A data-breach response plan for strata managers
If your managing-agent business is covered by the Privacy Act, a suspected eligible data breach must be assessed within about 30 days, and where serious harm is likely you must notify the affected residents and the OAIC. If you fall under the small-business exemption the notifiable-breach scheme does not legally bind you, but strata offices are active ransomware targets, so every manager needs a plan tuned to the owners roll, arrears files and CCTV.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
First, are you inside the Notifiable Data Breaches scheme?
Be honest about this before you copy anyone's plan, because the legal duty is not universal in strata.
The Notifiable Data Breaches (NDB) scheme binds APP entities. Your managing-agent business is an APP entity only if either its annual turnover exceeds A$3 million or it is a related body corporate of a larger covered group. Many branded and national managers are caught on that second limb even when a local office assumes it is exempt. Plenty of smaller independent managers under A$3 million, and almost every owners corporation, genuinely fall within the small-business exemption (s 6D) and are not bound by the NDB scheme. That exemption is still in force as at July 2026; its proposed removal is not law and has no legislated date, so this is not a deadline. Read: does the Privacy Act apply to strata managers?
So there are two honest tracks on this page. If you are covered, the NDB scheme is a legal obligation with defined steps. If you are exempt, you have no NDB duty, but you still hold the same sensitive data and should still have a plan. We cover both below, and we will not tell an exempt manager they must notify under a scheme that does not bind them.
Why strata is a real target, not a hypothetical
A strata office concentrates an entire building's personal information in one small place: the owners and strata roll, tenant and occupier details, levy arrears and debt-recovery files, by-law-breach records, committee and proxy records naming individuals, contractor details, and CCTV footage and access logs. That is a dense, saleable pool, and attackers know it.
This is already happening. NSW-based Strata Republic was hit by the Kairos ransomware group, with a large data set claimed in a leak post around April 2025. Strata manager SSKB suffered a ransomware attack exposing customer names, emails and phone numbers . The point is not to frighten you with a countdown. It is that the exposure is concrete and current, so a plan you can actually run under pressure is the practical baseline whether or not a statute compels one.
What counts as an "eligible data breach"
For a covered manager, the NDB scheme turns on an eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of, personal information you hold, that a reasonable person would conclude is likely to result in serious harm to an affected individual, where you have not been able to prevent that harm through remedial action.
In strata terms, that could be a ransomware exfiltration of the roll, a misdirected email sending one owner's arrears file to the wrong recipient, a lost laptop with the resident database, or CCTV footage accessed by someone with no authority to view it. Not every incident is an eligible breach. A quickly contained error you remediate before serious harm becomes likely may not meet the threshold. The scheme asks you to make that judgement, and to document it.
Your response plan, step by step
Write this down before you need it. A workable strata breach plan has six moves.
1. Contain. Stop the bleed first. Isolate the affected system, revoke or reset compromised credentials, recall a misdirected message where you can, and secure any physical device. Preserve evidence rather than wiping it.
2. Name who is in charge. Nominate a response lead and a deputy in advance, with after-hours contact details, so the plan does not stall on a Friday night. Record who is authorised to speak to residents, to the committee, and to the media.
3. Assess within about 30 days. If you are a covered manager and you suspect an eligible breach, you must carry out a reasonable and expeditious assessment, and the scheme expects that to be completed within about 30 days of becoming aware of the grounds to suspect. Assess what data was involved, who is affected, and whether serious harm is likely. Do not treat 30 days as a target to run down; move as fast as the facts allow.
4. Notify where serious harm is likely. For a covered manager, if the assessment concludes serious harm is likely and you cannot prevent it, you must notify the affected individuals and the OAIC as soon as practicable, with a statement covering what happened, the kinds of information involved, and the steps people should take. In strata, "affected individuals" often includes people who never chose to deal with you, such as tenants collected via the owner, so plan for how you will actually reach them.
5. Tell the owners corporation and committee. Separate from any OAIC duty, your management agreement and your relationship with the scheme mean the owners corporation needs to know. Agree in advance who tells the committee, and when.
6. Review and fix. After the incident, record what happened, close the gap that allowed it, and update the plan. A breach you learn nothing from is a breach you will repeat.
