Information security and privacy incident notification form
What you should know before using this form
Any organisation that is subject to the Privacy and Data Protection Act 2014 (Vic) (PDP Act) can use this form to report incidents to OVIC, whether voluntarily or by obligation.
- This form should not be used by members of the public to report incidents, data breaches or alleged wrongdoing by VPS employees or organisations to OVIC.
- Individuals wishing to do so, should instead use OVIC's Privacy Complaint Form.
Organisations that are subject to:
- Part 4 of the PDP Act and the Victorian Protective Data Security Standards (VPDSS) should notify OVIC of certain information security incidents, and
- Part 3 of the PDP Act are encouraged to notify OVIC of incidents involving personal information that could cause harm to affected individuals.
How will the information I provide be used?
We use the information you provide to help us manage information security and privacy incident notifications. This includes confirming that we received your notification and contacting you to discuss the incident if we need to.
We may also send your information to the Victorian Government Cyber Incident Response Service, if you want us to.
Collection of personal information
The incident notification form collects personal information including:
- your name
- position title
- organisation
- contact number, and
- email address for the purpose of follow up, research projects or activities set out in OVIC’s Regulatory Action Policy.
Where you provide personal information, OVIC may use it to provide you with return confirmation of receipt of your form, seek clarification on the contents of your form or report on any trends. If you do not provide the information requested in this form, it may limit OVIC’s ability to follow up with you. When submitting your form via email, we may be able to identify you from your email address.
OVIC will not disclose your personal information without your consent (e.g. where you request assistance from the Victorian Government Cyber Incident Response Service), except where required or authorised to do so by law. OVIC does publish de-identified information (or aggregated data) in our monitoring and assurance reports. OVIC does publish de-identified information (or aggregated data) in our monitoring and assurance reports.
You may contact OVIC to request access to any personal information you have provided to us by emailing enquiries@ovic.vic.gov.au.
For further information on how OVIC handles personal information, please review our privacy policy.
Important! Do not include the personal information of any employees or individuals involved in, or impacted by, the incident. The only personal information requested is that of the organisation’s nominated contact representative which should be noted in the designated fields on this form.
Information you enter onto this form is stored locally, in your browser, until you submit it. If you do not submit the form, the information you enter will stay stored locally in your browser until you clear the browser cache or delete any information you entered onto the form.
You may also clear the form and start again by using the "reset this form" button.