Where our data comes from

Every figure on this site is computed from the pinned sources - no number is typed in by hand.

Publication history

When the OAIC published each period of these statistics, and what each release changed in the published record. This is the record of the published data: when the data was incorporated into this site, with the file hashes, is internal and lives in the sources registry and the curation decisions below.

  1. 2018-07January to March 2018: 63 notificationsThe scheme commenced on 22 February 2018, so the first quarter is partial: 63 notifications over five weeks. The standalone quarterly report for this period carries no issue date; the figure entered the published record with the July 2018 quarterly report, whose history table prints it.
  2. 2018-07April to June 2018: 242 notificationsThe first full quarter of the scheme, and the first report with a complete quarter of data. Published July 2018.
  3. 2018-10July to September 2018: 245 notificationsPublished October 2018. Source counts first stated in prose this quarter: 139 malicious or criminal attack, 92 human error, 14 system fault.
  4. 2018-11NDB scheme 12-month insights reportA supplementary publication covering the scheme's first twelve months. It restates the quarterly reporting volumes and adds analysis; it publishes no period total that the quarterly reports do not already carry.
  5. 2019-02October to December 2018: 262 notificationsPublished February 2019. Source counts first stated in prose: 168 malicious or criminal attack, 85 human error, 9 system fault.
  6. 2019-05January to March 2019: 215 notificationsPublished May 2019. Source counts: 131 malicious or criminal attack, 75 human error, 9 system fault. The report notes the OAIC will move to six-monthly reporting from July 2019.
  7. 2019-08April to June 2019: 245 notificationsPublished August 2019, the last quarterly report. Source counts: 151 malicious or criminal attack, 84 human error, 10 system fault.
  8. 2020-02-28July to December 2019: 537 notificationsThe first six-monthly report, published 28 February 2020. Source counts: 343 malicious or criminal attack, 170 human error, 24 system fault.
  9. 2020-07-31January to June 2020: 518 notifications, and Jul-Dec 2019 restated to 532Published 31 July 2020. First published 518 notifications (317 malicious or criminal attack, 176 human error, 25 system fault). This release also changed the record for an earlier period: it restates July to December 2019 from 537 to 532, and carries a correction to a growth statement in the February 2020 report (19% should have been 17%).
  10. 2021-01-28July to December 2020: 539 notifications, and Jan-Jun 2020 restated to 512Published 28 January 2021, statistics current as at 8 January 2021. First published 539 notifications (310 malicious or criminal attack, 204 human error, 25 system fault). Restates January to June 2020 from 518 to 512, with source splits restated to 312 malicious or criminal attack and 173 human error.
  11. 2021-08-23January to June 2021: 446 notifications, and Jul-Dec 2020 restated to 530Published 23 August 2021, statistics current as at 7 July 2021. First published 446 notifications (289 malicious or criminal attack, 134 human error, 23 system fault). Restates July to December 2020 from 539 to 530, with source splits restated to 304 malicious or criminal attack, 203 human error and 24 system fault.
  12. 2022-02-22July to December 2021: 464 notifications, and Jan-Jun 2021 restated to 436Published 22 February 2022, statistics current as at 24 January 2022. First published 464 notifications (256 malicious or criminal attack, 190 human error, 18 system fault). Restates January to June 2021 from 446 to 436, with source splits restated to 281 malicious or criminal attack, 133 human error and 22 system fault.
  13. 2022-11-10January to June 2022: 396 notifications, and Jul-Dec 2021 restated to 460Published 10 November 2022, statistics current as at 30 September 2022. First published 396 notifications (250 malicious or criminal attack, 131 human error, 15 system fault). Restates July to December 2021 from 464 to 460, with source splits restated to 253 malicious or criminal attack and 189 human error. This is also the first period in which recruitment agencies are reported as a separate sector.
  14. 2023-03-01July to December 2022: 497 notifications, and Jan-Jun 2022 restated to 393Published 1 March 2023, statistics current as at 29 January 2023. First published 497 notifications (350 malicious or criminal attack, 123 human error, 24 system fault). Restates January to June 2022 from 396 to 393, with source splits restated to 249 malicious or criminal attack and 129 human error.
  15. 2023-09-05January to June 2023: 409 notifications, and Jul-Dec 2022 restated to 486Published 5 September 2023, statistics current as at 1 August 2023. First published 409 notifications (288 malicious or criminal attack, 107 human error, 14 system fault). Restates July to December 2022 from 497 to 486, and this is the release whose comparison block republishes that period's source splits as 340 malicious or criminal attack, 122 human error and 24 system fault, summing to the restated total.
  16. 2024-02-22July to December 2023: 483 notifications, and Jan-Jun 2023 restated to 407Published 22 February 2024, statistics current as at 30 January 2024. First published 483 notifications (322 malicious or criminal attack, 144 human error). Restates January to June 2023 from 409 to 407 without republishing that period's source split, which is why the split still sums to 409.
  17. 2024-09-16January to June 2024: 527 notifications, and Jul-Dec 2023 restated to 485Published 16 September 2024, statistics current as at 31 July 2024. First published 527 notifications (354 malicious or criminal attack, 156 human error). Restates July to December 2023 from 483 to 485, the only upward restatement in the series.
  18. 2025-05-13July to December 2024: 595 notifications, and Jan-Jun 2024 restated to 518Published 13 May 2025, statistics current as at 11 February 2025, with Consumer Data Right data current as at 11 March 2025. First published 595 notifications (404 malicious or criminal attack, 170 human error); with the restated January to June 2024 figure of 518 this release publishes the 2024 total of 1,113. It restates January to June 2024 from 527 to 518. This is the last bi-annual report: the OAIC moved to publishing through the statistics dashboard.
  19. 2026-06-29July to December 2025: 670 notificationsThe first period published as machine-readable data rather than a report: the NDB statistics workbook, created on data.gov.au on 29 June 2026. Ten tabs carry the period's notifications by month and source, individuals affected, kinds of personal information, specific sources of breach, the top 5 sectors by source, and time to identify and time to notify by sector and source. January to June 2025 has no published period: the dashboard replaced the report cycle before it was covered.

Restatements, period by period

Published figures restate as assessments complete. The site pins the latest value and keeps the first-published figure beside it.

PeriodFirst publishedLatestRestated in
2019-H1460447notifiable-data-breaches-report-januaryjune-2020
2019-H2537532notifiable-data-breaches-report-januaryjune-2020
2020-H1518512notifiable-data-breaches-report-julydecember-2020
2020-H2539530notifiable-data-breaches-report-januaryjune-2021
2021-H1446436notifiable-data-breaches-report-july-to-december-2021
2021-H2464460notifiable-data-breaches-report-january-to-june-2022
2022-H1396393notifiable-data-breaches-report-july-to-december-2022
2022-H2497486notifiable-data-breaches-report-january-to-june-2023
2023-H1409407notifiable-data-breaches-report-july-to-december-2023
2023-H2483485notifiable-data-breaches-report-january-to-june-2024
2024-H1527518notifiable-data-breaches-report-july-to-december-2024

Figure basis

Share of notifications that were malicious or criminal, per half year

basis: period (published report figure)

Figure 'source_share_trend' on a period basis, computed from 74 fact rows (hash 8b7a21986c2b034a).

The sources

How each dimension is derived

Curation decisions