Yes. A lost, stolen or un-wiped device that held personal information can be a notifiable data breach, with the same obligations to notify as a cyber attack. The Notifiable Data Breaches scheme is usually associated with hackers, but a retired laptop that leaves your control with its data intact fits the definition just as well. This guide explains how disposal causes breaches, and how to make sure yours does not.
Yes. Under the Notifiable Data Breaches scheme, an organisation covered by the Privacy Act must notify affected individuals and the OAIC when there is unauthorised access to, or loss of, personal information that is likely to result in serious harm. A device retired without its data destroyed, then lost, stolen, sold on or simply unaccounted for, is exactly that: a loss of personal information that could cause serious harm. The scheme does not distinguish between a hacker exfiltrating data and a hard drive walking out the door with it intact; both are unauthorised access or loss. So improper disposal is not a lesser risk than a cyber incident, it is another route to the same notifiable breach. The way to keep disposal out of the breach column is to destroy the data to a recognised standard and hold a certificate proving it, which is what a certified data destruction process delivers.
The mental model most businesses carry is that data breaches come from outside: phishing, ransomware, a hacked server. That is where most attention goes, and it should get a lot. But the same personal information sits on every device you retire, and when a business hardens its network while treating disposal as a facilities chore, it leaves a door open at the end of the asset life that is just as capable of causing a notifiable breach. This guide connects the disposal you may not think of as a security event to the breach scheme you already take seriously.
A notifiable breach needs three things to line up. A badly handled disposal supplies all three with ease.
The Notifiable Data Breaches scheme is triggered when there is unauthorised access to or unauthorised disclosure of personal information, or a loss of it, that a reasonable person would conclude is likely to result in serious harm to the individuals concerned, and the harm cannot be prevented through remedial action. Map that onto disposal and the fit is uncomfortable. A retired laptop, server or photocopier holds personal information. If it is sold, gifted, dropped at a recycler without the data destroyed, or simply goes missing from a store room, that information has been lost or disclosed without authorisation. And where it includes the kinds of records that enable identity theft or fraud, financial details, health information, identity documents, serious harm is a realistic outcome. Three ingredients, all present. The disposal did not feel like a security event, but by the definition that matters, it was one.
The point where this most often bites is the assumption that a device was cleared when it was not. A factory reset that left data recoverable, a wipe that failed silently on an SSD, a copier returned with its drive intact: in each case the organisation believed the data was gone and it was not, so the loss of the device became a loss of the data. This is why the evidence, not just the intention, matters. Being able to show that a specific device was destroyed to a recognised standard is what lets you say, if that device is later lost, that there was no personal information on it to breach.
The scheme allows that a breach need not be notified if remedial action prevents the likely serious harm. Certified destruction is the ultimate remedial action taken in advance: if a lost device's data was already destroyed and you hold the certificate, there is no personal information to be accessed, and therefore no notifiable breach from that device. Proper disposal does not just reduce the chance of a breach; it removes the device from the equation entirely.
Breaches are at a high level, and human error, exactly the category careless disposal falls into, is a growing share. Figures from a named source.
The Office of the Australian Information Commissioner reported 532 notifiable data breaches in the first half of 2025, and while cyber attacks remain the largest single cause, breaches attributed to human error rose to 37% of the total, up from 29% in the previous period. Careless disposal, a device lost, an un-wiped drive sold on, a copier returned with its data intact, is a human-error breach in exactly this sense: not malicious, just a control that was not applied. That it is preventable is precisely why it is worth preventing, and against a maximum penalty of $50M or more, plus the notification obligations and reputational cost a breach brings, the certified destruction that removes the risk is trivially cheap. You can read the current breach statistics and the scheme itself on the OAIC website.
Four practices turn end-of-life IT from a breach waiting to happen into a documented non-event.
Assume any device that touched personal information still holds it until proven otherwise, including the ones easy to forget: servers, backups, photocopiers, phones and networking gear.
Certified wiping to a standard such as NIST 800-88, or physical destruction where a drive cannot be verifiably wiped, matched to the media, so the data is genuinely unrecoverable rather than apparently gone.
A documented chain of custody, so a device is never lost in the window between leaving your control and being destroyed, which is a loss the scheme would count.
A certificate for each device is your evidence that the data was destroyed. If a device is ever lost afterwards, the certificate shows there was nothing on it to breach.
Route every retired device through the same certified process, rather than letting some be handled informally by different teams. Most disposal breaches happen to the device that fell outside the process: the laptop a manager took home, the copier facilities returned, the server a project decommissioned quietly. One accountable process, covering everything, is what closes those gaps.
The questions businesses ask most about disposal and the breach scheme.
It can be. If the device held personal information that was not destroyed, and it is lost, stolen or disclosed in a way likely to result in serious harm that cannot be prevented by remedial action, it meets the definition of a notifiable data breach, and the organisation must notify affected individuals and the OAIC. The scheme does not treat a lost device differently from a cyber incident; both are unauthorised access or loss of personal information.
The belief does not help if the data was in fact recoverable. A factory reset that left data behind, or a wipe that failed silently on an SSD, means the device still held personal information, so its loss is still a loss of that information. This is why evidence matters more than intention: a certificate showing the device was destroyed to a recognised standard is what lets you demonstrate there was no data to breach.
It removes the device from the equation. The scheme allows that a breach need not be notified where remedial action prevents the likely serious harm. If a device's data was already destroyed to a recognised standard and you hold the certificate, a later loss of that device exposes no personal information, so there is no notifiable breach from it. Certified destruction is remedial action taken in advance.
The ones outside the usual IT process: photocopiers and multifunction devices with internal drives, servers and backups decommissioned by a project team, laptops taken home by departing staff, and networking gear retired during an upgrade. Disposal breaches tend to happen to the device that fell outside the process, which is why routing everything through one certified process is the reliable fix.
The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act, which includes most businesses handling personal information above the small-business threshold, along with health service providers and others regardless of size. If your business is subject to the Privacy Act, the scheme applies to a loss of personal information through disposal just as it does to a cyber incident. If you are unsure of your status, the OAIC provides guidance.
With the destruction certificate and chain-of-custody record for that device. Together they show the data was destroyed to a recognised standard and the device was accounted for, so if it is later lost there was no recoverable personal information on it. That documentation is the difference between a defensible position and a notification, which is why keeping the certificates matters as much as doing the destruction.
See how ITC destroys the data on every retired device to a recognised standard, tracks each one to destruction, and certifies it, so a lost device is a documented non-event rather than a notifiable breach.
Evidence for your auditor
Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.