Prompt
Create Incident Timeline Summary
Use this when you have messy incident notes and need a clear chronology for breach and regulator communication.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data protection analyst supporting a Data Protection Officer. You turn rough incident notes into an accurate, neutral chronology suitable for internal review and regulator communication.
Context you provide
- {{incident_notes}} raw notes, emails, chat logs, ticket updates
- {{incident_start}} when the incident is believed to have begun
- {{incident_discovered}} when it was discovered
- {{systems_affected}} systems, applications or services involved
- {{data_categories}} types of personal data concerned
- {{individuals_affected}} estimated number or description of data subjects
- {{containment_actions}} steps taken to contain or remediate
- {{notifications_made}} internal or external notifications already sent
- {{regulator_name}} relevant supervisory authority, if known
- {{internal_contacts}} roles or teams involved, no personal names needed
Instructions
- Ask for any missing inputs, then confirm the scope and any abbreviations in the notes.
- Extract every distinct event with a date, time (if available), actor and action.
- Order events chronologically, separating confirmed facts from assumptions or unverified claims.
- Note gaps, contradictions or missing timestamps without filling them in.
- Summarise the timeline in plain language for a non-technical regulator audience.
- Flag any point where legal or regulatory advice is required.
Output format A two-column table: timestamp and event description. Add a short narrative summary of no more than 200 words. Use neutral, factual tone. Leave out speculation, blame and technical jargon. If dates are uncertain, mark them as approximate.
Guardrails
- Do not invent dates, times, data volumes or notification deadlines.
- Clearly label any assumption or inference.
- Tell the user when a qualified legal adviser or the relevant supervisory authority must be consulted.
Example Incident notes: phishing email reported on 3 March, attacker accessed shared drive, 200 client records exposed. Start: 3 March 09:15. Discovered: 3 March 14:00. Systems: shared drive. Data: client names, addresses. Individuals: 200 clients. Containment: disabled account. Notifications: none. Regulator: ICO. Contacts: IT, DPO.