Industry News

Queensland Public Sector Data Breach Reports Climb as Mandatory Notification Begins

ABC News · 6 Oct 2026
Key Takeaway Most breaches stem from simple human error, so train staff to double-check recipients and attachments before sending personal information, and know your notification obligations before an incident happens.

Queensland's Office of the Information Commissioner received 82 data breach notifications from the public sector last financial year, compared with 53 the year before. The regulator also received 353 privacy complaints, more than double the previous year. Information Commissioner Joanne Kummrow wrote in the annual report that its services had "reached unprecedented levels". It was the first year of a mandatory notification scheme that began in July 2025. Before that, notifications were voluntary.

A spokesperson for the office said most breaches were caused by accident or human error, and most involved unauthorised disclosure. Examples include a misdirected email, text message or system notification sent to the wrong person, or one that included personal information by mistake. Some breaches were deemed malicious and intentional. The office pointed to the major cybersecurity incident involving the online learning platform Canvas, which affected an education technology provider in May.

Under the scheme, ministers, departments and public authorities must notify the Commissioner and affected individuals of an eligible data breach. That means personal information was compromised and is likely to cause serious harm to at least one person. The obligation was extended to local governments in July this year. Cybersecurity consultant Luke Irwin said breaches are still "massively" under-reported, and that in some cases organisations are choosing not to report when they should.

data breach Queensland privacy human error notification scheme

Summarised by CISO AI from ABC News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.