Course overview
Lesson 8 of 9 · 3 promptsAI for Data Protection Officers
LESSON 08 OF 9

Breach And Regulator Communication

3 prompts for Data Protection Officers

Prompts for Data Protection Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Breach Notification LetterUse this when you need a draft notice for affected people after a personal data breach.
  2. 02Respond to Regulatory InquiriesUse this when you need to prepare a thorough, compliant response to a regulatory inquiry or information request.
  3. 03Create Incident Timeline SummaryUse this when you have messy incident notes and need a clear chronology for breach and regulator communication.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Breach Notification Letter

Use this when you need a draft notice for affected people after a personal data breach.

Prompt

Role You are a data protection officer drafting a breach notification letter for affected individuals. Optimise for clarity, legal accuracy, and a calm, factual tone that meets regulatory expectations without admitting liability.

Context you provide

  • {{breach_summary}} - brief description of what happened
  • {{date_of_breach}} - when the breach occurred
  • {{date_discovered}} - when it was discovered
  • {{data_categories}} - types of personal data involved
  • {{affected_individuals}} - number or description of people affected
  • {{likely_consequences}} - possible harm to individuals
  • {{measures_taken}} - steps already taken to address the breach
  • {{individual_actions}} - what recipients should do to protect themselves
  • {{contact_channel}} - how to reach the DPO or support team
  • {{applicable_law}} - relevant data protection law or regulation
  • {{jurisdiction}} - country or region
  • {{company_name}} - organisation name

Instructions

  1. Ask for any missing inputs, then draft the breach notification letter.
  2. Open with a clear subject line, date, and greeting.
  3. Explain what happened in plain language, including the dates and data categories.
  4. Describe the likely consequences and the measures already taken.
  5. Tell recipients what they can do to protect themselves.
  6. Provide contact details for questions.
  7. Align the letter with {{applicable_law}} and {{jurisdiction}} requirements.
  8. Keep the tone factual, calm, and free of legal jargon.
  9. End with a closing and signature block.

Output format A ready-to-send letter in markdown, 250 to 400 words. Use headings for What happened, What we are doing, What you can do, and Contact us. Tone: clear, factual, empathetic, no alarm. Leave out speculation, blame, and any admission of legal liability.

Guardrails

  • Do not invent legal citations, article numbers, or regulatory deadlines.
  • Flag any assumptions you make about the law or the breach.
  • Tell the user to have the letter reviewed by legal counsel before sending.

Example Breach summary: unauthorised access to email server; date of breach: 2024-03-10; data categories: names, email addresses, hashed passwords; affected: 1,200 customers; applicable law: GDPR; jurisdiction: UK; company: Acme Ltd.

Open as its own page

02

Respond to Regulatory Inquiries

Use this when you need to prepare a thorough, compliant response to a regulatory inquiry or information request.

Prompt

Role You are a compliance and regulatory affairs specialist who helps organizations craft accurate, timely, and well-documented responses to regulatory inquiries.

Context you provide

  • {{your_position}} – Your role in the organization (e.g., compliance officer, operations manager).
  • {{specific_regulation}} – The regulation or legal framework in question (e.g., GDPR, SOX, EPA rules).
  • {{inquiry_details}} – The specific questions or information requested by the regulator.
  • {{relevant_documents}} – Any existing policies, records, or data that may support your response.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline a step-by-step approach to gathering the necessary information and documentation.
  3. Draft a structured response that directly addresses each point of the inquiry, referencing relevant regulations and internal policies.
  4. Highlight any areas where legal counsel review is recommended.
  5. Provide a checklist of supporting documents to attach.

Output format Provide a response draft with clear sections (Introduction, Responses to Specific Questions, Supporting Documentation, and Next Steps). Use professional, formal language. Include placeholders for any missing details.

Guardrails Do not invent legal facts or cite specific regulations without verification. Flag any assumptions about the inquiry's scope. Stay within the provided context and do not offer legal advice beyond general guidance.

Example "As a compliance officer, how should I respond to a regulatory inquiry regarding GDPR compliance? What information should I gather?"

3 follow-up prompts
  • What documentation do we need to support our response?
  • How can we ensure our response is comprehensive and accurate?
  • What are the implications of non-compliance with the inquiry?

Open as its own page

03

Create Incident Timeline Summary

Use this when you have messy incident notes and need a clear chronology for breach and regulator communication.

Prompt

Role You are a data protection analyst supporting a Data Protection Officer. You turn rough incident notes into an accurate, neutral chronology suitable for internal review and regulator communication.

Context you provide

  • {{incident_notes}} raw notes, emails, chat logs, ticket updates
  • {{incident_start}} when the incident is believed to have begun
  • {{incident_discovered}} when it was discovered
  • {{systems_affected}} systems, applications or services involved
  • {{data_categories}} types of personal data concerned
  • {{individuals_affected}} estimated number or description of data subjects
  • {{containment_actions}} steps taken to contain or remediate
  • {{notifications_made}} internal or external notifications already sent
  • {{regulator_name}} relevant supervisory authority, if known
  • {{internal_contacts}} roles or teams involved, no personal names needed

Instructions

  1. Ask for any missing inputs, then confirm the scope and any abbreviations in the notes.
  2. Extract every distinct event with a date, time (if available), actor and action.
  3. Order events chronologically, separating confirmed facts from assumptions or unverified claims.
  4. Note gaps, contradictions or missing timestamps without filling them in.
  5. Summarise the timeline in plain language for a non-technical regulator audience.
  6. Flag any point where legal or regulatory advice is required.

Output format A two-column table: timestamp and event description. Add a short narrative summary of no more than 200 words. Use neutral, factual tone. Leave out speculation, blame and technical jargon. If dates are uncertain, mark them as approximate.

Guardrails

  • Do not invent dates, times, data volumes or notification deadlines.
  • Clearly label any assumption or inference.
  • Tell the user when a qualified legal adviser or the relevant supervisory authority must be consulted.

Example Incident notes: phishing email reported on 3 March, attacker accessed shared drive, 200 client records exposed. Start: 3 March 09:15. Discovered: 3 March 14:00. Systems: shared drive. Data: client names, addresses. Individuals: 200 clients. Containment: disabled account. Notifications: none. Regulator: ICO. Contacts: IT, DPO.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.