SEE WHAT YOUR ASSESSMENT PRODUCES
Sample assessment report
Fictional, anonymised sample — not a real incident or legal advice. Both the assessment and notification draft require human review before use.
This example uses the same report generator as a saved assessment. The reviewer decision is complete; notification remains outstanding.
NOTIFIABLE BREACH — ASSESSMENT RECORD Organisation: Example Services Pty Ltd (fictional) Contact: Privacy officer · privacy@example.com (sample only) Incident: SAMPLE-001 Revision: 1 Status: complete — sample only Generated: 2026-09-09T10:22:01.607Z Rules: NDB decision support · 2026-09-04 INDICATIVE OUTCOME: Potentially notifiable breach Your answers indicate the core eligible data breach criteria may be met. Obtain urgent qualified review; this tool does not decide whether notification is legally required. Incident title Customer identity documents exposed through a shared link Date grounds for suspicion were identified 2026-09-01 Incident date (if known) 2026-08-31 What happened? A folder containing customer identity documents was accessible through a public link. Access logs indicate an unknown external party downloaded files before access was revoked. This is a fictional, anonymised example. Kinds of personal information involved Names, dates of birth, addresses and identity document images. No real customer records are included in this sample. Estimated individuals affected 12 Containment actions taken Disabled the public link, restricted folder permissions and preserved access logs for investigation. Is the organisation covered by the Australian NDB scheme? yes Does this involve personal information? yes Was information accessed or disclosed without authorisation, or lost where access or disclosure is likely? yes Evidence supporting the scope assessment For this fictional example, the organisation is assumed to be an APP entity. Logs establish unauthorised access to personal information. Is serious harm likely for any affected individual? yes Serious harm assessment and supporting evidence Combined identity details and document images could enable identity fraud with serious financial consequences. The unknown recipient downloaded readable copies; revoking access cannot retrieve them. Has remedial action prevented likely serious harm for ALL affected individuals? no Remedial action, timing, and evidence of effectiveness Further downloads were prevented, but existing copies could not be recovered. Likely serious harm has not been prevented for all affected people. Recommended protective steps for affected individuals Contact the issuing authority for advice about exposed identity documents. Monitor accounts for unusual activity and contact your financial institution promptly about suspected fraud. Be alert to targeted phishing and verify unexpected requests independently. Person responsible for review Example privacy officer (fictional) Reviewer decision notify Reasons for the reviewer decision In this example, the reviewer concludes notification is required based on confirmed access and likely serious harm despite containment. Prepare and review the statement and notify the OAIC and affected individuals as soon as practicable. Notification method and reference Sample only. No notifications have been sent. Notification dates remain blank. Prevention and follow-up actions Review sharing permissions, restrict public links and train staff on handling identity documents. NEXT STEPS - If there are reasonable grounds to believe an eligible breach occurred, notify the OAIC and affected individuals as soon as practicable. - Prepare the notification pack and have it reviewed. - Do not treat the assessment period as permission to delay notification. DRAFT NOTIFICATION — REVIEW BEFORE USE Organisation and contact: Example Services Pty Ltd (fictional); Privacy officer · privacy@example.com (sample only) Description: A folder containing customer identity documents was accessible through a public link. Access logs indicate an unknown external party downloaded files before access was revoked. This is a fictional, anonymised example. Information involved: Names, dates of birth, addresses and identity document images. No real customer records are included in this sample. Recommended individual actions: Contact the issuing authority for advice about exposed identity documents. Monitor accounts for unusual activity and contact your financial institution promptly about suspected fraud. Be alert to targeted phishing and verify unexpected requests independently. This report is decision support, not legal advice or a notification submission. No notification has been sent by this application. Dates marked notified are user-entered records. Seek qualified advice for jurisdiction, coverage, exceptions and other reporting duties. Official guidance: https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme Submit a reviewed notification: https://www.oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breachStart your free initial check