All posts
March 2018·5 min read

Australia's data breach laws are now in effect: a checklist for WordPress site owners

The Notifiable Data Breaches scheme became law on 22 February 2018. If you run a WordPress site that collects customer or visitor information, your obligations are now active. Here's a practical checklist.

What's now in effect

The Privacy Amendment (Notifiable Data Breaches) Act 2017 came into full effect on 22 February 2018. Organisations covered by the Privacy Act 1988 must now notify both the OAIC and affected individuals when an eligible data breach occurs — one that is likely to result in serious harm to individuals whose personal information was involved.

For WordPress site owners, this isn't abstract legal compliance. A compromised website database containing customer names and email addresses is exactly the kind of event this scheme was designed to address.

Immediate checklist

1. Know what personal data your site holds

Walk through every data collection point on your site:

  • Contact forms — do they store submissions in the database, or just email them to you? (Most store them.)
  • WooCommerce — customer names, addresses, email addresses, order history
  • User registration — any site with accounts stores personal information
  • Booking or enquiry plugins — check their settings for what gets stored and for how long
  • Newsletter signup forms — do you store email addresses locally or only in your email platform?

2. Update your privacy policy

Your privacy policy should accurately describe what information you collect, how you use it, how long you retain it, and how individuals can request access to or deletion of their data. If it was last updated before the NDB scheme existed, it needs a review.

3. Know your incident response

If your site is compromised, you need a plan:

  • Who do you call? (Hosting provider, security professional, legal counsel)
  • How do you assess the scope of what was accessed?
  • What's the OAIC notification process? (Submit at oaic.gov.au)
  • How do you notify affected customers?

You don't need a formal documented plan for a small business, but thinking through these steps in advance means you're not making decisions under pressure.

4. Verify your security basics are in order

  • WordPress core and all plugins are current
  • Admin accounts use strong, unique passwords
  • Login access is protected at the server level (rate limiting at minimum)
  • You have recent backups — these are essential for assessing a breach's scope
  • Unused plugins are deleted (not just deactivated)

5. Consider data minimisation

Personal data you don't collect can't be breached. Review your contact forms and opt-in fields: are you collecting information you don't actually use? Phone numbers, addresses, and company details in enquiry forms are only worth collecting if your business process uses them. Removing unnecessary fields reduces your exposure.

What GDPR means alongside NDB

The EU's General Data Protection Regulation (GDPR) comes into effect in May 2018. If your site is accessed by European visitors — which any public website potentially is — you may have additional obligations. The GDPR requirements overlap significantly with good data practices under the NDB scheme but add specific requirements around consent, data portability, and the right to erasure.

The practical outcome for most Australian small business WordPress sites: make sure your cookie consent and privacy policy cover what you actually do, and make sure you can honour a request to delete a customer's information if they ask.


DownUnder WP runs every site in an isolated environment on Australian servers. Your customer data stays in Australia, within Australian jurisdiction, on infrastructure you control through your dashboard.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.