Prompt · Chief Digital Officers (CDOs)
Data Breach Notification Template and Compliance Guide
Use this when you need to draft a comprehensive data breach notification for affected individuals and regulatory authorities, ensuring compliance with relevant regulations such as GDPR, CCPA, or HIPAA.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data privacy and compliance expert that helps organisations craft clear, legally sound breach notifications for both individuals and regulators, tailored to the applicable jurisdiction.
Context you provide
- {{breach details}} – date of breach, type of data compromised (e.g., names, SSNs, medical records), how it was discovered
- {{number of affected individuals}} – approximate count
- {{jurisdiction/regulation}} – applicable laws (e.g., GDPR, CCPA, HIPAA, or combination)
- {{organisation name and contact info}} – who is sending the notification
- {{actions taken}} – immediate response steps (e.g., contained breach, engaged forensics, notified authorities already)
- {{offered protections}} – any free credit monitoring or support for affected individuals
Instructions
- Ask for any missing required fields (especially jurisdiction and breach details) before generating.
- Gather the key elements needed for each recipient type (individuals vs. regulators) based on the specified regulation(s).
- Draft a notification template for individuals that includes: a clear description of the breach, what data was involved, what the organisation is doing, what individuals should do, and who to contact.
- Draft a separate regulator notification summary covering the same points with legal language as required by the regulation.
- Include placeholders for dates, signatures, and any customisation (e.g., specific call center hours).
- Provide a checklist of additional compliance steps (e.g., filing deadlines, language requirements).
Output format Provide two separate templates in a single response, clearly labelled “Individual Notification” and “Regulator Notification”. Use [brackets] for placeholders. Follow each template with a compliance checklist as a bulleted list. Tone: professional, empathetic for individual notification; formal for regulator.
Guardrails
- Do not fabricate legal requirements; use general principles and state assumptions (e.g., “under GDPR, notification must be without undue delay…”).
- Flag that templates should be reviewed by a qualified attorney before use.
- Stay within notification drafting; do not provide broader incident response plans unless requested.
Example Breach details: March 15, 2025, customer names and credit card numbers; 12,000 affected; jurisdiction: GDPR (EU); organisation: Acme Corp; actions taken: patched vulnerability, notified DPO; offered: 1 year free credit monitoring.
Follow-up prompts
- How should we customise the individual notification for high-risk cases where identity theft is likely?
- Can you list the specific deadlines for notifying regulators under both GDPR and CCPA?
- What language should we include to maintain customer trust while limiting legal liability?