Each year, the Office of the Australian Information Commissioner (OAIC) reports on notifiable data breaches received under the Notifiable Data Breaches scheme. The 2025 figures, released on 6 July 2026, show a total the not-for-profit sector cannot easily overlook. The NFP sector saw 1205 breach notifications, an 8% rise in 2024 alone, the highest since the scheme began in 2018. Health and financial services carry the headlines, but the ACNC has now told charities directly that the same pressure applies to them. If you sit on a charity board or hold a Responsible Person role, here is what the record numbers mean for the data you hold.
The OAIC received 1205 notifications in 2025, up 8% on 2024's 1112 figure. 716 of those notifications were attributable to malicious or criminal activity rather than human error. Health service providers were the most commonly affected group, accounting for 225 notifications, 19% of the total. The notifications were spread across multiple different sectors with the top sectors broken down below by volume:
The OAIC's 2026 Community Attitudes to Privacy Survey found 82% of Australians are now concerned about data breaches, up from 74% in 2023. Charities sit outside that top five, but they hold the same donor, beneficiary and staff records that make those sectors a target.
The sector has already had a preview of what a large-scale breach looks like. A cyber-attack on charity telemarketer Pareto Phone exposed donor details linked to dozens of organisations, including Amnesty International, the Australian Conservation Foundation, WWF Australia and Bush Heritage Australia, with some records dating back more than 15 years. Separately, the OAIC accepted an enforceable undertaking from Oxfam Australia after a breach that affected up to 1.7 million records. Both cases point to the same lesson: a breach does not need to start inside your own systems. Fundraising agencies, telemarketers and software vendors are part of your charity's data footprint, and its risk.
In January 2026, the ACNC urged charities to review their cyber security measures for the year ahead, pointing boards to four steps; identify and assess risks, prevent incidents, engage staff and third parties, and take action when concerns arise. This sits alongside Governance Standard 5, which requires Responsible People to act with reasonable care and diligence, act honestly in the charity's best interests, and manage the charity's affairs, including its data, responsibly. Cyber security is no longer a task for whoever manages the charity's IT alone. It is a standing item for the board table.
The ACNC's Governance Toolkit sets out low cost starting points to follow and assist.
None of these needs a large budget or a dedicated security team. It needs a board that has asked the question and can point to a plan.
Record breach numbers are not a reason for alarm. They are a reason for a conversation. Most charity boards are not lacking in care; they are lacking the time to turn general awareness into a documented plan. Reviewing your charity's data practices this year is a meaningful way to protect the trust donors and beneficiaries place in you. If you would like to talk through where your charity's cyber security currently stands, we are happy to have that conversation.
Stay informed on what you can do to protect your organisations from data breaches.