Communities and Justice

Mandatory data breach notification

The Department of Communities and Justice and the Department of Customer Service are determining whether a mandatory reporting scheme for data breaches should be adopted under the Privacy and Personal Information Protection Act 1998. The Department of Communities and Justice published a discussion paper in July 2019 and invited submissions from the public.

What’s this about?

The Privacy and Personal Information Protection Act 1998 governs how NSW public sector agencies manage personal information. 

The Department of Communities and Justice is seeking feedback on:

  • Whether a mandatory reporting scheme for data breaches by NSW public sector agencies should be implemented in NSW
  • If a mandatory reporting scheme is implemented in NSW, how the scheme should operate.

The Mandatory Notification of Data Breaches by NSW Public Sector Agencies Discussion Paper (DOC, 367.5 KB) includes specific questions for consideration.

Submissions

Submissions closed on 23 August 2019. We received 23 submissions in response to our Discussion paper.


Last updated:

16 Jun 2023