Data Privacy Incident Response Notification Script
Author a high-stakes, regulatory-compliant email disclosure script for data privacy notifications.
Use this template when technical or security incidents require immediate, transparent, and legally mandated email notices to affected users and internal stakeholders.
Role: Lead Data Privacy & Regulatory Compliance Counsel specialized in incident disclosure, GDPR/CCPA enforcement, and technical crisis communication.
Context
- Regulatory Framework: {{jurisdiction_framework}}
- Scope of Exposure: {{incident_scope}}
- Impacted Audience: {{affected_user_cohort}}
- Remediation Measures: {{mitigation_actions}}
- Regulatory Notice Window: {{statutory_deadline}}
- Privacy Office Contact: {{dpo_contact_channel}}
Task
Construct an end-to-end, multi-tier operational email notification script that informs {{affected_user_cohort}} of {{incident_scope}}, satisfies {{jurisdiction_framework}} compliance standards, and provides immediate protective workflows before {{statutory_deadline}}.
Method
- Define mandatory statutory disclosures required by {{jurisdiction_framework}} for external notifications.
- Frame the incident timeline concisely, articulating exactly what happened without speculative language.
- Enumerate the data fields involved according to {{incident_scope}} using clear, bulleted syntax.
- Detail the immediate technical remediation and containment steps implemented through {{mitigation_actions}}.
- Provide explicit, step-by-step security guidance tailored specifically to {{affected_user_cohort}}.
- Detail zero-cost protection tools provided (e.g., credit monitoring, credential reset workflows).
- Integrate direct, verifiable inquiry mechanisms linking to {{dpo_contact_channel}}.
- Formulate internal team escalation boilerplate for handling inbound customer replies.
Constraints
- MUST adhere strictly to the disclosure obligations established by {{jurisdiction_framework}}.
- MUST NOT speculate on threat actor attribution or liability outside verified facts.
- Ensure the notification language is accessible to non-technical users while remaining legally bulletproof.
- Limit main notification body to under 400 words to ensure complete readership during critical advisories.
Output format
Provide the complete communication framework arranged in these exact components:
- Incident Email Subject & Metadata (Subject Lines, Sender Alias, Header Security Flags)
- Primary User Notification Script (Summary, What Occurred, Data Involved, What We Did, Steps You Should Take)
- Internal Customer Support Response Script (Standardized reply macros for high-anxiety inbound inquiries)
Self-review
- Confirm that all 6 variables are accurately integrated without technical ambiguity.
- Validate that mitigation instructions match {{mitigation_actions}} directly.
- Check that the notification meets the transparency thresholds mandated by {{statutory_deadline}}.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.