September 15, 2026

Amanda Lacey

72 Hours Is the New Deadline for Every Australian Data Breach

On 1 September 2026, Attorney-General Michelle Rowland released draft reforms to the Privacy Act that replace one of the vaguest phrases in Australian regulation with one of the most precise. Right now, organisations that suffer an eligible data breach must notify affected individuals and the Information Commissioner “as soon as practicable.” Under the proposed changes, once an organisation has reasonable grounds to believe a notifiable breach has occurred, the clock is fixed: 72 hours.

What’s actually changing

Organisations keep the existing 30 days to work out whether a suspected incident meets the threshold of an “eligible” data breach. Once that threshold is met, though, the 72-hour countdown to notify the Commissioner starts, not from when the breach happened, but from when the organisation knew. If the full picture isn’t available in time, the draft bill allows a statement to be lodged with reasons for the gaps, followed by updates “as soon as possible.” The reforms also introduce a general obligation to take reasonable steps to mitigate harm for every data breach, not only the ones serious enough to be classed as eligible. No commencement date has been set, and legal commentators are pushing for a runway of around two years, similar to past privacy overhauls, but the direction of travel is settled.

Why this is a communications problem before it’s a compliance one

A fixed deadline changes what “fast” means, and it changes it for the public-facing response as much as the regulatory filing. Seventy-two hours is not enough time to work out what happened, brief a spokesperson, draft a customer notification, prepare a media statement and get sign-off from legal, all for the first time, while the incident is still live. Security specialists have already flagged the practical gap this creates: as Illumio’s Andrew Kay put it, a company “cannot protect Australians’ personal information if it does not know where that information sits” or detect activity fast enough to act on it. The same gap applies to communications. An organisation that hasn’t rehearsed its breach response before an incident will spend most of its 72 hours finding out what it needs to say, rather than saying it well.

A legal deadline forces a decision. It doesn’t write the statement for you.

What it means for financial services, legal and property clients

The sectors carrying the most sensitive personal and financial data are the ones with the least room to improvise. A financial services firm holding account and identity data, a law firm holding privileged client files, or a property business moving settlement funds and identity documents through conveyancing, all sit squarely inside the new regime, and all face reputational exposure that moves faster than a 72-hour filing clock once a breach becomes public through other means, a customer complaint, a journalist, or social media, before the official notification lands.

The takeaway

The firms that come through a breach with their reputation intact will be the ones that treated 72 hours as a deadline for execution, not for drafting. That means a pre-approved notification template, a named and briefed spokesperson, and a decision tree for the 30-day eligibility window and the 72-hour clock that follows it, all agreed before an incident, not during one. The reform is still in draft. The advantage of building the plan now is that it’s one of the only parts of this you get to do without a deadline.

Need a crisis plan? We can help.

Amanda Lacey, Crisis Communications professional

By Amanda Lacey

This article is provided for general commentary on public interest matters and does not constitute legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *