Data Breach Initial Report
First report of a suspected data breach: what happened and when it was discovered, data and people affected, containment so far, and notification clocks.
A ready-to-use technology, saas & dev form for engineering, IT and product teams: 32 questions, 3 pages, 4 conditional rules.
- Questions
- 32
- Pages
- 3
- Layouts
- classic
- Time to complete
- ≈ 12 min
- Conditional rules
- 4
Searches this template answers
- data breach incident report form
- suspected data breach report online
- personal data breach notification form
- security incident initial report form
- data breach reporting form staff
Also filed under
Live preview and test console
This is the real form. Answer it to test the flow — nothing is sent or stored.
Page 1 of 3 — What happened
This template runs as a straight sequence — no branching rules.
Compliance checklist
- Payment items priced — passingEvery payment question charges a real amount, so a submission always records a payment.
- Conditional logic resolves — passingEvery rule points at a question or page that exists in this template.
- Legal text not required — passingThis template collects neither health nor regulated financial information.
- Question labels unique — passingLogic and exports address questions by label, so duplicates are ambiguous.
What happens after submit: nothing is stored in this preview. On your own copy, every response triggers an instant email notification and lands in your response dashboard, ready to export or forward.
Happy with it? Take a copy into your workspace — every question, rule and setting comes with it.
Who this template is for
Data Breach Initial Report is built for engineering, IT and product teams who need to route technical requests with the context needed to triage them.
- Engineering, IT and product teams working in technology, saas & dev.
- Teams who need to route technical requests with the context needed to triage them without writing code or paying for a custom build.
- Anyone replacing vague reports that can't be reproduced or prioritised with one structured record per enquiry.
- Respondents are users, testers and internal stakeholders — the form asks them 32 questions across 3 screens.
Why this form is useful
It removes the cost of vague reports that can't be reproduced or prioritised and turns each submission into a record your team can act on immediately.
- 24 questions are required, so submissions arrive complete instead of needing a follow-up email.
- It captures a phone number for urgent follow-up.
- It accepts a document or photo upload as evidence.
- It pins the request to a specific date.
- It allows multiple selections without free text.
- It captures a numeric value you can filter and sort on.
- Conditional logic hides 4 questions until they are relevant — shorter forms convert better than long ones.
- Splitting the form across 3 pages keeps each screen short and shows respondents how much is left.
How to use this template
From copy to live form is a few minutes of work, and every step is reversible.
- 1Press “Use this template” — a fresh copy of Data Breach Initial Report lands in your workspace, ready to edit.
- 2Rename or delete any question, and change what is required. Nothing here is fixed.
- 3Open Notifications and add the email addresses that should be alerted on each submission; add an auto-reply to the respondent if the form collects an email address.
- 4Check the upload limits on the file question so respondents can attach what you actually need.
- 5Publish it, then either share the link directly or paste the embed snippet into your site — the embedded form resizes to fit and loads no marketing or advertising trackers.
- 6Watch responses land in Submissions, where you can filter, label and export them to CSV or PDF.
Logic and conditions blueprint
Exactly how this form behaves as it is answered — 4 conditional rules ship with it.
- Features conditional validation: if “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes mandatory before the form can be sent.
- Features conditional validation: if “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes mandatory before the form can be sent.
- Features conditional validation: if “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes mandatory before the form can be sent.
- Features conditional validation: if “Has anyone outside the organisation been told?” is Yes, “Who was told, when, and by whom” becomes mandatory before the form can be sent.
- All 4 rules are editable in the Logic tab, and the built-in checker warns about rules that contradict each other.
About this template
A breach report has one urgent job: start the clock accurately. Notification deadlines usually run from the moment the organisation became aware, not from the moment the incident happened, and getting that timestamp right matters more than a polished narrative. This three-page form is written to be filled in within the hour. The first page records who is reporting, what they believe happened, when it occurred if known, and — as separate mandatory fields — the date and time it was discovered and how it came to light. The second page covers scope: the kind of information involved, whether it includes anything especially sensitive, the number of people affected or an estimate with a note that it is an estimate, whether the data was encrypted, whether it left the organisation and who now holds it. The third page covers response and clocks: containment steps already taken, whether the exposure is still live, whether anyone outside has been told, whether a supplier is involved, and the assessment fields for regulator and individual notification deadlines. Whether notification is required is a decision for your data protection lead under the applicable law.
