The Notifiable Data Breaches scheme became law on 22 February 2018. If you run a WordPress site that collects customer or visitor information, your obligations are now active. Here's a practical checklist.
The Privacy Amendment (Notifiable Data Breaches) Act 2017 came into full effect on 22 February 2018. Organisations covered by the Privacy Act 1988 must now notify both the OAIC and affected individuals when an eligible data breach occurs — one that is likely to result in serious harm to individuals whose personal information was involved.
For WordPress site owners, this isn't abstract legal compliance. A compromised website database containing customer names and email addresses is exactly the kind of event this scheme was designed to address.
Walk through every data collection point on your site:
Your privacy policy should accurately describe what information you collect, how you use it, how long you retain it, and how individuals can request access to or deletion of their data. If it was last updated before the NDB scheme existed, it needs a review.
If your site is compromised, you need a plan:
You don't need a formal documented plan for a small business, but thinking through these steps in advance means you're not making decisions under pressure.
Personal data you don't collect can't be breached. Review your contact forms and opt-in fields: are you collecting information you don't actually use? Phone numbers, addresses, and company details in enquiry forms are only worth collecting if your business process uses them. Removing unnecessary fields reduces your exposure.
The EU's General Data Protection Regulation (GDPR) comes into effect in May 2018. If your site is accessed by European visitors — which any public website potentially is — you may have additional obligations. The GDPR requirements overlap significantly with good data practices under the NDB scheme but add specific requirements around consent, data portability, and the right to erasure.
The practical outcome for most Australian small business WordPress sites: make sure your cookie consent and privacy policy cover what you actually do, and make sure you can honour a request to delete a customer's information if they ask.
DownUnder WP runs every site in an isolated environment on Australian servers. Your customer data stays in Australia, within Australian jurisdiction, on infrastructure you control through your dashboard.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.