Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
This self-assessment does not ask for any information that identifies you or your organisation. No information you enter is sent to us unless at the end of the self-assessment, you elect to go on to submit a privacy breach notification to us. Nothing you enter in this self-assessment or go on to submit to us is stored on our website.
It is important to note that this self-assessment tool is only a guide. Every breach is different and we are not limited to the self-assessment result when assessing if any decision not to notify us was reasonable in the circumstances.
If you are unsure which answer value to choose when you complete the self-assessment, we encourage you to err on the side of caution.
This self-assessment is to help organisations that have a data breach that involves personal information to work out if the breach is likely to cause serious harm and therefore if they are legally required to notify us and any affected persons. As you have indicated that this isn’t applicable to you, you do not need to continue.
This self-assessment has 6 questions and should take no more than 5 minutes.
Based on your responses at this time, your organisation’s privacy breach looks unlikely to cause serious harm to any affected persons.
Please note the self-assessment result is a guide to assist you. Every breach is different and the Office of the Privacy Commissioner is not limited to the self-assessment result when assessing if your decision not to notify us was reasonable in the circumstances.
You can contact us at notifyus@privacy.org.nz or 0800 803 909 if you are still uncertain.
We encourage you to report to us whether or not you have to. If you report a breach to us that may be unlikely to cause serious harm, we will use the information to inform how we can better assist organisations with their privacy obligations.
If you choose to report
Based on your responses, your organisation's privacy breach looks likely to cause serious harm to affected persons. Under the Privacy Act 2020, you are legally required to report a privacy breach to us and notify any affected persons if it is likely to cause serious harm. Not reporting to us a privacy breach that may cause serious harm is an offence and may result in a fine of up to $10,000.
We encourage you to report to us ahead of the legislation taking effect on 1 December 2020. We may be able to provide you with support and advice. You can also check out our online guidance on privacy breaches and how to respond to them.
Report this notifiable privacy breach to us now
If you would like to retain a copy of this evaluation, you can print it directly from this page.
If you think some of your answers were not quite correct, you can start the assessment again.
Please review your responses before you submit your update. You will be able to print a copy of your update after you submit it.