What this form asks
Every question is editable — rename it, make it optional, or delete it entirely.
Page 1 — What happened
- Reported byrequired
- Role and teamrequired
- Best number to reach yourequired
- What you believe has happenedrequired
- Type of incidentrequired
- Date it happened, if known
- Date it was discoveredrequired
- Time it was discoveredrequired
- How it came to lightrequired
- Systems, files or mailboxes involvedrequired
Page 2 — Data and people affected
- Information involvedrequired
- Does it include especially sensitive information?required
- Whose information is it?required
- People affected, or best estimate
- Is that figure confirmed or an estimate?required
- Was the data encrypted or protected?required
- Did the data leave the organisation?required
- Where it went, and who holds it now
- Could this cause harm to the people affected?required
Page 3 — Containment and clocks
- What has already been done to contain itrequired
- Is the exposure still live?required
- What is stopping it being closed
- Is a supplier or third party involved?required
- Which supplier, and what they have been told
- Has anyone outside the organisation been told?required
- Who was told, when, and by whom
- Date the organisation became awarerequired
- Time the organisation became awarerequired
- Data protection lead informedrequired
- Evidence preserved, and where it is held
- Attach screenshots, logs or correspondence
- Confirmationsrequired
32 questions in total.
Example of a completed data breach incident report form
Shows an early, honest report filed as soon as an incident is noticed, before all the facts are known.
- Reported by
- Helena Whitfield
- Role and team
- Customer Support Lead
- What you believe has happened
- An email containing a customer list was sent to the wrong recipient
- Type of incident
- Misdirected email
- Date it was discovered
- 2026-02-20
- Information involved
- Names, email addresses
- Whose information is it?
- Customers
- People affected, or best estimate
- 40
- Was the data encrypted or protected?
- No
Sample data — no real people, addresses or records are shown.
How the form changes as it's filled in
This template ships with 4 conditional rules, grouped into 4 behaviours driven by 4 questions. Everything below is already set up — edit or delete any rule once the template is in your workspace.
Driven by “Is the exposure still live?”
- Makes answers required
If “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes required before the form can be submitted.
Driven by “Did the data leave the organisation?”
- Makes answers required
If “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes required before the form can be submitted.
Driven by “Is a supplier or third party involved?”
- Makes answers required
If “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes required before the form can be submitted.
Driven by “Has anyone outside the organisation been told?”
- Makes answers required
If “Has anyone outside the organisation been told?” is Yes, “Who was told, when, and by whom” becomes required before the form can be submitted.
Set it up step by step
- 1
Publish it internally as the one route
Staff should have a single place to report, and it should be reachable in two clicks from wherever they work.
- 2
Alert on submission
Send every submission to the data protection lead immediately by more than one channel; a queue defeats the purpose.
- 3
Never gate it on certainty
Suspected is enough. The form is written so an incomplete report can be submitted in minutes and updated later.
- 4
Record awareness precisely
The awareness date and time drive statutory deadlines, so capture them separately from when the incident occurred.
Mistakes to avoid
- Investigating first and reporting later, which quietly burns most of the notification window.
- Recording only the incident date, leaving the awareness timestamp — the one deadlines run from — unrecorded.
- Deleting the offending email or file before it is preserved as evidence.
What it pairs with
Most teams don't run this form on its own. These are the forms and systems it sits next to.
What to do with the responses
Assess notification duties against the recorded awareness time, contain and close the exposure, then run a postmortem once the incident is over.
Works in this layout
Forms that overlap this one
These pages cover the same subject ground as the data breach initial report, matched on the words people actually search for.
