My information was part of a privacy breach. What can I do?

Accidental loss or disclosure of personal information is a risk that every agency faces. Privacy principle 5 requires agencies to have safeguards in place to minimise this risk, but it is always present, whether the cause is a malicious third-party, a software error, or a simple staff error. The important thing is that when a privacy breach occurs, the agency concerned takes steps to identify what happened and who is affected and to limit the impact of the privacy breach on individuals.

If you discover your personal information was part of a privacy breach, or you are worried that it might have been, the important thing is to be proactive and take steps to protect yourself and your information.

Here are some suggestions about what you can do.

Contact the agency responsible

Knowing what information is at risk can help you identify passwords that may need to be reset, or prepare for other consequences of your personal information being disclosed, such as risks to your personal safety or the risk of identity theft.

Find out what information has been lost or disclosed, where your information may have ended up, and what steps the agency is taking to resolve the issue. Not all this information may be available immediately, particularly when the agency is investigating the extent and cause of the breach, and the agency may need to report back to you once they have a clear idea about what happened.

Contact our Office

Our Office supports agencies with advice about managing data breaches, and investigates complaints from affected individuals. If you are concerned about the steps being taken by the agency involved, we may be able to help.

You may find it useful to consult our information for agencies about how to manage the breach once it has occurred. Although this is primarily a resource for agencies, it provides some useful information for individuals whose personal information has been disclosed.

Contact other support agencies

If your information was disclosed in a data breach, one possible consequence to you is identity fraud or theft. The identity support service, IDcare,(external link) can provide help and support.

The Department of Internal Affairs(external link) and Police(external link) also have information about what you can do to reduce the chances of identity fraud, and what to do if you become a victim of it. 

Read these related AskUs articles