Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Privacy new case form

On the new privacy case form, fill in the fields.

FieldDescription
NumberNumber of the case. This field is automatically set.
TitleName of the case. For example, `Customer records compromised by unprotected back-up database`.
TypeNature or type of case. This field is automatically set to Privacy case.
StateWorkflow state of the case. This field is automatically set to New.
RequesterPerson who reported the case.
Primary entityEntity impacted by the case. Only the entities identified in the impacted areas are available for selection as the primary entity.
Sub-typeSub type of case. For example, Documentation Loss.
Priority

Priority of the case. The choices are as follows:- 1 - Critical - 2- High - 3 - Moderate - 4 - Low - 5 - Planning

Note: The default value in this field is set to Planning.

Requested on behalf ofName of the person on whose behalf you’ve created the case.
Entity ownerUser who is the owner of the entity. This field is automatically set based on the entity selected in the Impacted areas related list.
DescriptionBrief description of the case.
Personal information
Contains personal informationField to decide if the breach contains personal information. The choices are as follows:- To be decided: Select this option if you’re not sure if the breach has personal information. - Yes: Select this option if the breach has personal information. - No: Select this option if the breach doesn’t have personal information.
Number of impacted individualsNumber of people impacted by the case.
Categories of data subjects/individuals impactedDefine who is impacted by the case. The choices are as follows:- Customers - Employees
Assignment
Assignment groupGroup assigned to the case. Note: The assignment group is preconfigured to the case type during configuration setup.
Case analystAnalyst who will analyze and work on the case. The case analyst is a part of the Assignment group.
Watch listPeople who must be aware of the case.
Accountable executiveExecutive who is accountable for the case.
Primary origin
LocationLocation where the case occurred. For example, the location is Japan.
Impacted business unitBusiness unit that is impacted by the breach.
SourceSource of the case creation. This field is automatically set to Manual when the case is manually created. If the case is reported from the Employee Center, the field displays the source as Employee Center.
Additional sourceMode of how the case is reported when the case is created manually. This field is available only when Manual is selected from the Source field and the record is saved. The choices are as follows:- Email - Phone
Sub-locationSub location of the case occurrence. For example, the sub location is Tokyo.
Impacted departmentDepartment impacted by the case. The choices are as follows:- Finance - HR - IT - Marketing - Sales
Source recordSource record of source object from where the case is created. For example, if the case is reported from risk events, then this field displays the name of the risk event from which the case is reported.
Schedule
Date of occurrenceDate the case occurred. For example, the case may have occurred on 18-02-2022.
Date of discoveryDate the case is discovered by you. For example, the case may have occurred on 18-02-2022, but is discovered by the user only on 12-03-2022.
Reported dateDate the case is reported.
Case closure SLAExpected date of case closure.
Investigation planned startPlanned start date to investigate the case.
Investigation actual startActual start date of case investigation.
Remediation planned startPlanned start date to remediate the case.
Remediation actual startActual start date of case remediation.
Investigation planned endPlanned end date to investigate the case.
Investigation actual endActual end date of case investigation.
Remediation planned endPlanned end date of case remediation.
Remediation actual endActual end date of case remediation.
Breach analysis
Breach statusStatus to indicate if a breach has occurred or not. The choices are as follows:- To be determined: This is the default value. - Breach detected: If the breach is confirmed. - Future potential: If the breach has not occurred but may occur in the future. - Not a breach: When there is no breach detected.
Breach startDate the breach started. This field only appears when Breach detected or Future potential is selected from the Breach status field.
Reporting statusStatus of the case being reported to the regulators. This field is automatically set based on the reporting status of the regulations associated with the case. If a case has many regulations and even if one regulation is identified as reportable, then the reporting status of the case is set to Reportable. The default value of this field is To be determined.
Breach endDate the breach ended. This field only appears when Breach detected or Future potential is selected from the Breach status field.
Breach significance identifiedDate when the user identifies that the breach is significant. This field only appears when Breach detected or Future potential is selected from the Breach status field.
Root cause analysis
Primary causePrimary cause of the case occurrence. This field is automatically set to the primary cause that is selected in the Cause and consequences related list.
Related consequenceConsequences of the primary cause for the case.
Overall observationsObservations made regarding the case.
Remediation takenField to indicate if remediation measures have been taken to address the case. The choices are as follows:- Yes - No
Overall preventive measuresPreventive measures taken toward the case.
Activity
Work notes \(Private\)Notes or information regarding the case.
Additional comments \(Customer visible\)Additional information regarding the case for the customers.

Parent Topic:Create a privacy case in the Privacy Workspace