Data Breach Public Notification Register

The Environment Protection Authority (EPA) maintains this register in accordance with section 59P(2) of the Privacy and Personal Information Protection Act 1998 (PPIP Act).

This register contains details of public notifications issued by the EPA in relation to eligible data breaches involving personal information.

Notifications remain available on this register for at least 12 months from the date of publication.

Data breach policy

The EPA's Data Breach Policy outlines our approach to complying with the Mandatory Notification of Data Breach Scheme, including role and responsibilities for:

  • containing, assessing and managing data breaches 
  • notifying and reporting on 'eligible data breaches'.

Public notification register of data breaches

Salesforce Report Litter and Local Litter Check Portal

Date of data breach

Unknown – EPA became aware of the breach on 6 August 2026

Type of breach

Unauthorised disclosure

Description of the breach

An issue with guest user accounts in Salesforce may have made litter reports and user contact details available. 

How the breach occurred

There was an issue with guest user access to the EPA’s Report Litter and Local Litter Check within Salesforce.

Other affected agencies (if applicable)

N/A

Personal information subject of the breach

The personal information included litter reports made by individuals using Report Litter and the contact details of users of the Local Litter Check.

The EPA can confirm sensitive documents such as drivers’ licences and financial information is not captured by the portal.

Time the information was available as a consequence of disclosure, access, or loss

The EPA is unable to determine how long the personal information may have been available prior to its temporary closure on 6 August 2026. The Local Litter Check has been active since 2018 while the Report Litter web app was launched in 2015 and upgraded to its current form in 2021. 

Risk mitigation activities and or planned action to control harm

As soon as we became aware of the incident, the EPA took immediate steps to secure the information and investigate the matter. This included closure of the portals until the security issues had been resolved (between 6 August and 20 August) as well as the implementation of enhanced security testing and improved controls.

Recommended action(s) for affected individuals

Individuals should:

  • Be cautious of unexpected emails, phone calls or text messages seeking personal information
  • Avoid opening links or attachments from unknown or unexpected senders
  • Use strong and unique passwords for online services
  • Enable multi-factor authentication where available
  • Monitor for signs of identity misuse, scams or fraudulent activity
  • Contact ID Support NSW for assistance

Date notification published

28 September 2026

Geospatial server

Date of data breach

29 June 2026

Type and description of the breach

CLM and UPSS spatial datasets were assigned public access permissions.

How the breach occurred

A subfolder containing CLM and UPSS spatial datasets had inadvertently been assigned public access permissions.

Other affected agencies (if applicable)

N/A

Personal information subject of the breach

The personal information involved may have included full names and contact addresses.

Importantly the EPA can confirm that no financial or primary proof-of-identity documents were exposed.

Time the information was available as a consequence of disclosure, access, or loss

April 2021 to 13 July 2026.

Risk mitigation activities and or planned action to control harm

The EPA secured the data on discovery by revoking unauthorised access, strengthened access controls by updating relevant permissions and user privileges, and is contacting affected individuals where possible.

Recommended action(s) for affected individuals

Individuals should:

  • Be cautious of unexpected emails, phone calls or text messages seeking personal information
  • Avoid opening links or attachments from unknown or unexpected senders
  • Use strong and unique passwords for online services
  • Enable multi-factor authentication where available
  • Monitor for signs of identity misuse, scams or fraudulent activity
  • Contact ID Support NSW for assistance

Date notification published

28 August 2026

POEO Register

Date of data breach

28 June 2025

Type and description of the breach

Unauthorised third-party access to the EPA’s POEO public register, which includes non-public documents relating to Dangerous Goods, Radiation and Pesticides licences.

How the breach occurred

Unauthorised third-party access.

Other affected agencies (if applicable)

N/A

Personal information subject of the breach

  • Full name
  • Postal address
  • Contact email address.

We confirm that no financial or primary proof-of-identity documents, such as driver’s licence numbers were exposed.

Time the information was available as a consequence of disclosure, access, or loss

Between 2015 and February 2026.

Risk mitigation activities and or planned action to control harm

Took the POEO Register offline to undertake a comprehensive security check.

Notified Cyber Security NSW and the NSW Privacy Commissioner that we believe Dangerous Goods, Radiation and Pesticides licence documents, dated between 1 January 2011 and 13 November 2024, have been accessed without permission.

Recommended action(s) for affected individuals

Individuals should:

  • Be cautious of unexpected emails, phone calls or text messages seeking personal information
  • Avoid opening links or attachments from unknown or unexpected senders
  • Use strong and unique passwords for online services
  • Enable multi-factor authentication where available
  • Monitor for signs of identity misuse, scams or fraudulent activity
  • Contact ID Support NSW for assistance.

Date notification published

13 May 2026

Get help or make a complaint

ID Support

ID Support NSW offers assistance for individuals dealing with data breaches and information compromise.

To contact ID Support NSW:

  • visit ID Support NSW 
  • phone 1800 001 040, Monday to Friday 9 am to 5 pm, excluding public holidays. Interpreter services are available.

NSW Environment Protection Authority

To contact us:

Submit a privacy complaint

If you were impacted by a breach, you can submit a privacy complaint to the EPA regarding this incident to [email protected]