Under the Privacy Act 1988, Australian businesses must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. This includes breaches involving personal information like names combined with financial details, health information, or identity documents. Notification must occur as soon as practicable after becoming aware of the breach. Penalties for serious privacy breaches can reach $50 million, three times the benefit obtained, or 30% of adjusted turnover—whichever is greater. Mercury IT helps businesses assess breach severity, meet notification obligations, and implement improvements to prevent future incidents.

