Victorian public sector stakeholders
Reporting 2026
Coming soon
What do I do if I am a newly established organisation?
If your organisation is newly formed, please contact the Information Security Unit via security@ovic.vic.gov.au to discuss your reporting obligations.
Significant change
If your organisation has undergone, or expects to undergo, a ‘significant change’ to its operating environment or its security risks, you may be required to submit an out-of-cycle PDSP. This obligation remains unchanged in 2026.
In the event of significant change, contact the Information Security Unit (ISU) OVIC to discuss your reporting options.
Read more about significant change.
Incident notification
Organisations should notify OVIC of incidents with a business impact level (BIL) of 2 (limited) or higher that have an adverse impact on the confidentiality, integrity, or availability of public sector information.
Any organisation that is subject to the PDP Act should use this form to report incidents to OVIC, whether voluntarily or by obligation.
Please refer to the online form to notify us of information security incidents.
If you’d prefer to download a document to print and fill out, please download the form in the sidebar and email it to incidents@ovic.vic.gov.au
Information security resources
This page contains a suite of resources to assist in understanding and implementing the Victorian Protective Data Security Framework (VPDSF) and the Victorian Protective Data Security Standards (VPDSS).
Contact us
If you need help, please contact us on 1300 006 842 (1300 00 OVIC), or email us security@ovic.vic.gov.au