All posts
October 2017·6 min read

Australia's data breach notification laws: what WordPress site owners need to know

The Privacy Amendment (Notifiable Data Breaches) Act 2017 passed parliament in February 2017 and takes effect in February 2018. If your WordPress site collects contact details, processes orders, or stores member information, the new obligations apply to you.

What the Notifiable Data Breaches scheme is

Australia's Privacy Amendment (Notifiable Data Breaches) Act 2017 passed parliament in February 2017 and takes effect on 22 February 2018. It amends the Privacy Act 1988 to require organisations covered by the Act to notify both affected individuals and the Office of the Australian Information Commissioner (OAIC) when an eligible data breach occurs.

An eligible data breach is one that is likely to result in serious harm to any of the individuals whose information was involved. This includes unauthorised access to personal information — such as a hacker accessing your website's database.

Does it apply to your website?

The scheme applies to organisations with an annual turnover above $3 million, as well as certain smaller businesses regardless of turnover — including health service providers, businesses that trade in personal information, and businesses that hold tax file numbers.

Even if you're below the turnover threshold, consider your obligations: if your WordPress site processes payments, stores customer order history, runs a membership system, or collects health-related information, you may be covered. If in doubt, consult a lawyer familiar with Australian privacy law.

What a breach notification requires

If an eligible breach occurs, you must notify affected individuals "as soon as practicable" and notify the OAIC. The notification to individuals must describe the breach, what information was involved, what steps you recommend they take, and your contact details.

You also need to have assessed the breach quickly enough to make that notification timely — the expectation is that you have processes in place to detect and assess a breach, not that you find out about it months later from a customer.

WordPress-specific implications

For a business running a WordPress site, the practical implications:

  • Contact form data. If your contact form stores submissions in the database (most do by default), a database breach exposes that data. Know what's stored and for how long.
  • WooCommerce orders. Customer names, addresses, email addresses, and order history are personal information. A compromised WooCommerce database is a notifiable breach.
  • User accounts. Any WordPress site with user registration stores personal information. Compromised user tables — including hashed passwords — are potentially notifiable.
  • Third-party plugins. Plugins that collect or store personal information — booking systems, membership plugins, enquiry forms — all extend your data footprint. Know what they store.

Practical steps to prepare

  • Audit what personal information your WordPress site collects and where it's stored
  • Review your privacy policy to accurately describe your data practices
  • Ensure you have recent backups — you can't assess a breach's scope if you don't know what was in the database
  • Review your hosting security: is your site kept updated, is login access controlled, is your hosting environment appropriately secured?
  • Know who to contact: OAIC is at oaic.gov.au, and having a lawyer's number for legal guidance is worth it for a covered business

The security connection

The NDB scheme is partly a motivator to take security seriously — the cost of a breach now includes mandatory notification obligations on top of cleanup and recovery. For a small business, notifying customers that their data was exposed is a reputational event that goes beyond the technical incident.

The best way to avoid triggering the scheme isn't to minimise your notification obligations — it's to prevent the breach from happening in the first place.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.