The Clock Starts the Moment You Discover a Breach
When a data breach is discovered, the pressure to communicate quickly collides with the need to communicate accurately โ and legal counsel usually isn't available to draft a first version within the first few hours. Having a solid template ready before an incident happens means you can move from "we think something happened" to "here is our draft notice, ready for legal review" in minutes rather than days, which matters because many breach notification laws attach real deadlines to how fast you must notify.
Why Timing Matters
Under the EU General Data Protection Regulation (GDPR), Article 33 generally requires notifying the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Article 34 separately requires notifying the affected individuals directly, without undue delay, when the breach is likely to result in a high risk to their rights and freedoms. Outside the EU, most U.S. states have their own breach notification statutes with their own timing language โ commonly phrased as "without unreasonable delay" โ plus sector-specific rules for healthcare (HIPAA), financial services (GLBA), and others. None of this is optional once a breach meeting the relevant threshold has occurred.
The Standard Elements of a Notification Letter
Regardless of jurisdiction, a well-structured breach notice generally covers the same core sections:
- What Happened โ a plain-language description of the incident: what occurred, when it was discovered, and how it was discovered.
- What Information Was Involved โ the specific categories of personal data exposed (names, emails, passwords, SSNs, financial data, health data, etc.) rather than a vague reference to "some information."
- What We Are Doing โ concrete remediation: forced password resets, credit monitoring offers, enhanced security measures, law enforcement engagement, and whether there's evidence of actual misuse.
- What You Can Do โ specific, actionable guidance for the recipient: monitoring statements, placing a fraud alert or credit freeze, changing reused passwords, enabling MFA.
- How to Get More Information โ a real contact channel, ideally a dedicated hotline or email, not a generic "no-reply" address.
Common Mistakes That Make Notices Worse
- Vague data-type language. "Some of your information may have been affected" tells the recipient nothing actionable. Naming the specific categories lets them take the right protective steps.
- Burying the remediation offer. If you're offering free credit monitoring, say so clearly, including duration and how to enroll โ don't make people hunt for it.
- Legalistic tone with no empathy. A notice that reads like pure liability-management, with no acknowledgment of impact on the reader, tends to increase reputational damage rather than reduce it.
- Skipping legal review because "time is short." A template gets you a fast first draft, but the specific facts of your incident, your industry, and your jurisdiction(s) still require sign-off from qualified counsel before anything goes out.
It's Not Just the Individuals โ Think About Who Else Needs a Notice
A single incident often triggers more than one notification obligation, and it's easy to focus only on the individual-facing letter and forget the others. Depending on the facts, you may also need to notify: the relevant data protection or privacy regulator (e.g. under GDPR Article 33, or a state Attorney General under many U.S. state laws), your cyber insurance carrier (often within a strict policy deadline, sometimes before you've even finished your investigation), business partners or customers whose data flows through your systems under a contract, and payment processors if payment card data was involved. Each of these may have its own required content and timing, which is why a single "master" incident timeline โ capturing discovery date, containment date, and scope determination โ is worth maintaining alongside the individual notification letter itself.
Prepare the Template Before You Need It
The organizations that handle breach communication well are almost always the ones that had a notification template, a remediation playbook, and a legal review process worked out before an incident, not during one. Building that starting point now โ and updating it as your remediation offerings and legal guidance evolve โ turns a chaotic first 24 hours into a much more manageable process. Pair the letter with an internal checklist: who needs to sign off, which regulators and partners need parallel notices, and how remediation offers (credit monitoring duration, hotline staffing) will actually be fulfilled once the letter goes out โ a notice that promises support your team isn't ready to deliver creates a second problem on top of the breach itself.