Product · free template

Data Breach Initial Report

First report of a suspected data breach: what happened and when it was discovered, data and people affected, containment so far, and notification clocks.

A ready-to-use technology, saas & dev form for engineering, IT and product teams: 32 questions, 3 pages, 4 conditional rules.

Questions
32
Pages
3
Layouts
classic
Time to complete
12 min
Conditional rules
4
Preview it in the gallery

Searches this template answers

Also filed under

Live preview and test console

This is the real form. Answer it to test the flow — nothing is sent or stored.

Page 1 of 3What happened

Report it now, even if details are missing

Include your country code.

This template runs as a straight sequence — no branching rules.

Compliance checklist

Ready to publish
  • Payment items priced — passingEvery payment question charges a real amount, so a submission always records a payment.
  • Conditional logic resolves — passingEvery rule points at a question or page that exists in this template.
  • Legal text not required — passingThis template collects neither health nor regulated financial information.
  • Question labels unique — passingLogic and exports address questions by label, so duplicates are ambiguous.

What happens after submit: nothing is stored in this preview. On your own copy, every response triggers an instant email notification and lands in your response dashboard, ready to export or forward.

Happy with it? Take a copy into your workspace — every question, rule and setting comes with it.

Who this template is for

Data Breach Initial Report is built for engineering, IT and product teams who need to route technical requests with the context needed to triage them.

  • Engineering, IT and product teams working in technology, saas & dev.
  • Teams who need to route technical requests with the context needed to triage them without writing code or paying for a custom build.
  • Anyone replacing vague reports that can't be reproduced or prioritised with one structured record per enquiry.
  • Respondents are users, testers and internal stakeholders — the form asks them 32 questions across 3 screens.

Why this form is useful

It removes the cost of vague reports that can't be reproduced or prioritised and turns each submission into a record your team can act on immediately.

  • 24 questions are required, so submissions arrive complete instead of needing a follow-up email.
  • It captures a phone number for urgent follow-up.
  • It accepts a document or photo upload as evidence.
  • It pins the request to a specific date.
  • It allows multiple selections without free text.
  • It captures a numeric value you can filter and sort on.
  • Conditional logic hides 4 questions until they are relevant — shorter forms convert better than long ones.
  • Splitting the form across 3 pages keeps each screen short and shows respondents how much is left.

How to use this template

From copy to live form is a few minutes of work, and every step is reversible.

  1. 1Press “Use this template” — a fresh copy of Data Breach Initial Report lands in your workspace, ready to edit.
  2. 2Rename or delete any question, and change what is required. Nothing here is fixed.
  3. 3Open Notifications and add the email addresses that should be alerted on each submission; add an auto-reply to the respondent if the form collects an email address.
  4. 4Check the upload limits on the file question so respondents can attach what you actually need.
  5. 5Publish it, then either share the link directly or paste the embed snippet into your site — the embedded form resizes to fit and loads no marketing or advertising trackers.
  6. 6Watch responses land in Submissions, where you can filter, label and export them to CSV or PDF.

Logic and conditions blueprint

Exactly how this form behaves as it is answered — 4 conditional rules ship with it.

  • Features conditional validation: if “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes mandatory before the form can be sent.
  • Features conditional validation: if “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes mandatory before the form can be sent.
  • Features conditional validation: if “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes mandatory before the form can be sent.
  • Features conditional validation: if “Has anyone outside the organisation been told?” is Yes, “Who was told, when, and by whom” becomes mandatory before the form can be sent.
  • All 4 rules are editable in the Logic tab, and the built-in checker warns about rules that contradict each other.

About this template

A breach report has one urgent job: start the clock accurately. Notification deadlines usually run from the moment the organisation became aware, not from the moment the incident happened, and getting that timestamp right matters more than a polished narrative. This three-page form is written to be filled in within the hour. The first page records who is reporting, what they believe happened, when it occurred if known, and — as separate mandatory fields — the date and time it was discovered and how it came to light. The second page covers scope: the kind of information involved, whether it includes anything especially sensitive, the number of people affected or an estimate with a note that it is an estimate, whether the data was encrypted, whether it left the organisation and who now holds it. The third page covers response and clocks: containment steps already taken, whether the exposure is still live, whether anyone outside has been told, whether a supplier is involved, and the assessment fields for regulator and individual notification deadlines. Whether notification is required is a decision for your data protection lead under the applicable law.

What this form asks

Every question is editable — rename it, make it optional, or delete it entirely.

Page 1 — What happened

  • Reported byrequired
  • Role and teamrequired
  • Best number to reach yourequired
  • What you believe has happenedrequired
  • Type of incidentrequired
  • Date it happened, if known
  • Date it was discoveredrequired
  • Time it was discoveredrequired
  • How it came to lightrequired
  • Systems, files or mailboxes involvedrequired

Page 2 — Data and people affected

  • Information involvedrequired
  • Does it include especially sensitive information?required
  • Whose information is it?required
  • People affected, or best estimate
  • Is that figure confirmed or an estimate?required
  • Was the data encrypted or protected?required
  • Did the data leave the organisation?required
  • Where it went, and who holds it now
  • Could this cause harm to the people affected?required

Page 3 — Containment and clocks

  • What has already been done to contain itrequired
  • Is the exposure still live?required
  • What is stopping it being closed
  • Is a supplier or third party involved?required
  • Which supplier, and what they have been told
  • Has anyone outside the organisation been told?required
  • Who was told, when, and by whom
  • Date the organisation became awarerequired
  • Time the organisation became awarerequired
  • Data protection lead informedrequired
  • Evidence preserved, and where it is held
  • Attach screenshots, logs or correspondence
  • Confirmationsrequired

32 questions in total.

