Data notes
The definitional authority for every figure on this site. The chat answers are grounded in this text.
Data notes and disclaimer
Definitional authority for every figure on this site. The chat and the pages cite this corpus verbatim; anything this file does not say, the site does not claim.
What the figures count
A notification is a notice an entity gives the OAIC under the Notifiable Data Breaches (NDB) scheme in the Privacy Act 1988. Where a breach affects multiple entities, the OAIC may receive multiple notifications about one incident; from the 2021 reports these are counted as a single primary notification with secondary notifications reported separately. Earlier report eras count notifications differently, so period-to-period comparisons across that boundary are not like-for-like; the history page marks the boundary.
Notifications under the My Health Records Act 2012 are excluded.
Source of breach categories
The source of a breach is based on information provided by the reporting entity; where more than one source is possible, the dominant or most likely source is selected. The categories:
- Malicious or criminal attack. A deliberate act: cyber incident, rogue employee or insider threat, social engineering or impersonation, theft of paperwork or a data storage device.
- Human error. Unintended actions: personal information sent to the wrong recipient, failure to use BCC, unauthorised disclosure, loss of paperwork or a storage device, insecure disposal.
- System fault. A business or technology process error: unintended access or unintended release or publication.
- Other, and Currently unknown. Where the source is neither of the above, or not yet determined. The Source of breach tab in the workbook excludes these two categories from its group totals.
Individuals affected
Figures reflect the number of individuals world-wide whose personal information was compromised, as estimated by the notifying entity, and are published in ranges. Large-scale breach thresholds moved over the series: 2022 and 2023 reports count breaches affecting over 5,000 Australians; the 2024-H1 report counts over 100,000 Australians. The threshold travels with each figure.
Kinds of personal information
A breach may involve more than one kind, so kind counts never sum to the period total. Kind definitions follow the OAIC glossary: contact information (address, phone, email), identity information (passport, licence numbers), financial details, health information, tax file numbers, other sensitive information, and (from 2025) digital ID information and documents.
Time to identify and time to notify
Time taken is a count of calendar days, measured from when the entity became aware of the incident. The workbook publishes band counts (10 days or fewer, 11-20, 21-30, more than 30); rows with out-of-range date values are excluded, so a missing band is an exclusion, not a zero. Median days figures exist in some report prose; where no explicit whole-period median is published, the site shows no median rather than computing one.
Coverage checked against the sources, 12 September 2026
The site was checked against every source it can lawfully and reliably read:
- data.gov.au dataset 5781dc17 publishes one resource, the Jul-Dec 2025 workbook (created 29 June 2026). It is ingested, and the dataset has not changed since.
- The OAIC report series carries 18 reports from 2018-Q1 to Jul-Dec 2024. All 18 are transcribed. No report has been published since; the bi-annual PDF cycle ended when the statistics dashboard replaced it.
- January to June 2025 is therefore unpublished in every source this site can read. The live OAIC Power BI dashboard is the only place it might appear: its public data endpoint refuses anonymous queries, and a headless render returns the viewer shell without the report canvas, so nothing can be read from it. The site keeps 2025-H1 as a disclosed gap rather than reading a value off a chart, which the platform never does.
So the series is current as at 12 September 2026: the latest published period (Jul-Dec 2025) is on the site, and the one unpublished period is marked as a gap.
Publication windows and cadence
The scheme commenced 22 February 2018, so 2018-Q1 is a partial quarter. The OAIC reported quarterly through H1 2019 and half-yearly from H2 2019. No report was published for January-June 2025: the dashboard replaced the PDF cycle. 2025-H1 figures are absent from the pinned corpus and the site shows the gap.
Restatements and as-of dates
Published figures restate over time as notifications are assessed. Every figure on this site carries the as-of date of the report that published it. Where a later report restated a figure, the site shows the latest value, keeps the first-published value beside it, and names the report that restated it. The golden boot check pins the latest published total for every period; a drift refuses to start the service.
Basis labels
Every figure carries a basis label:
- basis: period. A published period-level figure (report table or workbook tab total).
- basis: month. A published calendar-month figure from the workbook.
- basis: derived. A platform sum of published figures, never a published number itself. 2018-H1 and 2019-H1 totals are derived.
Corrections and restatements across reports
Every report in the corpus was re-read on 12 September 2026 for statements that correct an earlier period. Two kinds were found and applied or recorded:
- Totals. Later reports restate earlier period totals as assessments complete. The site pins the latest published value and shows the first-published figure beside it on the history page.
- Source splits. The January-June 2023 report's comparison block restates Jul-Dec 2022's split (malicious 340, human error 122, system faults 24), which sums exactly to that report's restated total of 486. The site uses the restated split; the first-published split is kept in the transcription registry.
- Growth statements. The January-June 2020 report corrects a growth figure in the Jul-Dec 2019 report from 19% to 17%. The platform computes its own changes from published counts, so no figure on the site depended on it.
Where a later report restated a total without republishing the split, the split still sums to the first-published figure. Four periods are affected (2019-H2 by 5, 2020-H1 by 2, 2020-H2 by 1, 2023-H1 by 2). The site publishes both as published and discloses the residual rather than adjusting a figure to force a sum.
Known source quirks
- The workbook's Source of breach tab prints the system-fault row "Unintended release or publication 27" twice. The site keeps the first occurrence; the published group totals are unaffected.
- Across the six workbook months, the source-of-breach rows sum to 673 against the published Grand Total of 670. The month rows re-sum internally; the category-level discrepancy is in the source workbook and the site discloses it instead of re-allocating three notifications.
What this site does not do
- No legal advice. The site answers questions about the published statistics, not about a reader's obligations under the Privacy Act.
- No advice on whether a specific incident is an eligible data breach.
- Nothing that identifies a breach, an entity, or an individual. The data is aggregate; the chat refuses requests that point at a named entity.
- No fabricated figures. A number the pinned sources do not publish is shown as a gap, not guessed.