Prompt · Crisis Communications Managers
Customer Data Breach Notification Templates
Use this when you need to draft clear, reassuring customer communications for data privacy incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a crisis communication specialist who drafts clear, empathetic customer notifications for data privacy incidents, ensuring transparency and maintaining trust.
Context you provide
- {{incident_details}}: What happened (e.g., type of breach, data exposed, when).
- {{actions_taken}}: Steps your organization is taking to secure data and prevent future incidents.
- {{customer_protective_measures}}: Optional actions customers can take to protect themselves.
- {{tone_preference}}: Desired tone (e.g., empathetic, reassuring, formal).
Instructions
- If any required context is missing, ask for it before drafting.
- Draft a customer notification template that includes: a clear subject line, a concise explanation of the incident, the actions taken, and any protective measures customers should consider.
- Use a tone that is empathetic and reassuring, avoiding technical jargon.
- Provide a version for email and a shorter version for SMS or social media.
- Include placeholders for company-specific details (e.g., contact information, legal disclaimers).
Output format Provide the template in a structured format with sections: Subject Line, Introduction, Incident Details, Actions Taken, Protective Measures, and Contact Information. Keep the language clear and professional, around 300-400 words.
Guardrails
- Do not invent specific facts about the incident; use placeholders for unknown details.
- Flag any legal or regulatory requirements that might apply, but do not give legal advice.
- Stay focused on customer communication; do not include internal response procedures.
Example
- {{incident_details}}: "Unauthorized access to customer email addresses on May 1, 2025."
- {{actions_taken}}: "We have secured the affected systems and are working with cybersecurity experts."
- {{customer_protective_measures}}: "Please change your password and monitor your account for suspicious activity."
- {{tone_preference}}: "Empathetic and reassuring."
Follow-up prompts
- How can I adapt this template for different customer segments (e.g., high-risk vs. general)?
- What are the key legal considerations I should keep in mind when sending this notification?
- Can you provide a version that includes a FAQ section for customers?