Picture a Friday afternoon. Someone emails you to say a folder of your call recordings turned up where it should not be.
That is the moment most business owners realise they never asked one question. What happens to my call data in a breach, and who reports it?
This is the unglamorous side of running voice agents. It is also the part that decides whether a bad day becomes a fine. So we wrote down exactly how AI voice agent breach notification works on both sides of the Tasman.
You will get the plain version. The NZ Privacy Commissioner's mandatory scheme, the Australian Notifiable Data Breaches scheme, who reports, how fast, and what to ask us before anything goes wrong.
Two countries, two schemes, one duty that stays with you.
What is a notifiable data breach for call data?
A notifiable breach is when personal information is accessed, lost, or disclosed without authorisation and it is likely to cause serious harm. For voice agents that means call recordings, transcripts, and any caller details inside them. Not every glitch qualifies. The serious harm test is the trigger.
Think about what sits in a single answered call. A caller's name, their phone number, maybe a home address, sometimes a medical reason for the call.
That is personal information under both the NZ Privacy Act 2020 and the Australian Privacy Act 1988. So a leak of call data is treated the same as a leak of any other customer record.
The good news is most calls are short. The average answered call runs about 30 seconds, around 40 cents of talk time. Short calls mean less stored per record. But one exposed recording can still cause harm. Volume is not the only thing that matters.
Who can access your call recordings and transcripts?
Access is tightly scoped. Your portal, transcripts, and structured call records live on our Sydney servers. Only your authorised team and the small group inside Waboom AI who run your agent can reach them. The live audio is processed offshore under documented arrangements with our voice infrastructure partner.
So there are two surfaces to think about. The records you log into and review sit in Sydney. The moment of live audio, while a call is actually happening, is handled by our voice infrastructure partner offshore.
We are honest about that split because it changes your risk picture. We never claim all data stays in Australia, because it does not.
If you want the full map of where each piece lives, we wrote a dedicated guide on where your voice agent data is stored across NZ and AU. It walks through every storage point in detail. We also cover how to set a retention window so old recordings auto-delete on a schedule you choose.
Records sit in Sydney; live audio is processed offshore. The split is the point.
What does the NZ mandatory breach scheme require?
If a breach is likely to cause serious harm, you must notify two parties as soon as practicable. The Office of the Privacy Commissioner, and the affected people. This has been mandatory since December 2020. Failing to notify is an offence carrying a fine of up to 10,000 dollars.
The Privacy Commissioner publishes the serious harm factors to weigh. Things like how sensitive the information is, who got hold of it, and whether it was protected.
You report through NotifyUs, the Commissioner's online tool. You do not wait until you have every detail. You notify once you reasonably believe serious harm is likely.
Running agents in New Zealand? Our walkthrough of NZ Privacy Act 2020 compliance for voice agents lays out the wider obligations beyond breach reporting. It pairs well with this piece.
Want the whole security picture in one place?
See how we handle residency, retention, and access on our voice agent security and trust page.
What does the Australian Notifiable Data Breaches scheme require?
Australia's Notifiable Data Breaches scheme sits inside the Privacy Act 1988 and is enforced by the OAIC. If you have reasonable grounds to believe an eligible breach occurred, you must notify the OAIC and affected individuals as soon as practicable. An eligible breach is one likely to result in serious harm.
The scheme connects to the 13 Australian Privacy Principles, the APPs, which govern how Australian organisations handle personal information end to end. A breach is what happens when those principles fail in practice.
There is one extra step Australia adds. If you only suspect an eligible breach, you get up to 30 days to assess whether it actually meets the threshold. That assessment must be reasonable and expeditious, not a stalling tactic.
So the Australian flow is suspect, assess within 30 days, then notify as soon as practicable if it qualifies. New Zealand has no fixed assessment window, which is why you act the moment serious harm looks likely.
How fast must you report, and who reports?
Both countries use as soon as practicable, not a fixed deadline, once serious harm is likely. Australia allows up to 30 days to assess a suspected breach first. You, the business, are the one who must notify. The data is collected under your name. We act as your processor and feed you everything you need to file.
This is the part people get wrong. The regulator holds you accountable, not your technology supplier. Your name is on the privacy collection statement, so the obligation is yours.