If you are exempt, you still need a plan
If you are a smaller independent manager under A$3 million and not part of a larger group, the NDB scheme does not legally bind you, and we are not going to pretend it does. But the data is just as sensitive, and residents are harmed just the same. The honest position is: you have no statutory notification duty, yet you should still contain the incident, work out who is affected, and tell the people whose data was exposed so they can protect themselves. Treating an exempt office as if breaches do not matter is a reputational and, potentially, a state-law and contractual risk, not a free pass.
Keep in mind too that a serious surveillance or data misuse can attract exposure outside the Privacy Act altogether, including under a statutory tort of serious invasion of privacy that was legislated and commenced around June 2025 , which does not depend on the small-business exemption.
Tune the plan to strata's data
A generic website breach template will not fit a strata office, because it does not know what you hold. Build your plan around the three data pools that actually create risk here.
- The owners and strata roll. Names, lot details and contact details for a whole building. A roll leak is a mass-exposure event, so it should be your worst-case scenario in the plan. Note that you must still keep and disclose the roll under state strata law, so the answer is to secure it, not to stop holding it. Read: who can access the strata roll?
- Arrears and debt-recovery files. Financial-hardship information about identifiable residents, which is both sensitive and a natural target for fraud. Read: levy arrears, debt recovery and privacy in strata
- CCTV footage and access logs. Vision of residents and visitors, plus records of who came and went. Your plan should say who may access footage, how a footage breach is handled, and how it ties to your state surveillance-devices obligations. Read: CCTV and surveillance privacy laws for strata
One more link between breach and retention: the data you no longer hold cannot be breached. A covered manager owes APP 11.2 (destroy or de-identify personal information you no longer need), and state strata law sets a record-keeping floor (in NSW, about seven years . Keeping ex-owner and former-tenant records forever just widens the blast radius. Read: how long must a strata manager keep owner records?
So, what should you do?
If you are covered, put a written NDB response plan in place now: contain, assign, assess within about 30 days, notify affected residents and the OAIC where serious harm is likely, tell the owners corporation, then review. If you are exempt, build the same plan minus the statutory notification, because the ransomware risk is real either way and residents are harmed just the same. Either way, tune it to the roll, the arrears files and the CCTV, and keep less data for less time. Read the cornerstone: privacy compliance for strata and owners-corporation managers.
Common questions
Does my strata management business have to notify a data breach?
Only if you are covered by the Privacy Act, that is, your turnover exceeds A$3 million or you are a related body corporate of a larger covered group. A covered manager must assess a suspected eligible breach within about 30 days and, where serious harm is likely, notify the affected individuals and the OAIC. A smaller independent manager under A$3 million and not in a larger group is generally not bound by the notifiable-breach scheme, though it should still have a plan.
How long do I have to respond to a suspected breach?
If you are covered, the scheme expects a reasonable and expeditious assessment, generally completed within about 30 days of becoming aware of grounds to suspect an eligible breach. That is an outer limit, not a target. Contain the incident and assess as fast as the facts allow, and notify as soon as practicable once serious harm is found to be likely.
We are under $3 million. Can we ignore data breaches?
No. You may have no legal duty to notify under the notifiable-breach scheme, and we will not pretend you do, but strata offices are active ransomware targets and the data you hold is highly sensitive. The honest baseline is to contain the incident, work out who is affected, and tell those people so they can protect themselves. State strata obligations, your management agreement and your reputation all still apply.
What is the single biggest breach risk in a strata office?
The owners roll, because it concentrates a whole building's identities and contact details in one file, and because you are required to keep and disclose it under state strata law. You cannot solve that by not holding it, so the plan is to secure it tightly, control who can access it, and treat a roll exposure as your worst-case scenario.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Notifiable Data Breaches scheme applies to your business depends on your turnover and structure under the Privacy Act 1988 (Cth); many smaller managers and owners corporations fall within the small-business exemption and are not bound by it. State strata legislation, your management agreement and state surveillance-devices law apply separately and vary by jurisdiction. Privaproof's strata documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version and confirm your own state's requirements. For advice on your specific circumstances, consult a qualified Australian legal practitioner.