Priya Sharma
CTO
The Notifiable Data Breaches scheme sets hard timelines and disclosure obligations that most cloud architectures aren't built to meet by default. Here's what data sovereignty and breach-readiness actually require at the infrastructure level.
The Notifiable Data Breaches (NDB) scheme, in force since 2018 and increasingly enforced since, requires organisations covered by the Privacy Act to notify affected individuals and the OAIC when a data breach is likely to result in serious harm — and to do it 'as soon as practicable.' On paper, that sounds like a legal and process problem. In practice, it's an architecture problem, because you can't assess or report a breach quickly if your systems can't tell you what data was exposed, when, and to whom.
A common misconception is that choosing an Australian cloud region solves data sovereignty. It solves data residency — where bytes physically sit — but sovereignty is broader: it also covers who can compel access to that data (including under foreign legal jurisdictions like the US CLOUD Act, which can reach data held by US-headquartered providers regardless of region), and who operationally administers the systems that hold it.
Under the NDB scheme, once you're aware of reasonable grounds to suspect an eligible data breach, you generally have 30 days to complete an assessment — but 'as soon as practicable' notification expectations mean organisations that take the full 30 days without good reason draw regulatory scrutiny. The architectures that meet this comfortably are the ones that can answer three questions quickly, because the system was built to answer them, not because someone manually reconstructs logs under pressure.
“The NDB scheme rewards architectures that can answer 'what happened and to whom' in hours, not weeks. That capability has to be designed in — it isn't something you can buy off the shelf after an incident starts.”
— Priya Sharma, CTO, Alliance Corporation
Alliance Corporation designs cloud architectures and data governance frameworks built for Australian data sovereignty and NDB-scheme readiness. Talk to our Cloud & Security team about a breach-readiness assessment.
Priya Sharma
CTO · Alliance Corporation
Part of the Alliance Corporation leadership team, shaping technology strategy across AI, cloud and enterprise software for clients in 50+ countries.