Australia's first civil penalty under the Privacy Act came to $5.8 million, and $1.6 million of it had nothing to do with the attack. On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $4.2 million for failing to take reasonable steps to protect personal information, $800,000 for failing to carry out a reasonable and expeditious assessment of the suspected breach, and $800,000 for failing to give the Information Commissioner a statement as soon as practicable. inSUPPORT designs incident response during onboarding rather than on the day, and that second figure is the reason why.
For a board or a finance portfolio, the first instinct on reading a number like that is to ask whether the security budget is big enough. It is a fair question, and it is not quite the one this judgment answers. The court did not penalise a company for being attacked. It penalised a company for what it did before the attack, and separately for what it did afterwards. Those are two different problems, and only one of them is about spending.
TL;DR: What to remember
- ✅ The Federal Court made one aggregate $5.8 million civil penalty order against Australian Clinical Labs on 8 October 2025, the first in the history of the Privacy Act, with a separate $400,000 costs order on top.
- ✅ The penalty was for conduct, not for being a victim. Suffering an attack is not a contravention. Failing to protect the information, failing to assess the breach expeditiously and failing to notify the Commissioner in time each is.
- ✅ $1.6 million of the total was for what happened after the incident, the assessment and the notification, not the security posture that came before it.
- ✅ The affected systems arrived through the Medlab acquisition in December 2021 and had not been integrated into the company's core environment when the attack landed in February 2022.
Contents
- How the $5.8 million breaks down
- The second $1.6 million was about conduct, not security
- What the case says an organisation should be able to do
- Straight answers on the Clinical Labs case
How the $5.8 million breaks down
The headline number puts one security failure and two process failures under a single total, so the useful information is in the components, not the sum. The Court made one aggregate civil penalty order of $5.8 million, comprising three penalty components for three different kinds of contravention. It is one order, not three, and the split matters because the three failures are not the same failure. The full judgment is Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, and it repays reading in the original. Reviewed August 2026.
| Amount | What it related to |
|---|---|
| $4,200,000 | Failing to take reasonable steps to protect personal information, Australian Privacy Principle 11.1, across more than 223,000 contraventions |
| $800,000 | Failing to carry out a reasonable and expeditious assessment of whether an eligible data breach had occurred |
| $800,000 | Failing to prepare and give the Information Commissioner a statement about the eligible data breach as soon as practicable |
| $5,800,000 | Aggregate civil penalty ordered by the Federal Court, 8 October 2025 |
| $400,000 | Ordered separately as a contribution to the Commissioner's costs, on top of the civil penalty |
The attack occurred in February 2022 and affected the personal information of more than 223,000 individuals. It landed on Medlab Pathology's IT systems, which Australian Clinical Labs had acquired in December 2021 and which had not at that point been integrated into ACL's core IT environment. Senior management were involved in the decisions around that integration.
That is the detail with the widest reach. The compromised systems came into the business through an acquisition and had not yet been brought inside the environment the company already ran and maintained. A recent purchase, a set of systems still sitting outside the fold, a plan to integrate them later: for anyone who has bought a business or is about to, that sequence is a familiar one.
The second $1.6 million was about conduct, not security
The $1.6 million is the part of this judgment that should change how a board thinks about readiness. It is entirely about the days and weeks that followed the incident, not the security posture that preceded it. A company can spend well on protection and still land squarely inside this figure, because the two failures behind it are not spending failures.
Two duties sit behind that $1.6 million. Under the Notifiable Data Breaches scheme, an entity that has reasonable grounds to suspect an eligible data breach must take all reasonable steps to complete an assessment within 30 calendar days of becoming aware of the grounds for that suspicion. Once it forms the reasonable belief that an eligible data breach has occurred, it must prepare a statement and give a copy to the Commissioner as soon as practicable. The OAIC sets both of those out in its own quick reference guide for responding to data breaches. Both duties apply to entities covered by the scheme, and each is triggered by its own statutory threshold rather than by the incident alone.
Good intentions and a busy month do not discharge either duty. They are conduct obligations with a clock attached, and the court treated the failure to meet them as separately penalisable from the failure to protect the data in the first place. Where those thresholds are met, weak investigation capability can produce an assessment contravention in its own right, and it can push the notification late as well. One thin capability, two separate exposures.
The regulator's own framing of the orders emphasised deterrence, and pointed at expeditious investigation as the specific conduct it wants to see. That is a statement about capability, not about the size of a budget.
What the case says an organisation should be able to do
The judgment does not prescribe an incident response method, and it should not be read as though it does. Set it beside the regulator's own guidance, though, and the shape of a workable one is clear enough. The OAIC describes four steps: contain the breach, assess it by gathering the facts and evaluating the risks, notify individuals and the Commissioner where required, and review. Doing all four properly means being able to preserve what happened, get critical services back in an order that reflects business priority, and meet the statutory obligations, all at once and under pressure.
