SEE WHAT YOUR ASSESSMENT PRODUCES

Sample assessment report

Fictional, anonymised sample — not a real incident or legal advice. Both the assessment and notification draft require human review before use.

This example uses the same report generator as a saved assessment. The reviewer decision is complete; notification remains outstanding.

NOTIFIABLE BREACH — ASSESSMENT RECORD

Organisation: Example Services Pty Ltd (fictional)
Contact: Privacy officer · privacy@example.com (sample only)
Incident: SAMPLE-001
Revision: 1
Status: complete — sample only
Generated: 2026-09-09T10:06:18.745Z
Rules: NDB decision support · 2026-09-04

INDICATIVE OUTCOME: Potentially notifiable breach
Your answers indicate the core eligible data breach criteria may be met. Obtain urgent qualified review; this tool does not decide whether notification is legally required.

Incident title
Customer identity documents exposed through a shared link

Date grounds for suspicion were identified
2026-09-01

Incident date (if known)
2026-08-31

What happened?
A folder containing customer identity documents was accessible through a public link. Access logs indicate an unknown external party downloaded files before access was revoked. This is a fictional, anonymised example.

Kinds of personal information involved
Names, dates of birth, addresses and identity document images. No real customer records are included in this sample.

Estimated individuals affected
12

Containment actions taken
Disabled the public link, restricted folder permissions and preserved access logs for investigation.

Is the organisation covered by the Australian NDB scheme?
yes

Does this involve personal information?
yes

Was information accessed or disclosed without authorisation, or lost where access or disclosure is likely?
yes

Evidence supporting the scope assessment
For this fictional example, the organisation is assumed to be an APP entity. Logs establish unauthorised access to personal information.

Is serious harm likely for any affected individual?
yes

Serious harm assessment and supporting evidence
Combined identity details and document images could enable identity fraud with serious financial consequences. The unknown recipient downloaded readable copies; revoking access cannot retrieve them.

Has remedial action prevented likely serious harm for ALL affected individuals?
no

Remedial action, timing, and evidence of effectiveness
Further downloads were prevented, but existing copies could not be recovered. Likely serious harm has not been prevented for all affected people.

Recommended protective steps for affected individuals
Contact the issuing authority for advice about exposed identity documents. Monitor accounts for unusual activity and contact your financial institution promptly about suspected fraud. Be alert to targeted phishing and verify unexpected requests independently.

Person responsible for review
Example privacy officer (fictional)

Reviewer decision
notify

Reasons for the reviewer decision
In this example, the reviewer concludes notification is required based on confirmed access and likely serious harm despite containment. Prepare and review the statement and notify the OAIC and affected individuals as soon as practicable.

Notification method and reference
Sample only. No notifications have been sent. Notification dates remain blank.

Prevention and follow-up actions
Review sharing permissions, restrict public links and train staff on handling identity documents.

NEXT STEPS
- If there are reasonable grounds to believe an eligible breach occurred, notify the OAIC and affected individuals as soon as practicable.
- Prepare the notification pack and have it reviewed.
- Do not treat the assessment period as permission to delay notification.

DRAFT NOTIFICATION — REVIEW BEFORE USE
Organisation and contact: Example Services Pty Ltd (fictional); Privacy officer · privacy@example.com (sample only)
Description: A folder containing customer identity documents was accessible through a public link. Access logs indicate an unknown external party downloaded files before access was revoked. This is a fictional, anonymised example.
Information involved: Names, dates of birth, addresses and identity document images. No real customer records are included in this sample.
Recommended individual actions: Contact the issuing authority for advice about exposed identity documents. Monitor accounts for unusual activity and contact your financial institution promptly about suspected fraud. Be alert to targeted phishing and verify unexpected requests independently.

This report is decision support, not legal advice or a notification submission. No notification has been sent by this application. Dates marked notified are user-entered records. Seek qualified advice for jurisdiction, coverage, exceptions and other reporting duties.
Official guidance: https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme
Submit a reviewed notification: https://www.oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach
Start your free initial check