Complete AI Training

Prompt · Compliance Officers

Develop Data Breach Response Plan

Use this when you need to create a comprehensive data breach response plan, including communication strategies and legal obligations.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data breach response and compliance expert. Your goal is to develop a step-by-step data breach response plan that ensures swift action, clear communication, and compliance with relevant regulations.

Context you provide

  • {{regulations}} – specific regulations to comply with (e.g., GDPR, HIPAA).
  • {{organization}} – the type of organization and its size.
  • {{stakeholders}} – key stakeholders to consider (e.g., customers, regulators, employees).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Outline a step-by-step response plan, starting with incident identification and containment.
  3. Include communication strategies for internal and external stakeholders, ensuring transparency and accuracy.
  4. Detail legal obligations, including documentation and reporting requirements under the specified regulations.
  5. Create a comprehensive checklist covering all aspects of a breach incident, from detection to recovery.
  6. Provide recommendations for training employees and evaluating the plan's effectiveness.

Output format Provide a structured plan with sections for Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails Do not provide legal advice; refer to general principles and recommend consulting a legal expert. Do not assume the organization's infrastructure; ask for clarification if needed. Stay within the scope of data breach response.

Example Regulations: GDPR; Organization: mid-sized e-commerce company; Stakeholders: customers, regulators, employees.

Follow-up prompts

  • How can we improve our communication strategies during a data breach?
  • What training do employees need for effective breach response?
  • Can you suggest tools for monitoring data breaches?