessment. Taking the vendor's word for it is not an assessment. Build provider breach-notification into your contracts, and run your own s 26WH assessment.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether a particular incident is a notifiable data breach depends on the facts. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading