Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for data protection officers

Personal Data Breach Notification Agent

Breaches assessed and notified on time with accurate facts

Personal Data Breach Notification Agent: what goes in, what the agent does and what you get

What it does

When personal data is exposed, the clock for regulator notice is often 72 hours, and facts arrive slowly. When a possible breach is reported, this agent starts the clock and builds the breach record: what happened, data types, number of people affected and containment steps. It assesses the risk to people, treating sensitive data as likely high risk and encrypted data with a safe key as lower risk. It checks the record for gaps such as an unknown number of people and asks the incident team for them. If the deadline approaches with gaps, it drafts a phased notification. It drafts regulator and individual notices and updates them as facts change. The DPO approves every notification. Edge case: the data was encrypted and the key was safe, so individual notice may not be needed.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedNo 1 STARTS WHEN Possible breach reported 2 DOES Start clock and record facts 3 DOES Assess risk to people 4 CHECKS THE RESULT Are key facts known? If not: ask the incident team and prepare phased noticeif needed. Back to step 2. 5 USES A TOOL Draft notifications 6 YOU APPROVE DPO approves notifications 7 RESULT Breach register updated
Read the steps as a list
  1. Possible breach reported
  2. Start clock and record facts
  3. Assess risk to people
  4. Are key facts known?If not: ask the incident team and prepare phased notice if needed. Back to step 2.
  5. Draft notifications
  6. DPO approves notificationsThe agent waits here for your OK.
  7. Breach register updated

How it decides

It rates risk to people by data type, volume and protection, and applies notification rules.

  • Regulator notice within 72 hours if risk
  • Encrypted with safe key: lower risk
  • Sensitive data: likely high risk

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Notification rules by law
  • Risk scale
  • Templates
  • Escalation contacts

What keeps you in control

It always asks you first

  • Regulator and individual notifications

Hard limits

  • Never sends notifications
  • Never minimizes facts

It stops when

  • Done: notified or documented not to notify
  • Stop: legal privilege requested

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensA misdirected email on Monday exposed customer records with account numbers. At hour 24 the count of people was still unknown, so the facts check failed. The agent asked the incident team, and at hour 48 they confirmed 340 people. It drafted the regulator notice and a customer letter. The DPO approved both at hour 60, inside the 72-hour window.

More agents for data protection officers