Skip to main content
Rules Mate

Free tool

NDB notification timer

Last verified: 28 May 2026

When you become aware of a suspected data breach, you have up to 30 days to assess whether it's an 'eligible data breach' under the Privacy Act. Once confirmed eligible, you must notify the OAIC and affected individuals 'as soon as practicable'. This tool tracks both clocks and surfaces the next steps for each stage.

Breach details
Current stage
Enter the date you first became aware of the breach to start the 30-day clock.

Reference tool only — not legal advice. The OAIC, your privacy officer, and (where applicable) an Australian-admitted lawyer should be consulted on serious or complex breaches. Cyber insurers usually require notification within 24 hours — check your policy too.

Related tools

Not sure which obligations apply to you?

Run the Compliance Fingerprint — a 2-minute structured assessment that maps your business to every obligation, deadline and regulator that triggers.

Build my Compliance Fingerprint →