Bug Bounty Report Form
bugdeskfeaturehelpdeskintake
Incident Postmortem Form
bugdeskfeaturehelpdeskincident
Vendor Security Questionnaire
bugdatadeskfeaturehelpdesk
Maintenance Window Notice
affectedbugdeskfeaturehelpdesk
Hardware Request
bugdeskfeaturehelpdeskintake
Accessibility Feedback Form
bugdeskfeaturehelpdeskintake
Frequently asked questions
How is this different from an incident postmortem?
This is the initial report, filed within the hour, with awareness timestamps and notification questions. The postmortem comes afterwards and looks at causes and prevention.
Should staff report if they are not sure?
Yes. Every field allows 'not yet known', because a fast uncertain report is far more useful than a slow complete one.
Does it decide whether we must notify a regulator?
No. It gathers the facts and timestamps; your data protection lead decides under the law that applies to you.
Who should be able to see submissions?
A small named group only. The form holds sensitive detail, so restrict access and avoid routing it to a shared inbox.
Is the Data Breach Initial Report template free to use?
Yes. You can preview and test Data Breach Initial Report on this page without an account, and take a copy into your own HelloForms workspace on the free plan. There is nothing to install and no card required to publish it.
What does the Data Breach Initial Report template ask for?
It asks 32 questions across 3 pages, 24 of which are required. Every question is listed in full further down this page, and each one can be renamed, reordered, made optional or deleted after you copy the template.
Can I edit the Data Breach Initial Report form after copying it?
Yes — the copy is entirely yours. Change wording, add or remove questions, switch between the classic layout, restyle it to match your brand, and set who gets notified on each submission.
How does the conditional logic in this technology, saas & dev form work?
4 conditional rules ship with the template: Features conditional validation: if “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes mandatory before the form can be sent. Features conditional validation: if “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes mandatory before the form can be sent. Features conditional validation: if “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes mandatory before the form can be sent. All rules are editable in the Logic tab.
Where do responses to the Data Breach Initial Report form go?
Submissions land in your workspace under Submissions, where you can search, filter, label and export them to CSV or PDF. You can also email a notification to your team on every submission and send the respondent an auto-reply.
Can I embed the Data Breach Initial Report form on my own website?
Yes. Publish the form and paste the embed snippet into any page or share the direct link. The embedded form resizes to fit its container and loads no advertising or marketing trackers inside the iframe.
Can respondents upload files?
Yes. This template includes a file upload question, so respondents can attach documents or photos with their answers. You can adjust the accepted file types and size limits on that question.
Related templates
More forms teams pair with the data breach initial report.
Related categories
- Marketing & Agency templates
- Cleaning & Facilities templates
- Facilities & Property Management templates
Discord Mod Application Form
Recruit moderators who'll actually show up — experience, time zones, judgement calls and scenario answers.💻 Technology, SaaS & Dev13 questionsShort form — 13 questions across 2 pages.View templateAccess Removal Request
Leaver access removal: who is leaving and when, what they had access to, equipment to recover, mailbox and file handover, and confirmation once done.💻 Technology, SaaS & Dev24 questionsMedium length — 24 questions across 2 pages.View templateNew User Account Request
Request accounts for a new starter: who they are, start date, team and manager, what they need access to, equipment, and manager approval before setup.💻 Technology, SaaS & Dev24 questionsMedium length — 24 questions across 2 pages.View templateCustomer Churn Survey
Learn why customers cancel — and offer a save path — in six honest questions.💻 Technology, SaaS & Dev9 questionsShort form — 9 questions on a single page.View templateProduct Feedback Survey
Structured in-app feedback with satisfaction, NPS and follow-up consent in eight questions.💻 Technology, SaaS & Dev10 questionsShort form — 10 questions on a single page.View templateAccessibility Feedback Form
Structured reporting for accessibility barriers, capturing page, assistive technology used, severity and reply preference.💻 Technology, SaaS & Dev13 questionsShort form — 13 questions across 3 pages.View template