
"1,205 breach notifications: what Australia's data breach data says, and how the OAIC started actually enforcing"
1,205 breach notifications: what Australia's data breach data says, and how the OAIC started actually enforcing
Australia's Notifiable Data Breaches scheme turned eight in 2026, and it has never been busier. The regulator also stopped behaving like a complaint desk. Both facts matter if you're a business with notification obligations — or a person wondering why their health provider keeps texting them an apology.
The numbers: an all-time high
The OAIC received 1,205 data breach notifications in the 2025 calendar year — the highest since the scheme began in 2018, and an 8% rise on 2024's 1,112. The OAIC published the figures in July 2026 alongside a new quick-reference guide for entities trying to work out whether, and how, to notify. (OAIC media release, NDB statistics dashboard)
The shape of the data is consistent with prior years:
- Malicious or criminal activity dominates: 716 of the 1,205 notifications — cyber hacking remains the primary cause.
- Health service providers top the list again: 225 notifications, 19% of the total, followed by financial services (157), Australian Government agencies (118), and professional associations and education (81 each).
- Public concern is climbing faster than the numbers: OAIC's 2026 Australian Community Attitudes to Privacy Survey found 82% of Australians see data breaches as the top privacy risk, up from 74% in 2023.
The trend line since the 2022 amendments is instructive: the December 2022 changes raised the maximum civil penalty under s 13G dramatically and signalled that notification failures would carry a price tag. The 2024 tranche-1 amendments layered on further civil penalty provisions from 11 December 2024. Notification volume rising alongside real penalties suggests entities are both getting breached more and taking the reporting duty more seriously.
The enforcement shift
For years the standard critique of the OAIC was that it was a complaint-handling shop with slow-moving determinations. Privacy Commissioner Carly Kind put that formally to bed in March 2026, describing an intentional shift toward strategic enforcement. The results she cited:
- Australian Clinical Labs: the Federal Court's first-ever civil penalty under the Privacy Act, $5.8 million, imposed in October 2025 for the 2022 Pathology breach.
- Optus and Medibank: civil penalty proceedings filed and continuing through 2026.
- Meta Platforms: a $50 million settlement the OAIC describes as a watershed.
- Bunnings and Kmart: determinations applying the Privacy Act to facial recognition — landmark decisions about new technologies rather than classic breaches.
(OAIC — Handling privacy complaints, Bird & Bird review)
The OAIC also made and published ten determinations in the last financial year, gained infringement-notice powers, and in 2026 is running Commissioner-initiated investigations into rental technology, connected cars and tracking pixels, plus an inaugural compliance sweep covering in-person collection practices in real estate and licensed venues.
What changed after 2022
The 2022 amendments did two durable things. First, they made non-compliance expensive in theory; October 2025's ACL penalty proved it in practice. Second, they reset expectations — an entity that delays assessment or sits on a breach now faces a regulator with penalty authority and, since 2024, infringement notices. The pending tranche-2 exposure draft would tighten further: 72-hour notification for eligible breaches and positive duties to maintain breach response systems. That is draft law, not current law — but the direction is unambiguous. (Attorney-General's Department consultation)
Practical takeaways
If you run an entity under the scheme: the OAIC's own quick-reference guide and self-assessment checklist are the honest starting point, and the ACAMS-era excuse "we didn't know we had to notify" has a measurable price. If you're an individual: expect breach notices to keep coming — health data is the leakiest category. Reduce what a breach can cost you by cutting what's connected in the first place; our degoogled phone comparison covers devices designed to hold less, and a FIDO2 hardware key neutralises the password-reuse cascade that turns one breach into five. For the broader reform picture, see our Privacy Act reform status piece.
This article is general information, not legal advice.