The Privacy Amendment (Notifiable Data Breaches) Act 2017 passed parliament in February 2017 and takes effect in February 2018. If your WordPress site collects contact details, processes orders, or stores member information, the new obligations apply to you.
Australia's Privacy Amendment (Notifiable Data Breaches) Act 2017 passed parliament in February 2017 and takes effect on 22 February 2018. It amends the Privacy Act 1988 to require organisations covered by the Act to notify both affected individuals and the Office of the Australian Information Commissioner (OAIC) when an eligible data breach occurs.
An eligible data breach is one that is likely to result in serious harm to any of the individuals whose information was involved. This includes unauthorised access to personal information — such as a hacker accessing your website's database.
The scheme applies to organisations with an annual turnover above $3 million, as well as certain smaller businesses regardless of turnover — including health service providers, businesses that trade in personal information, and businesses that hold tax file numbers.
Even if you're below the turnover threshold, consider your obligations: if your WordPress site processes payments, stores customer order history, runs a membership system, or collects health-related information, you may be covered. If in doubt, consult a lawyer familiar with Australian privacy law.
If an eligible breach occurs, you must notify affected individuals "as soon as practicable" and notify the OAIC. The notification to individuals must describe the breach, what information was involved, what steps you recommend they take, and your contact details.
You also need to have assessed the breach quickly enough to make that notification timely — the expectation is that you have processes in place to detect and assess a breach, not that you find out about it months later from a customer.
For a business running a WordPress site, the practical implications:
The NDB scheme is partly a motivator to take security seriously — the cost of a breach now includes mandatory notification obligations on top of cleanup and recovery. For a small business, notifying customers that their data was exposed is a reputational event that goes beyond the technical incident.
The best way to avoid triggering the scheme isn't to minimise your notification obligations — it's to prevent the breach from happening in the first place.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.