Arabic version: ارتفاع تقارير خروقات البيانات في القطاع العام بكوينزلاند
According to ABC News, Queensland’s Office of the Information Commissioner received 82 data breach notifications from the public sector in the last financial year, up from 53 in 2024-25. The independent regulator also received 353 privacy complaints in 2025-26, more than double the previous year.
The increase came in the first year of Queensland’s mandatory data breach notification scheme, which began in July 2025. Ministers, departments and public authorities must notify the Information Commissioner and affected people when an eligible breach occurs. The obligation was extended to local governments in July this year.
An eligible breach occurs when personal information held by an agency is compromised and is likely to cause serious harm to at least one person. The commissioner’s office said most reported breaches resulted from accidents or human error, with unauthorised disclosures the most common type. Examples can include messages or system notifications sent to the wrong recipient containing unintended personal information.
A small number of notifications involved malicious, intentional unauthorised access, the office said. It cited the major cybersecurity incident involving the Canvas online learning platform, which affected an education technology provider in May. Information Commissioner Joanne Kummrow said the office’s services had reached “unprecedented levels” during the financial year.
Cybersecurity consultant Luke Irwin said breaches remained “massively” under-reported and argued that some organisations choose not to report incidents when they should. He said privacy was still treated as a second thought by many organisations and raised concerns about who assesses potential harm after a breach, particularly where leaked information could endanger victim-survivors of domestic violence.




















