Time to respond
How fast entities identify breaches and notify the OAIC. Time taken is a count of calendar days. Under section 26WH of the Privacy Act, entities must complete an assessment of a suspected eligible data breach within 30 days of becoming aware of reasonable grounds to suspect one; the reports publish the within-30-days share as a timeliness measure. There is no statutory notification deadline in these measures, so this page reports timeliness, it does not grade compliance.
Shares are over the in-range breaches only (out-of-range date values are excluded by the workbook); each basis label shows the base.
Within 30 days, per period
Notified to the OAIC within 30 days
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.
Identified within 30 days
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.
Identify and notify, Jul-Dec 2025
Time to identify the breach, by top 5 sectors
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?A missing band means the workbook row is absent (out-of-range date values are excluded), not zero. Time taken is a count of calendar days.
Time to identify the breach, by source
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?A missing band means the workbook row is absent (out-of-range date values are excluded), not zero. Time taken is a count of calendar days.
Time to notify the OAIC, by top 5 sectors
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?A missing band means the workbook row is absent (out-of-range date values are excluded), not zero. Time taken is a count of calendar days.
Time to notify the OAIC, by source
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?A missing band means the workbook row is absent (out-of-range date values are excluded), not zero. Time taken is a count of calendar days.