Our job is to make your report fast and accurate. We tell you what was affected, when, and which records were involved. Then you file with the OPC or the OAIC.
Speed protects you. The longer a breach sits unreported, the worse it looks to the regulator and to your customers. A clean 48-hour response reads very differently to a six-week silence.
Australia gives you up to 30 days to assess; New Zealand wants notice the moment harm looks likely.
How does honest residency limit your exposure?
Honest residency shrinks your breach surface. Your most sensitive long-term records, the transcripts and structured data, sit on our Sydney servers under your control. Live audio is handled offshore but is not retained the way your records are. Less stored data means fewer records exposed if anything goes wrong.
The biggest lever you control is retention. If a recording is deleted, it cannot leak. We let you set short retention windows, and we can delete a specific record in about 10 minutes on request.
Run the maths on a 200-dial outbound campaign. That is around 100 dollars NZD of calling. The records it creates only stay a risk while you keep them. Tight retention turns a large historical pile into a small rolling window.
We go deeper on this in our guide to zero-retention and secure data for voice agents. It explains how minimising stored audio is the cleanest form of breach protection there is.
What should you ask a vendor before a breach happens?
Ask five questions before you sign, not after a folder of recordings goes missing. Where does each type of data live. How fast can a record be deleted. Who gets notified in a breach and how fast. What documentation backs the offshore processing. And who carries the reporting duty.
Here is the short list we hand new clients.
If a supplier cannot answer the residency question in one sentence, that is your answer. Vague residency means vague accountability. Our broader rundown of voice AI privacy and compliance across NZ and Australia covers the full checklist.
One more thing buyers forget. Every one of our calls discloses that the caller is speaking with an AI. That transparency is not just polite. It reduces the chance a recording becomes a dispute later, which is one less path to a complaint.
The economics still work with all of this in place. A Sydney client produced 141 vendor leads in 90 days at 32.74 dollars per seller. A Christchurch developer booked viewings at 7.12 dollars each. Compliance and performance are not a trade-off. You can see how the records themselves are structured in our note on what lives inside your call data, and how we treat it across the wider Waboom voice agent platform.
Get the residency and reporting story in writing.
Read exactly how we protect your call data on the Waboom AI security page, then ask us the five questions above.
Frequently Asked Questions
Does a single leaked call recording count as a notifiable breach?
It can. If the recording holds personal information and the leak is likely to cause serious harm, it meets the threshold in both countries. A recording with a name, number, and a sensitive reason for the call is exactly the kind of record regulators care about. Volume helps the case but is not required.
Who notifies the regulator, me or Waboom AI?
You do. The data is collected under your business name, so the legal duty to notify the OPC or the OAIC is yours. We act as your processor. Our role is to tell you immediately what was affected and when, so your report to the regulator is fast and accurate.
How long do I have to report a breach in Australia?
Once you have reasonable grounds to believe an eligible breach occurred, you notify as soon as practicable. Only suspect a breach? The Notifiable Data Breaches scheme gives you up to 30 days to assess it. That assessment must be reasonable and prompt.
Is the timeframe different in New Zealand?
Yes. New Zealand has no fixed assessment window. Under the Privacy Act 2020 you notify the Office of the Privacy Commissioner and affected people as soon as practicable once serious harm looks likely. Failing to notify a notifiable breach is an offence with a fine of up to 10,000 dollars.
Can you delete my call recordings to reduce my risk?
Yes. You set a retention window so recordings auto-delete on a schedule you choose. We can also delete a specific record in about 10 minutes on request. Deleted data cannot leak. Short retention is the simplest breach protection you have, and our zero-retention guide covers the setup.
Does HIPAA apply to my New Zealand or Australian business?
No. HIPAA is a United States health privacy law and does not apply to NZ or AU businesses. In New Zealand your obligations come from the Privacy Act 2020 and the OPC. In Australia they come from the Privacy Act 1988, its 13 Australian Privacy Principles, and the OAIC. Those frameworks govern your call data.
Leonardo Garcia-Curtis
Founder & CEO at Waboom AI. Building voice AI agents that convert.
Ready to Build Your AI Voice Agent?
Let's discuss how Waboom AI can help automate your customer conversations.
Book a Free Demo


