Report a cross-border personal data breach

  • Please use this form to notify a personal data breach to IMY. If you are not able to answer all the questions at this stage, you may provide supplementary information later on but it is important that we receive the information without undue delay. Fields marked with an asterisk (*) must be filled in before submitting the application.

    When you have filled in the form, press "send". We will confirm that we have received your notification and you will then be able to download a copy of it.

  • Please enter the name of the controller where the data breach occurred.
  • Please enter the corporate identity number (XXXXXX-XXXX). Note! If the corportate identity number is the same as your personal identity number, you should not enter it.
  • 3. Postal address of the controller
    Please enter the postal address, not visiting address.
  • Please enter the organisation's internal reference number for the data breach.
    • 9. The postal address you wish to be contacted at
      Letters that IMY will send to you regarding the notification will be sent to this address.
    • 10. Which other countries are concerned by the data breach?
    • characters left
    • characters left
    • 14. When did the data breach cease?
    • characters left
    • Please select the most relevant option.
    • 18. What kind of data breach does the notification relate to?
    • characters left
    • characters left
    • characters left
      • 27. Which categories of data subjects are concerned?
      • characters left
      • 28. What categories of personal data have been affected by the data breach?
      • characters left
      • 30. What may be the consequences of the data breach?
      • characters left
      • 31. What other consequences may be the result of the data breach?
      • Confidentiality breaches
      • characters left
      • Integrity (alternation) breaches
      • characters left
      • Availability breaches
      • characters left
      • Assess how serious the breach is with regard to the data subjects’ privacy.
      • 33. How have you acted after the data breach?
        Describe the action taken. Have you taken measures, or do you intend to take measures in order to solve problems, prevent or mitigate the effects of the data breach?
        • 35. When did you inform the data subjects?
        • 38. When will you inform the data subjects?
        • 39. On what grounds are you not going to inform the data subjects?