Regulatory obligations remain with the data controller
Under the Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme, notification obligations sit with the data controller regardless of where a breach originated. A mandatory ransomware reporting regime, which commenced on May 30, 2025, under the Cyber Security Act 2024, now also applies to businesses with annual turnovers exceeding $3 million. Non-compliance carries a civil penalty of up to $19,800.