Those three things pull against each other in practice, which is why they are better decided before an incident than during one. The instinct in the first hour is to restore, and a poorly controlled recovery can overwrite or alter the evidence an assessment depends on. Working out the order of operations while the phones are ringing is how a slow assessment and a late notification become likely.
inSUPPORT sets incident response during onboarding for exactly this reason: preserve the evidence, restore critical services in business priority order, and report to the authorities inside the statutory timeframes. That sits inside its wider methodology, The 6 Step Cyber Strength System, rather than being a document produced at the end of a project, and the same sequence applies whether the environment is one a business built or one it inherited through an acquisition. The managed IT services model carries it forward as an ongoing obligation rather than a one-off deliverable.
For a board that wants to test its own position against this case, four checks do most of the work.
- Confirm who is accountable for deciding that an assessment has formally started, and how that decision is recorded.
- Confirm the organisation can produce the evidence an assessment needs without destroying it during recovery.
- Confirm someone can draft and lodge a statement to the Commissioner, and knows where the form is.
- Confirm the same holds on a weekend, because the 30 days are calendar days.
Straight answers on the Clinical Labs case
Q: Was Australian Clinical Labs penalised for being hacked?
A: No, and this is the most important distinction in the case. Suffering a cyber attack is not itself a contravention of the Privacy Act. The three components were for failing to take reasonable steps to protect personal information under APP 11.1, for failing to carry out a reasonable and expeditious assessment of the suspected breach, and for failing to give the Commissioner a statement as soon as practicable. Every one of those describes conduct rather than victimhood, which is precisely why the judgment is useful: conduct is something an organisation can prepare for in advance.
Q: Does an organisation need outside help to meet these obligations?
A: Not necessarily, but the work does need an owner. Where the Notifiable Data Breaches scheme covers an entity, its obligations under the scheme cannot be contracted away to a provider, so the question is not who is liable but who is capable. If nobody internally can preserve forensic evidence, work out what data was actually accessed and draft a statement to the Commissioner inside the timeframes, that capability has to come from somewhere. Legal advice on the notification decision itself should come from a lawyer.
Q: How quickly does the assessment clock actually run?
A: The OAIC's guidance is that an entity must take all reasonable steps to complete an assessment within 30 calendar days after the day it becomes aware of the grounds that caused it to suspect an eligible data breach. The notification duty is expressed differently: once the entity forms the reasonable belief that an eligible data breach has occurred, it must give the Commissioner a statement as soon as practicable. Thirty days is the outer boundary on the assessment, not a target to aim at.
Q: Where should a board start with this?
A: Start by finding out whether the capability exists, rather than whether the policy exists. Ask to see the incident response sequence, ask who holds each role, and ask when it was last exercised. If an acquisition has happened, ask specifically what was audited in the inherited environment and when. inSUPPORT runs that examination as a Cyber Strength Audit, which documents the current state and returns a plain English risk assessment ranked by business impact along with an audit trail that stands up in front of a board or an insurer.
The gap this judgment exposes is rarely a gap in intent. It is the distance between an incident response plan that exists and one that has been decided, documented and rehearsed by the people who would have to run it at two in the morning. Across more than 1,500 cyber audits for Australian businesses, one finding keeps recurring: the plan exists as a document and has never been walked through by the people who would have to use it. Kane Nawrocki has spent more than 25 years in IT watching that gap close only when someone tests it. A Cyber Strength Audit documents where an environment actually stands, examines identity and access, patching, backup and recovery, email and endpoint security and configuration drift, and returns a costed path to closing the gaps it finds. If an environment came in through an acquisition, that is the right place to start. We do not run an audit, hand over a report and disappear.
Book a Cyber Strength Audit →Citations
- Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach, in a first for the Privacy Act, Office of the Australian Information Commissioner. The regulator's account of the Federal Court orders of 8 October 2025: $5.8 million in total, split $4.2 million, $800,000 and $800,000 across the three contraventions, affecting more than 223,000 individuals. oaic.gov.au
- Quick reference guide for responding to data breaches, Office of the Australian Information Commissioner. Sets out the contain, assess, notify and review sequence, the requirement to take all reasonable steps to complete an assessment within 30 calendar days, and the duty to give the Commissioner a statement as soon as practicable. Dated 29 June 2026. oaic.gov.au
- Notifiable Data Breach statistics, January to June 2025, Office of the Australian Information Commissioner. Records 532 notifications in the period, with malicious or criminal attack accounting for 308 notifications, or 59 per cent, human error 193 notifications, or 37 per cent, and health the most affected sector at 18 per cent. Published 4 November 2025, and the most recent narrative statistics the OAIC had published at the time of writing. oaic.gov.au
Related Reading
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


