Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
If your agency (business or organisation) has a privacy breach that has (or might) cause serious harm then you need to notify us. This is a legal obligation under the Privacy Act. Ideally you’ll do that within 72 hours after you’re aware that you have a notifiable breach, even if you’re still investigating it.
You also need to tell the people who’ve been affected by your breach as soon as you can (unless an exception applies).
Our notification self-assessment tool will help your agency decide whether you need to notify us or not. It’s intended as a guide, not a final ruling. Agencies are still responsible for making their own assessment (sections 112–117 of the Privacy Act).
At the end of the self-assessment you have the option to go on to complete the NotifyUs report form.
Notify us of your privacy breach |
Update us about your breach |
NotifyUs will step agencies through the report form with guidance at every stage. There are answer choices for most questions. Download a copy of this information as a handy checklist (opens to PDF, 366KB).
Here is what you will be asked:
Contact details for your agency (business or organisation)
Your contact details so we know who we’re working with
Timeline about when the breach occurred
About the breach
Likely harm - you will be asked to indicate how serious the privacy breach is. Cultural perspectives of harm may also be relevant.
Read about ‘What is serious harm?’
Read about ‘What is an adverse consequence or harm?’
For each type of harm you identify, what do you think the impact of the harm will be? Consider cultural perspectives here too.
Depending on the answers to the above questions, you might also be asked:
Notifying affected people
Other organisations or authorities
Have you contacted any organisations (such as CERT, ID Care, Netsafe, or any other) that might be able to provide support to your organisation or people affected by the breach?
Final step and adding documents
As a last step you will be asked to provide any further information you think may be relevant to the breach. There is a free text field and an option to upload supporting documents. Please don’t send us personal information of your customers or clients in these attachments.
To make sure you can work with us in a free and frank manner, we are bound by a secrecy obligation. Read more about what that means for your agency.
Read more about, ‘What can and can’t you (OPC) share with me?
This page is for businesses and organisations to use. Individuals with privacy complaints should complain to the Privacy Commissioner.