Skip to content

A data-breach response plan for strata managers

If your managing-agent business is covered by the Privacy Act, you must carry out a reasonable and expeditious assessment of a suspected eligible data breach and take all reasonable steps to complete it within 30 days (Privacy Act 1988 (Cth) s 26WH(2)), and where serious harm is likely you must give the OAIC a statement and notify the individuals at risk (ss 26WK and 26WL). If the small-business exemption applies to your business, the notifiable-breach scheme does not legally bind you, but a strata office concentrates a whole building's personal information in one place, so every manager needs a plan tuned to the owners roll, arrears files and CCTV.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

First, are you inside the Notifiable Data Breaches scheme?

Be honest about this before you copy anyone's plan, because the legal duty is not universal in strata.

The Notifiable Data Breaches (NDB) scheme binds APP entities. The Notifiable Data Breaches (NDB) scheme applies to APP entities, and also to credit reporting bodies, credit providers and file number recipients (s 26WE(1)). Under section 6D your managing-agent business sits outside the APPs by default if its annual turnover for the previous financial year was A$3 million or less. That default is lost, and the list is not closed at two, if the business has had turnover above A$3 million in any completed financial year since it started (s 6D(4)(a), which is one-way: the exemption is not regained), if it is a body corporate related to a body corporate carrying on a business that is not a small business (s 6D(9)), if it discloses personal information about someone for a benefit or pays to collect it (s 6D(4)(c) and (d), each subject to the consent and legislation carve-outs in s 6D(7) and (8), and the one worth checking in strata is insurance commission), if it is a contracted service provider for a Commonwealth contract (s 6D(4)(e)), or if it opts in (s 6EA). One more that catches small offices: if you hold an individual's tax file number, for example a staff TFN declaration, you are a file number recipient (s 11) and the NDB scheme reaches that tax file number information whatever your turnover (s 26WE(1)(d)). This is the limb that surprises people, because it turns on ownership rather than on the size of the office. Australia's largest strata manager, PICA Group, publishes that it runs multiple brands across more than 220,000 lots; a firm sitting inside a group like that is an APP entity through s 6D(9) whatever its own local turnover. Under s 6D the exemption is the default position for a business turning over A$3 million or less, so a smaller independent manager may genuinely sit outside the NDB scheme, and so, on turnover, may the owners corporation itself. Whether it covers you turns on your own turnover, structure and dealings, not on a rule of thumb about strata. That exemption is still in force as at July 2026; its proposed removal is not law and has no legislated date, so this is not a deadline. Read: does the Privacy Act apply to strata managers?

So there are two honest tracks on this page. If you are covered, the NDB scheme is a legal obligation with defined steps. If you are exempt, you have no NDB duty, but you still hold the same sensitive data and should still have a plan. We cover both below, and we will not tell an exempt manager they must notify under a scheme that does not bind them.

Why strata is a real target, not a hypothetical

A strata office concentrates an entire building's personal information in one small place: the owners and strata roll, tenant and occupier details, levy arrears and debt-recovery files, by-law-breach records, committee and proxy records naming individuals, contractor details, and CCTV footage and access logs. That is a dense, saleable pool in one place.

This is already happening. In April 2026 the Kairos ransomware group named NSW-based Strata Republic on its darknet leak site and claimed to have taken a large data set (Cyber Daily, 20 April 2026). The company has not publicly confirmed the claim. Gold Coast strata manager SSKB disclosed in October 2022 that a third party had gained unauthorised access to its IT environment, downloaded information and posted a ransom demand, and that it had notified the OAIC and the Australian Cyber Security Centre. It said at the time it was still working out what personal information was involved (iTnews, 28 October 2022). The point is not to frighten you with a countdown. It is that the exposure is concrete and current, so a plan you can actually run under pressure is the practical baseline whether or not a statute compels one.

What counts as an "eligible data breach"

For a covered manager, the NDB scheme turns on an eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of, personal information you hold, that a reasonable person would conclude is likely to result in serious harm to an affected individual, where you have not been able to prevent that harm through remedial action.

In strata terms, that could be a ransomware exfiltration of the roll, a misdirected email sending one owner's arrears file to the wrong recipient, a lost laptop with the resident database, or CCTV footage accessed by someone with no authority to view it. Not every incident is an eligible breach. A quickly contained error you remediate before serious harm becomes likely may not meet the threshold. The scheme asks you to make that judgement, and to document it.

Your response plan, step by step

Write this down before you need it. A workable strata breach plan has six moves.

1. Contain. Stop the bleed first. Isolate the affected system, revoke or reset compromised credentials, recall a misdirected message where you can, and secure any physical device. Preserve evidence rather than wiping it.

2. Name who is in charge. Nominate a response lead and a deputy in advance, with after-hours contact details, so the plan does not stall on a Friday night. Record who is authorised to speak to residents, to the committee, and to the media.

3. Assess within about 30 days. If you are a covered manager and you suspect an eligible breach, 3. Assess within 30 days. If you are a covered manager and you are aware of reasonable grounds to suspect there may have been an eligible breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware of those grounds (s 26WH(2)). Assess what data was involved, who is affected, and whether serious harm is likely. The OAIC treats the 30 days as a ceiling, not a target, so move as fast as the facts allow and be ready to justify any delay in writing. Do not treat 30 days as a target to run down; move as fast as the facts allow.

