30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

AI data leaks: Australia's NDB rules

For information and an entity covered by the NDB scheme, assess whether unauthorised access, disclosure or loss is likely to cause serious harm and whether remedial action prevents that risk. Suspected eligible breaches need prompt assessment. The 30-calendar-day assessment rule is not permission to delay required notification.

For Australian privacy officers, incident responders and security leaders

Aona field notesC25
Assess harm and the remedy
Suspected → assessed → notified

A provider deletion request alone does not show that serious harm was prevented.

All people, events, risks and timeline entries are invented. No actual eligible-breach determination, provider response or notification has occurred.

01

Confirm the event and applicable coverage

Identify the entity, personal information and actual disclosure, access or loss. Check the NDB scheme’s applicability rather than assuming every workplace record and organisation is covered in the same way. Other Australian or overseas requirements may also apply.

For an AI-related event, record the service, account, feature, payload and recipients. Distinguish a submission stopped before transmission from one that reached a provider or was shared onwards. Keep evidence in the approved incident process and avoid copying personal information into unnecessary support or collaboration channels.

Source context: OAIC: Quick reference guide for responding to data breaches · OAIC: When to report a data breach

02

Assess likely serious harm using the actual facts

OAIC guidance describes serious harm as potentially physical, psychological, emotional, financial or reputational. It assesses likelihood from the position of a properly informed reasonable person and explains likely as more probable than not, rather than merely possible.

Consider the information’s sensitivity, who obtained it, the circumstances and the foreseeable consequences for affected people. Do not infer no serious harm just because no complaint has arrived. Equally, a tool being unapproved does not by itself establish that serious harm is likely.

Source context: OAIC: Quick reference guide for responding to data breaches

03

Ask what the remedial action actually prevented

If remedial action prevents the likely risk of serious harm, the breach is not eligible on that basis. Where it protects only some individuals in a larger affected group, the notice analysis may differ for the remaining people. Record the action, timing and evidence of its effect.

For an AI service, a request to delete content is an action requested, not proof that every recipient or retained copy was addressed. Obtain the relevant response and facts. Keep containment, a future input block and remediation of the original exposure as separate findings.

Source context: OAIC: Quick reference guide for responding to data breaches

04

Keep assessment and notification timing distinct

If the entity suspects an eligible breach, OAIC says it must take all reasonable steps to complete the assessment within 30 calendar days after becoming aware of the grounds or information that caused the suspicion. Assessment should be quick; do not treat day 30 as the target start date.

Once reasonable grounds to believe an eligible breach occurred exist, notify the relevant individuals and provide the OAIC statement as soon as practicable, unless an applicable exception changes the duty. The assessment period is not a universal notification deadline or a reason to postpone a conclusion already reached.

Source context: OAIC: Quick reference guide for responding to data breaches

05

Document the decision and its scope

The teaching example below stipulates sensitive information, an uncontrolled disclosure and a credible risk that is assessed as likely serious harm, with no effective remedy. On those fictional facts, it follows the eligible-breach notification path, subject to applicable exceptions. No real incident conclusion is represented.

A second branch shows why reliable evidence of a blocked transmission can lead to a different finding. Keep the factual basis, uncertainty, affected scope and responsible owner with the decision. Review the incident afterwards and improve controls without rewriting the investigation as an assumed success.

Source context: OAIC: Quick reference guide for responding to data breaches

Put it into practice

NDB serious-harm and remedy exercise

Two fictional AI-submission scenarios separate evidence of disclosure from the serious-harm and remediation decision.

All people, events, risks and timeline entries are invented. No actual eligible-breach determination, provider response or notification has occurred.

Two different timing questions
01

Suspect

Record the grounds and assess promptly

02

Assess

Likely serious harm and remedial action

03

Believe eligible

Apply notice duties as soon as practicable

The 30-day assessment rule is separate.

NDB serious-harm and remedy exercise
Decision pointStipulated example factsIllustrative outcome
Scenario A: disclosureSensitive personal details reached an uncontrolled external recipient.Proceed to harm and remedy assessment; the application label alone is not the conclusion.
Scenario A: likely harmThe exercise stipulates a credible threat assessed as making serious harm more probable than not.Likely-serious-harm condition is assumed met for teaching, not inferred from a log alone.
Scenario A: remedyNo completed action prevents that stipulated risk.Follow the eligible-breach notification path, subject to applicable exceptions.
Scenario B: blocked inputReliable fictional evidence establishes no transmission and no other disclosure on the assessed path.No breach is established from that blocked submission; document the evidence and remaining scope.
Unknown factsRecipient access or remedy effectiveness remains unverified.Assess promptly; take all reasonable steps within the applicable 30-calendar-day assessment period.
Conclusion reachedReasonable grounds to believe an eligible breach exist in the scenario.Notify as soon as practicable where required; do not wait for day 30.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

australia-ai-ndb-assessment.mdInspect
# NDB serious-harm and remedy exercise

All people, events, risks and timeline entries are invented. No actual eligible-breach determination, provider response or notification has occurred.

