Report a data breach

When an organisation or agency the Privacy Act 1988 covers has reasonable grounds to believe an eligible data breach has occurred, they must promptly notify any individual at risk of serious harm. They must also notify us.

An eligible data breach occurs when the following criteria are met:

If you want to notify us about a data breach involving your own personal information, please make a privacy complaint.

What your notification must include

When you notify us and any affected individuals include:

For more information on notifications, see Data Breach Preparation and Response.

Complete our online form

To notify us of a data breach, you should use our online Notifiable Data Breach form. To see the type of information we need, view this read only training version.

The more information you tell us about the circumstances of the data breach, what you’ve done to contain the data breach and any remedial action you’ve taken, will help us respond to your notification. Remember to attach a copy of your template notification to affected individuals when completing our online Notifiable Data Breach form.

Related pages

Data breach preparation and response

Guide to managing a data breach under the Privacy Act

About the Notifiable Data Breaches scheme

Who must be notified when an eligible data breach occurs