4. Notify where serious harm is likely. For a covered manager, if the assessment concludes serious harm is likely and you cannot prevent it, 4. Notify where serious harm is likely. For a covered manager, once you have reasonable grounds to believe there has been an eligible data breach you must prepare a statement and give a copy to the OAIC as soon as practicable (s 26WK(2)). The statement must set out your identity and contact details, a description of the breach, the kinds of information involved, and recommended steps for individuals (s 26WK(3)). As soon as practicable after that, you must notify the contents to each individual the information relates to, or to each individual at risk, or, if neither is practicable, publish the statement on your website and take reasonable steps to publicise it (s 26WL(2) and (3)). In strata, the people at risk often include people who never chose to deal with you, such as tenants whose details came via the owner, so plan for how you will actually reach them.

5. Tell the owners corporation and committee. This sits outside the Privacy Act. Most management agreements carry their own confidentiality and reporting terms, so check what yours actually requires, and agree in advance who tells the committee and when. Agree in advance who tells the committee, and when.

6. Review and fix. After the incident, record what happened, close the gap that allowed it, and update the plan. A breach you learn nothing from is a breach you will repeat.

If you are exempt, you still need a plan

If you are a smaller independent manager under A$3 million and not part of a larger group, the NDB scheme does not legally bind you, and we are not going to pretend it does. But the data is just as sensitive, and residents are harmed just the same. The honest position is: you have no statutory notification duty, yet you should still contain the incident, work out who is affected, and tell the people whose data was exposed so they can protect themselves. Treating an exempt office as if breaches do not matter is not a free pass. Your management agreement is likely to impose its own confidentiality and data-handling obligations, and your state's surveillance-devices legislation binds you regardless of the Privacy Act, so check both.

Keep in mind too that a serious surveillance or data misuse can attract exposure outside the Privacy Act altogether, including under Keep in mind too that exposure can arise outside the Privacy Act altogether. The statutory tort of serious invasion of privacy in Schedule 2 of the Privacy Act commenced on 10 June 2025 and does not depend on the small-business exemption. It is narrow, though: under Sch 2 cl 7(1) the invasion must be intentional or reckless and serious, the person must have had a reasonable expectation of privacy, and the public interest in their privacy must outweigh any countervailing public interest. Carelessness alone is not enough to ground it.

Tune the plan to strata's data

A generic website breach template will not fit a strata office, because it does not know what you hold. Build your plan around the three data pools that actually create risk here.

One more link between breach and retention: the data you no longer hold cannot be breached. A covered manager must take such steps as are reasonable in the circumstances to destroy or de-identify personal information it no longer needs, unless an Australian law or a court or tribunal order requires it to be kept (APP 11.2). State strata law is one of those laws: in NSW the owners corporation must cause the records listed in s 180(1) of the Strata Schemes Management Act 2015 to be retained for 7 years, and the regulations may prescribe a different period (s 180(2)). Check your own state's floor. Holding ex-owner and former-tenant records past it just widens the blast radius. Read: how long must a strata manager keep owner records?

So, what should you do?

If you are covered, put a written NDB response plan in place now: contain, assign, assess within about 30 days, notify affected residents and the OAIC where serious harm is likely, tell the owners corporation, then review. If you are exempt, build the same plan minus the statutory notification, because the exposure is the same either way and residents are harmed just the same. Either way, tune it to the roll, the arrears files and the CCTV, and keep less data for less time. Read the cornerstone: privacy compliance for strata and owners-corporation managers.

Common questions

Does my strata management business have to notify a data breach?

Only if you are covered by the Privacy Act. Under s 6D the small-business exemption is the default for a business turning over A$3 million or less, and it is lost on any of several triggers: turnover above A$3 million in a completed financial year (s 6D(4)(a), which does not reverse), being a body corporate related to a body corporate that is not a small business (s 6D(9)), disclosing personal information for a benefit or paying to collect it (s 6D(4)(c) and (d), subject to the consent carve-outs), a Commonwealth contract (s 6D(4)(e)), or opting in (s 6EA). Holding an individual's tax file number also brings that information into the scheme whatever your turnover (ss 11 and 26WE(1)(d)). A covered manager must take all reasonable steps to assess a suspected eligible breach within 30 days and, where serious harm is likely, give the OAIC a statement and notify the individuals at risk. If none of the triggers applies to you, the scheme does not bind you, but you should still have a plan. A smaller independent manager under A$3 million and not in a larger group is generally not bound by the notifiable-breach scheme, though it should still have a plan.

How long do I have to respond to a suspected breach?

If you are covered, the scheme expects a reasonable and expeditious assessment, generally completed within about 30 days of becoming aware of grounds to suspect an eligible breach. That is an outer limit, not a target. Contain the incident and assess as fast as the facts allow, and notify as soon as practicable once serious harm is found to be likely.

We are under $3 million. Can we ignore data breaches?

No. You may have no legal duty to notify under the notifiable-breach scheme, and we will not pretend you do, but the Strata Republic listing on this page shows the exposure is not hypothetical, and the data you hold is highly sensitive. The honest baseline is to contain the incident, work out who is affected, and tell those people so they can protect themselves. State strata obligations, your management agreement and your reputation all still apply.

What is the single biggest breach risk in a strata office?

The owners roll, because it concentrates a whole building's identities and contact details in one file, and because state strata law requires the owners corporation to keep it and make it available for inspection by owners and other entitled people (in NSW, Strata Schemes Management Act 2015 ss 177 and 182). Nobody solves that by not holding it, so the plan is to secure it tightly, control who can access it, and treat a roll exposure as your worst-case scenario.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Notifiable Data Breaches scheme applies to your business depends on your turnover and structure under the Privacy Act 1988 (Cth); many smaller managers and owners corporations fall within the small-business exemption and are not bound by it. State strata legislation, your management agreement and state surveillance-devices law apply separately and vary by jurisdiction. The law changes over time, so check you are working from a current version and confirm your own state's requirements. For advice on your specific circumstances, consult a qualified Australian legal practitioner.