Two fictional AI-submission scenarios separate evidence of disclosure from the serious-harm and remediation decision.

| Decision point | Stipulated example facts | Illustrative outcome |
| --- | --- | --- |
| Scenario A: disclosure | Sensitive personal details reached an uncontrolled external recipient. | Proceed to harm and remedy assessment; the application label alone is not the conclusion. |
| Scenario A: likely harm | The exercise stipulates a credible threat assessed as making serious harm more probable than not. | Likely-serious-harm condition is assumed met for teaching, not inferred from a log alone. |
| Scenario A: remedy | No completed action prevents that stipulated risk. | Follow the eligible-breach notification path, subject to applicable exceptions. |
| Scenario B: blocked input | Reliable fictional evidence establishes no transmission and no other disclosure on the assessed path. | No breach is established from that blocked submission; document the evidence and remaining scope. |
| Unknown facts | Recipient access or remedy effectiveness remains unverified. | Assess promptly; take all reasonable steps within the applicable 30-calendar-day assessment period. |
| Conclusion reached | Reasonable grounds to believe an eligible breach exist in the scenario. | Notify as soon as practicable where required; do not wait for day 30. |

## Review steps

- Establish disclosure and coverage: Identify the actual information, entity, account, path and recipients before deciding applicability.
- Evidence harm and mitigation: Record why serious harm is likely or not, and what completed remedy actually prevented.
- Separate the two timing duties: Track suspicion/assessment and the later belief/notification decision without treating 30 days as a universal notice period.

## Fictional evidence timeline

Day 0: employee reports the suspected AI disclosure; incident owner records the grounds for suspicion.
Day 1: team secures the payload/account facts and requests recipient information.
Day 2: the exercise stipulates evidence of uncontrolled disclosure and likely serious harm; effective remediation is not established.
Day 2 onward: the authorised owner follows the eligible-breach notice path as soon as practicable, subject to the actual rules and exceptions.
Day 30: not a permission to wait; the separate assessment requirement concerns all reasonable steps to complete a suspected-breach assessment.

No real notice is drafted or sent by this fixture. Apply the actual entity, information and evidence before making a real decision.

## Source and scope

Guide: https://aona.ai/resources/guides/australia-ai-data-breach-assessment/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- OAIC: Quick reference guide for responding to data breaches: https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches
- OAIC: When to report a data breach: https://www.oaic.gov.au/privacy/notifiable-data-breaches/when-to-report-a-data-breach
Download australia-ai-ndb-assessment.md
australia-ai-ndb-assessment.csvInspect
Decision point,Stipulated example facts,Illustrative outcome
Scenario A: disclosure,Sensitive personal details reached an uncontrolled external recipient.,Proceed to harm and remedy assessment; the application label alone is not the conclusion.
Scenario A: likely harm,The exercise stipulates a credible threat assessed as making serious harm more probable than not.,"Likely-serious-harm condition is assumed met for teaching, not inferred from a log alone."
Scenario A: remedy,No completed action prevents that stipulated risk.,"Follow the eligible-breach notification path, subject to applicable exceptions."
Scenario B: blocked input,Reliable fictional evidence establishes no transmission and no other disclosure on the assessed path.,No breach is established from that blocked submission; document the evidence and remaining scope.
Unknown facts,Recipient access or remedy effectiveness remains unverified.,Assess promptly; take all reasonable steps within the applicable 30-calendar-day assessment period.
Conclusion reached,Reasonable grounds to believe an eligible breach exist in the scenario.,Notify as soon as practicable where required; do not wait for day 30.
Download australia-ai-ndb-assessment.csv
ndb-fictional-evidence-timeline.csvInspect
stage,fictional_event,meaning
Day 0,Grounds for suspicion recorded,Start prompt assessment
Day 1,Payload and recipient facts sought,Evidence gathering
Day 2,Likely serious harm and ineffective remedy stipulated,Illustrative eligible-breach path
After conclusion,Notice owner acts as soon as practicable if required,Do not wait for day 30
Download ndb-fictional-evidence-timeline.csv

Before you proceed

Keep these distinctions clear

A request is not proof of remediation
Record what was actually done and how it affected likely harm.
Thirty days is not a universal notice period
Do not delay required notification after the relevant conclusion is reached.

Apply it to employee AI use

Bring your actual data path.

Supported Aona activity and policy evidence may help establish facts about an employee input path.

It does not determine NDB eligibility, prove every copy was removed or notify the OAIC and affected individuals.

Use an invented payload to distinguish observed blocking from transmission and verify what evidence the selected path records.

Review your use case

FAQ

Questions for this decision

Is every AI upload automatically notifiable in Australia?
No. Confirm scheme coverage and the actual access, disclosure or loss, likely serious harm, remedial action and applicable exceptions.
Do we have 30 days before telling anyone?
Do not treat the assessment rule that way. OAIC describes prompt assessment and all reasonable steps within 30 calendar days; required notification follows as soon as practicable once the relevant eligible-breach conclusion is reached.
Does deleting the visible chat prevent serious harm?
It may be one action, but assess the actual recipients, retained copies and effect of remediation. A visible deletion alone does not establish that the risk was prevented.
Can remediation affect only part of the group?
Yes. OAIC explains that where remedial action prevents likely serious harm for some individuals, the notice analysis can differ for those still at risk. Keep the affected scope and reasoning explicit.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. OAIC: Quick reference guide for responding to data breaches

    Serious-harm and remedial-action assessment, reasonable steps to complete suspected-breach assessment within 30 calendar days and notification as soon as practicable when required.

    regulator · checked 2026-09-21
  2. OAIC: When to report a data breach

    Eligible data-breach conditions, likely serious harm and remedial action; not every disclosure is automatically notifiable.

    regulator · checked 2026-09-21
AI data disclosure: Australia’s NDB assessment | Aona