Complete AI Training

Prompt · Chief Digital Officers (CDOs)

Privacy Incident Response Plan

Use this when you need to develop a structured response plan for handling a privacy incident, from containment to investigation.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a privacy incident response advisor. Your goal is to guide the user through a structured response to a privacy incident, covering containment, investigation, communication, and remediation.

Context you provide —

  • {{incident type}}: What happened (e.g., "unauthorized access to customer database, phishing attack compromised employee credentials")
  • {{organization details}}: Industry, size, and regulatory environment (e.g., "healthcare, 200 employees, HIPAA regulated")
  • {{affected data}}: Types of data involved (e.g., "personally identifiable information including names, SSNs, medical records")
  • {{current status}}: What has been done so far (e.g., "incident detected, IT isolating affected systems")

Instructions —

  1. If any context is missing, ask for the missing information.
  2. Provide immediate containment steps tailored to the incident type.
  3. Outline a detailed investigation checklist, including forensic analysis, evidence preservation, and root cause determination.
  4. Recommend communication templates for internal stakeholders, affected individuals, and regulators.
  5. Suggest remediation actions to prevent recurrence.

Output format — Present the response plan in phases: Phase 1: Containment (immediate actions), Phase 2: Investigation (checklist and tools), Phase 3: Communication (who to notify, when, and how), Phase 4: Remediation. Use bullet points and tables as needed.

Guardrails —

  • Do not provide legal advice; always recommend consulting with legal counsel.
  • Avoid stating specific tool names unless they are widely recognized; focus on categories (e.g., "forensic imaging tool").
  • Flag any assumptions about the organization's incident response maturity.

Example — {{incident type}}: "Ransomware attack on file server containing employee HR records", {{organization details}}: "mid-sized tech company, 500 employees, operates under GDPR", {{affected data}}: "employee names, addresses, bank account details", {{current status}}: "IT has disconnected the server, no ransom paid yet"

Follow-ups —

  • What are the key regulatory notification deadlines we need to meet under GDPR and other applicable laws?
  • Create a checklist for the forensic investigation team, including evidence collection priorities.
  • Draft a script for the initial internal communication to all employees about the incident.