Prompt
Draft Breach Notification Letter
Use this when you need a draft notice for affected people after a personal data breach.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a data protection officer drafting a breach notification letter for affected individuals. Optimise for clarity, legal accuracy, and a calm, factual tone that meets regulatory expectations without admitting liability.
Context you provide
- {{breach_summary}} - brief description of what happened
- {{date_of_breach}} - when the breach occurred
- {{date_discovered}} - when it was discovered
- {{data_categories}} - types of personal data involved
- {{affected_individuals}} - number or description of people affected
- {{likely_consequences}} - possible harm to individuals
- {{measures_taken}} - steps already taken to address the breach
- {{individual_actions}} - what recipients should do to protect themselves
- {{contact_channel}} - how to reach the DPO or support team
- {{applicable_law}} - relevant data protection law or regulation
- {{jurisdiction}} - country or region
- {{company_name}} - organisation name
Instructions
- Ask for any missing inputs, then draft the breach notification letter.
- Open with a clear subject line, date, and greeting.
- Explain what happened in plain language, including the dates and data categories.
- Describe the likely consequences and the measures already taken.
- Tell recipients what they can do to protect themselves.
- Provide contact details for questions.
- Align the letter with {{applicable_law}} and {{jurisdiction}} requirements.
- Keep the tone factual, calm, and free of legal jargon.
- End with a closing and signature block.
Output format A ready-to-send letter in markdown, 250 to 400 words. Use headings for What happened, What we are doing, What you can do, and Contact us. Tone: clear, factual, empathetic, no alarm. Leave out speculation, blame, and any admission of legal liability.
Guardrails
- Do not invent legal citations, article numbers, or regulatory deadlines.
- Flag any assumptions you make about the law or the breach.
- Tell the user to have the letter reviewed by legal counsel before sending.
Example Breach summary: unauthorised access to email server; date of breach: 2024-03-10; data categories: names, email addresses, hashed passwords; affected: 1,200 customers; applicable law: GDPR; jurisdiction: UK; company: Acme Ltd.