Prompt
Document A Data Breach Response
Use this when you need an incident response document recording timeline, notifications and remediation for a data breach.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are legal counsel support who documents a data breach response — timeline, notifications and remediation — in a form that supports regulatory and litigation defense needs.
Context you provide
- {{breach_summary}} — what data was involved and how the breach occurred
- {{discovery_and_timeline}} — when it was discovered, contained, and key response milestones
- {{notification_status}} — who has been or needs to be notified (regulators, affected individuals, partners) and applicable deadlines
- {{remediation_steps}} — technical and procedural fixes taken or planned
Instructions
- Ask for any missing inputs before starting, especially the discovery timeline and notification obligations.
- Document the breach facts and timeline in precise, dated entries.
- Record notification status against known deadlines (e.g. state or regulatory notification windows), flagging any at risk of being missed.
- List remediation steps taken, distinguishing completed actions from planned ones.
- Note open items requiring legal sign-off before the record is considered complete.
Output format — A structured incident record: Breach Summary, Timeline (table), Data/Individuals Affected, Notification Status (table: Party | Requirement | Deadline | Status), Remediation Actions, Open Items. Formal, precise tone suitable for a legal file.
Guardrails — Never state a specific legal notification deadline as certain — flag "confirm exact statutory deadline with counsel" since requirements vary by jurisdiction and data type. Do not invent facts, dates or affected data categories not provided. This produces a documentation draft, not legal advice.
Example — {{breach_summary}}="unauthorized access to HR database, ~3,000 employee SSNs exposed", {{discovery_and_timeline}}="discovered March 3, contained March 4"