The Notifiable Data Breaches scheme sounds like something built for large corporations with legal departments, but it applies to businesses of almost any size that hold personal information, which in practice means most small businesses too.
What counts as a breach
It's broader than a dramatic hacking headline. A lost laptop with customer details on it, an email sent to the wrong address containing personal information, or a compromised staff account can all count, if the exposure is likely to cause serious harm.
The rule isn't about being hacked. It's about what happens to people's information when things go wrong.
What you're actually required to do
If a breach is likely to result in serious harm, you're required to notify the Office of the Australian Information Commissioner and the individuals affected, as soon as practicable, explaining what happened and what they can do about it.
The realistic way to prepare
You don't need a formal policy document to handle this well, you need a habit: know roughly what personal data your business holds and where, and have a plan for who to call if something looks wrong, before you need it.
Part of what an audit covers
Understanding what data you hold and how it's protected is a core part of a Sfinco SMB Cyber Audit. See the OAIC's own guidance on the Free Resources page, or book an audit.