Queensland's Office of the Information Commissioner says it received 50 mandatory data-breach notifications during 2025–26, the first year of the state's notification scheme for most public-sector agencies.

The figure appears in the watchdog's annual report, tabled on 28 September, which also says its teams handled a record number of information-access and privacy matters and responded to 5,512 enquiries. The 50 figure counts notifications received by the regulator; it is not a count of people affected, nor does it show that every incident had the same cause or severity.

The mandatory scheme began for state public-sector agencies on 1 July 2025 and extended to local councils on 1 July 2026. Under the rules, eligible breaches involving personal information must be reported to affected people and the commissioner, subject to applicable exemptions.

The first-year total cannot be read as a like-for-like measure of whether breaches are increasing: the reporting obligation itself changed. Queenslanders concerned that a particular agency has exposed their information should look for that agency's notice and the commissioner's guidance on notification and support.

Sources: Office of the Information Commissioner annual-report summary, 28 September 2026; OIC scheme guidance.

Illustration disclosure: The featured image is an AI-generated concept representing data privacy. It is not a screenshot, a real government system or evidence of any specific breach.