Example of a completed data breach incident report form

Shows an early, honest report filed as soon as an incident is noticed, before all the facts are known.

Reported by
Helena Whitfield
Role and team
Customer Support Lead
What you believe has happened
An email containing a customer list was sent to the wrong recipient
Type of incident
Misdirected email
Date it was discovered
2026-02-20
Information involved
Names, email addresses
Whose information is it?
Customers
People affected, or best estimate
40
Was the data encrypted or protected?
No

Sample data — no real people, addresses or records are shown.

How the form changes as it's filled in

This template ships with 4 conditional rules, grouped into 4 behaviours driven by 4 questions. Everything below is already set up — edit or delete any rule once the template is in your workspace.

Driven by “Is the exposure still live?

  • Makes answers required

    If “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes required before the form can be submitted.

Driven by “Did the data leave the organisation?

  • Makes answers required

    If “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes required before the form can be submitted.

Driven by “Is a supplier or third party involved?

  • Makes answers required

    If “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes required before the form can be submitted.

Driven by “Has anyone outside the organisation been told?

  • Makes answers required

    If “Has anyone outside the organisation been told?” is Yes, “Who was told, when, and by whom” becomes required before the form can be submitted.

Set it up step by step

  1. 1

    Publish it internally as the one route

    Staff should have a single place to report, and it should be reachable in two clicks from wherever they work.

  2. 2

    Alert on submission

    Send every submission to the data protection lead immediately by more than one channel; a queue defeats the purpose.

  3. 3

    Never gate it on certainty

    Suspected is enough. The form is written so an incomplete report can be submitted in minutes and updated later.

  4. 4

    Record awareness precisely

    The awareness date and time drive statutory deadlines, so capture them separately from when the incident occurred.

Mistakes to avoid

  • Investigating first and reporting later, which quietly burns most of the notification window.
  • Recording only the incident date, leaving the awareness timestamp — the one deadlines run from — unrecorded.
  • Deleting the offending email or file before it is preserved as evidence.

What it pairs with

Most teams don't run this form on its own. These are the forms and systems it sits next to.

What to do with the responses

Assess notification duties against the recorded awareness time, contain and close the exposure, then run a postmortem once the incident is over.

Works in this layout

These pages cover the same subject ground as the data breach initial report, matched on the words people actually search for.

Frequently asked questions

How is this different from an incident postmortem?

This is the initial report, filed within the hour, with awareness timestamps and notification questions. The postmortem comes afterwards and looks at causes and prevention.

Should staff report if they are not sure?

Yes. Every field allows 'not yet known', because a fast uncertain report is far more useful than a slow complete one.

Does it decide whether we must notify a regulator?

No. It gathers the facts and timestamps; your data protection lead decides under the law that applies to you.

Who should be able to see submissions?

A small named group only. The form holds sensitive detail, so restrict access and avoid routing it to a shared inbox.

Is the Data Breach Initial Report template free to use?

Yes. You can preview and test Data Breach Initial Report on this page without an account, and take a copy into your own HelloForms workspace on the free plan. There is nothing to install and no card required to publish it.

What does the Data Breach Initial Report template ask for?

It asks 32 questions across 3 pages, 24 of which are required. Every question is listed in full further down this page, and each one can be renamed, reordered, made optional or deleted after you copy the template.

Can I edit the Data Breach Initial Report form after copying it?

Yes — the copy is entirely yours. Change wording, add or remove questions, switch between the classic layout, restyle it to match your brand, and set who gets notified on each submission.

How does the conditional logic in this technology, saas & dev form work?

4 conditional rules ship with the template: Features conditional validation: if “Is the exposure still live?” is Yes, “What is stopping it being closed” becomes mandatory before the form can be sent. Features conditional validation: if “Did the data leave the organisation?” is Yes, “Where it went, and who holds it now” becomes mandatory before the form can be sent. Features conditional validation: if “Is a supplier or third party involved?” is Yes, “Which supplier, and what they have been told” becomes mandatory before the form can be sent. All rules are editable in the Logic tab.

Where do responses to the Data Breach Initial Report form go?

Submissions land in your workspace under Submissions, where you can search, filter, label and export them to CSV or PDF. You can also email a notification to your team on every submission and send the respondent an auto-reply.

Can I embed the Data Breach Initial Report form on my own website?

Yes. Publish the form and paste the embed snippet into any page or share the direct link. The embedded form resizes to fit its container and loads no advertising or marketing trackers inside the iframe.

Can respondents upload files?

Yes. This template includes a file upload question, so respondents can attach documents or photos with their answers. You can adjust the accepted file types and size limits on that question.

More forms teams pair with the data breach initial report.

Related categories