Free tool
NDB notification timer
When you become aware of a suspected data breach, you have up to 30 days to assess whether it's an 'eligible data breach' under the Privacy Act. Once confirmed eligible, you must notify the OAIC and affected individuals 'as soon as practicable'. This tool tracks both clocks and surfaces the next steps for each stage.
Reference tool only — not legal advice. The OAIC, your privacy officer, and (where applicable) an Australian-admitted lawyer should be consulted on serious or complex breaches. Cyber insurers usually require notification within 24 hours — check your policy too.
Related tools
Not sure which obligations apply to you?
Run the Compliance Fingerprint — a 2-minute structured assessment that maps your business to every obligation, deadline and regulator that triggers.
Build my Compliance Fingerprint →