Identifier
Unique incident ID, report date, and reference to related ticket or case numbers so the controller can cross‑reference internal records and audit trails.
A single, clear form reduces ambiguity, ensures the controller receives the facts needed to meet legal obligations, and creates a defensible record of notification. Standardized details speed triage, minimize follow-up questions, and support regulatory reporting where required.
Internal security teams, third‑party processors, and vendor compliance officers typically prepare the form and send it to the controller or designated data protection contact.
The controller’s designated recipient (DPO, privacy inbox, or legal lead) should acknowledge receipt and log the notification in the controller’s incident register.
The DPO or privacy lead is authorized to receive and review controller notifications, coordinate regulator reporting, and confirm required disclosures. The DPO documents the controller’s assessment and any decisions about notifications to supervisory authorities and individuals.
A named security or compliance officer at the processor completes and signs the form, certifying the accuracy of the facts supplied and confirming the steps taken to contain and remediate the event.
Unique incident ID, report date, and reference to related ticket or case numbers so the controller can cross‑reference internal records and audit trails.
Concise description of what occurred, how it was discovered, and the timeframe of exposure; avoid speculation and use precise timestamps where available.
List affected systems, number and categories of individuals or records, and whether special categories of data (e.g., health, financial) are involved.
High-level technical root cause, access vectors, and indicators of compromise needed for controller risk assessment and forensic follow-up.
Actions taken to contain the issue, timeline for fixes, ongoing monitoring, and planned preventive measures to reduce recurrence.
Named point(s) of contact, phone/email, signature block, and a brief attestation that the information is accurate to the sender’s knowledge.
Use file formats and signing methods that preserve metadata and support audit trails.
Use secure transmission (TLS) and retain the signed copy and audit record to support regulatory response and later review.
| Field | Configuration |
|---|---|
| Notification Type | Security Incident | Mandatory selection |
| Authentication | Email + SMS code or SSO |
| Attachments Allowed | PDF, DOCX, log exports |
| Retention Setting | Retain signed record 7 years |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies | Varies | Varies |
Notify controller as soon as incident facts allow, without unreasonable delay.
Provide an initial form within 24 hours of detection when practicable.
Submit a comprehensive report within 72 hours if feasible.
Controller determines regulator timelines per applicable law and informs processor of obligations.
Controller coordinates individual notifications consistent with state and sector requirements.
Their team reduced turnaround on vendor notifications by standardizing the form and signatures.
A single signed form replaced informal emails for property data incidents.