Australia Releases Privacy Amendment Bill With 72-Hour Breach-Reporting Deadline
Summary
The Australian Attorney-General's Department released the Privacy Amendment (Personal Data Protection) Bill 2026 for consultation on 1 September 2026, proposing a fixed 72-hour deadline for notifying the Information Commissioner of an eligible data breach.
Details
The bill would replace the notifiable-data-breach scheme's "as soon as practicable" standard with a 72-hour deadline running from when an entity has reasonable grounds to believe an eligible breach occurred, while leaving the existing 30-day assessment window unchanged. Entities unable to file a complete statement could file an incomplete one with written notice of what is missing; failing to file anything within 72 hours could attract an infringement or compliance notice.
The package also introduces a deliberately narrow erasure right binding only "large digital platforms" โ Online Safety Act services clearing a $500m gross-revenue test or 2.5 million average monthly Australian users โ with broad exceptions for law enforcement, legal retention, technical impossibility and ongoing service delivery. The consultation paper flags concerns about discreet recording by smart glasses but stops short of banning them.
Assessment
The 72-hour deadline aligns the NDB scheme with the Security of Critical Infrastructure Act's 72-hour incident reporting and the Cyber Security Act 2024's ransomware-payment notification, bringing Australian breach-notification obligations into line with other jurisdictions' fixed-deadline regimes. The narrow erasure right is a significant retreat from the 2023 Privacy Act Review's economy-wide recommendation.