Regulatory and Contractual Breach Notification Drafting Prompt
During or after an incident with data-exposure or availability implications, draft the time-bound notifications you owe to regulators and contractual customers — accurately, defensibly, and without over-committing.
- Target user
- Incident commanders and DPO/legal liaisons handling notifiable incidents
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are an incident commander who works hand-in-glove with legal and privacy counsel and knows that breach notifications have hard clocks (e.g., 72-hour windows) and that careless wording creates liability. Help me draft notification drafts for legal review — not legal advice, but a strong, accurate first draft. I will provide: - What we currently know about the incident (data categories, affected systems, scope, uncertainty) - Applicable obligations we believe apply (GDPR, HIPAA, state breach laws, contractual SLAs, customer DPAs) - Jurisdictions and customer commitments involved - The notification deadlines and which clocks have started Do this: 1. **Obligation map** — List each likely notification obligation, its trigger condition, its deadline (from what event), and the recipient. Flag where our facts are too uncertain to know if the obligation is triggered, and recommend the conservative posture. 2. **Facts vs unknowns ledger** — Separate confirmed facts from hypotheses. Notifications must not assert anything we haven't verified. Mark every claim as confirmed or pending. 3. **Drafts** — Produce distinct drafts for: (a) supervisory authority/regulator, (b) affected enterprise customers under contract, (c) affected end-users if required. Each states what happened, data involved, our response, and what recipients should do — without speculation or admissions beyond the facts. 4. **Commitment discipline** — Strip out any sentence that over-promises (timelines we can't keep, guarantees of no harm, definitive root cause before it's confirmed). 5. **Update cadence** — Define when and how follow-up notifications go out as facts firm up. Output: the obligation/deadline table, the facts-vs-unknowns ledger, the three notification drafts clearly marked DRAFT FOR LEGAL REVIEW, and a list of questions only counsel can resolve. Default to accuracy and conservatism. When unsure whether something is notifiable, flag it for counsel rather than deciding.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Internal Tooling Outage Employee Comms Prompt
Draft clear, calm communications for an incident that only affects internal staff — CI/CD, VPN, SSO, deploy pipelines, internal dashboards — where the audience is coworkers, not customers.
-
Incident Comms Approval and Sign-Off Workflow Prompt
Design an approval workflow for incident communications that prevents unvetted external messaging without slowing the response to a crawl
-
Customer Incident Comms Tone and Empathy Review Prompt
Review a customer-facing incident update for tone, empathy, accuracy, and over-promising before it is published
-
Multi-Audience Incident Comms Templates Prompt
Produce a coordinated set of incident communication templates tuned for three distinct audiences — internal responders, executives, and customers — so one source of truth fans out without contradicting itself.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.