Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
This page is for businesses and organisations to use. Individuals with privacy complaints should complain to the Privacy Commissioner.
If your agency (business or organisation) has a privacy breach that has (or might) cause serious harm then you need to notify us. This is a legal obligation under the Privacy Act. Ideally you’ll do that within 72 hours after you’re aware that you have a notifiable breach, even if you’re still investigating it.
You also need to tell the people who’ve been affected by your breach as soon as you can (unless an exception applies).
Our notification self-assessment tool will help your agency decide whether you need to notify us or not. It’s intended as a guide, not a final ruling. Agencies are still responsible for making their own assessment (sections 112–117 of the Privacy Act).
At the end of the self-assessment you have the option to go on to complete the NotifyUs report form.
Notify us of your privacy breach |
Update us about your breach |
NotifyUs will step agencies through the report form with guidance at every stage. There are answer choices for most questions. Download a copy of this information as a handy checklist (opens to PDF, 366KB).
Here is what you will be asked:
Contact details for your agency (business or organisation)
Your contact details so we know who we’re working with
Timeline about when the breach occurred
About the breach
Likely harm - you will be asked to indicate how serious the privacy breach is. Cultural perspectives of harm may also be relevant.
Read about ‘What is serious harm?’
Read about ‘What is an adverse consequence or harm?’
For each type of harm you identify, what do you think the impact of the harm will be? Consider cultural perspectives here too.
Depending on the answers to the above questions, you might also be asked:
Notifying affected people
Other organisations or authorities
Have you contacted any organisations (such as CERT, ID Care, Netsafe, or any other) that might be able to provide support to your organisation or people affected by the breach?
Final step and adding documents
As a last step you will be asked to provide any further information you think may be relevant to the breach. There is a free text field and an option to upload supporting documents. Please don’t send us personal information of your customers or clients in these attachments.
While we ask you not to provide us with copies of the information involved in the breach, the breach notification form will collect some personal information (e.g. name and contact details). We collect this information to help us assess the privacy breach and as required by the Privacy Act.
Section 117 of the Privacy Act lists the information that you must provide us when making a privacy breach notification. This includes the details of a contact person within your agency and the identity of any person or body that your agency suspects may be in possession of personal information as a result of the privacy breach (if known). To comply with the requirement that notification must be made as soon as practicable, the information required by section 117 may be provided at a later date. However, failure to provide the information as soon as practicable after notification may result in enforcement action.
If you provide us with someone else’s information, please limit this to only what is necessary for the breach notification, and consider informing them that you have done so (if appropriate).
If you’d like to ask for a copy of your information, or to have it corrected, please contact us.
Please read our privacy statement for more information.
To make sure you can work with us in a free and frank manner, we are bound by a secrecy obligation. Read more about what that means for your agency.
Read more about, ‘What can and can’t you (OPC) share with me?
|
This page is for businesses and organisations to use. Individuals with privacy complaints should complain to the Privacy Commissioner. |