Home / Resources / Data Breach Cost Estimator
Free interactive tool

Data Breach Impact
Calculator.

Prepare · Protect · Perform

Get an indicative estimate of what a data breach could cost your organisation, and check whether it would trigger notification obligations under Australia's Notifiable Data Breaches scheme.

Quick answer: A data breach impact calculator estimates what a breach could cost your organisation by modelling notification, investigation, legal and recovery costs. Use it to size your exposure and plan your response before an incident happens.
Padlock resting on a keyboard, representing a data breach impact calculator and data security risk
Know your exposure
COST · RISK · NDBS OBLIGATIONS
The Estimator

Get your indicative estimate.

Enter a few details about your organisation and the incident to see a rough cost range and notification guidance.

Estimated cost per record –
Records affected –
Estimated total exposure –
At this scale, this incident would likely require notification to affected individuals and the OAIC under the Notifiable Data Breaches scheme.
Based on scale alone, this may fall below typical notification thresholds — but every case should still be individually assessed.

This is a rough, indicative estimate for planning purposes only — not a substitute for a formal breach impact assessment or legal advice. Actual costs vary widely by circumstance.

Why It Matters

Understanding breach exposure.

Cost isn't just remediation — it spans notification, regulatory, and reputational impact.

Notification Costs

Direct costs of notifying affected individuals and regulators, including legal review and communications.

Regulatory Exposure

Potential OAIC involvement, investigation costs, and compliance obligations under the Privacy Act.

Customer Trust

The longer-term cost of churn and reputational damage that follows a mishandled breach response.

Guide

How a data breach impact calculator helps

A data breach impact calculator gives you an indicative figure for what a breach could cost, based on the scenario and the response effort required. It is a planning tool, not a quote, but it helps leadership see the exposure before an incident happens.

What costs does the estimate include?

  • Detection and investigation
  • Notification of affected individuals and the regulator
  • Legal, regulatory and forensic costs
  • Remediation, credit monitoring and system recovery
  • Lost business and reputational damage

Notifiable data breaches in Australia

Under the Notifiable Data Breaches scheme in the Privacy Act, organisations covered by the Act must notify the OAIC and affected individuals when an eligible data breach is likely to result in serious harm. If you only suspect a breach, you must assess it within 30 days. Serious or repeated privacy breaches can attract penalties of up to the greater of A$50 million, three times the value of any benefit obtained, or 30% of adjusted turnover. See the OAIC's Notifiable Data Breaches guidance.

FAQ

Data breach impact calculator questions

How does the data breach impact calculator work?

You describe a breach scenario and the tool returns an indicative cost range, so you can see the size of your exposure. It relies on general assumptions, so treat the result as a planning starting point rather than a forecast.

What is a notifiable data breach?

An eligible data breach involves unauthorised access to, or disclosure or loss of, personal information that is likely to result in serious harm to one or more individuals, where remedial action has not prevented that harm. Organisations covered by the Privacy Act must notify the OAIC and the affected individuals.

How accurate is a data breach impact calculator?

It gives an indicative estimate only. Real costs vary widely with the type of data involved, the size of your organisation and how quickly you respond. A tested incident response plan is the most reliable way to keep the real cost down.

How long do you have to report a data breach in Australia?

Under the Notifiable Data Breaches scheme, if you suspect an eligible data breach you must assess it within 30 days. If it is an eligible data breach, you must notify the OAIC and the affected individuals as soon as practicable.