Section 26WAPrivacy Act 1988 (Cth)

Guide to this Part

• This Part sets up a scheme for notification of eligible data breaches.

• An eligible data breach happens if:

(a) there is unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity; and

(b) the access, disclosure or loss is likely to result in serious harm to any of the individuals to whom the information relates.

• An entity must give a notification if:

(a) it has reasonable grounds to believe that an eligible data breach has happened; or

(b) it is directed to do so by the Commissioner.

• The Commissioner may obtain information or documents in relation to actual or suspected eligible data breaches.

• This Part also deals with the collection, use and disclosure of personal information involved in eligible data breaches.

Sourced from the Federal Register of Legislation at 17 May 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au. Verify the current text against the official source before relying on it.

Related sections

Research how courts apply s 26WA

BriefBridge searches Australian caselaw by meaning — every answer cited to the paragraph.

Try BriefBridge free