Skip to main content
Rules Mate

Does Notifiable Data Breach (NDB) scheme apply to accountants and bookkeepers?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Yes

Yes. This obligation applies to accountants and bookkeepers whatever their structure or size. The deciding fact: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)).

The obligation in brief

Notifiable Data Breach (NDB) scheme. Under Part IIIC of the Privacy Act, APP entities must notify the OAIC and affected individuals if there has been an eligible data breach — unauthorised access, disclosure, or loss of personal information that is likely to result in serious harm. The assessment must be completed within 30 days of becoming aware.

Trigger: An eligible data breach — unauthorised access/disclosure of personal information likely to cause serious harm.

Why accountants & bookkeepers get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 24 of those industries the answer for "Notifiable Data Breach (NDB) scheme" is it depends on structure or size. Accountants & bookkeepers is one of the 11 where the answer is different: yes.

The deciding fact for accountants and bookkeepers: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A))

About the industry: Professional accounting and bookkeeping firms. Captured by Tranche 2 when providing designated services such as managing client money or company formation.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out)).

Answer by business structure and size

Each cell is the engine's outcome for a business in accountants & bookkeepers with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"Notifiable Data Breach (NDB) scheme": outcome for accountants and bookkeepers by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderYesYesYesYesYesYes
PartnershipYesYesYesYesYesYes
TrustYesYesYesYesYesYes
Pty Ltd companyYesYesYesYesYesYes
Public companyYesYesYesYesYesYes
Not-for-profit (unregistered)YesYesYesYesYesYes
Registered charityYesYesYesYesYesYes
Super fundYesYesYesYesYesYes
Foreign companyYesYesYesYesYesYes

What the obligation requires

When due
Notification 'as soon as practicable' after the entity is aware it is an eligible breach. Assessment within 30 days.
Evidence to keep
Breach assessment record, OAIC notification, individual notification, remediation steps log.
Maximum penalty
Up to $50M, or 3× benefit, or 30% of adjusted turnover (whichever is greater) for serious or repeated interferences
Regulator
OAIC
Jurisdiction
Commonwealth (national)

Other obligations where accountants & bookkeepers differ from the norm

Other industries with a non-default answer

Questions

Does Notifiable Data Breach (NDB) scheme apply to accountants and bookkeepers?
Yes. This obligation applies to accountants and bookkeepers whatever their structure or size. The deciding fact: AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)).
Is the answer the same for every industry?
No. For 24 of the 35 industries Rules Mate maps, the answer is it depends on structure or size. Accountants & bookkeepers is one of 11 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.