Data Breach Notification Letter Generator
The authority notice, the letter to the people affected and the record, from your facts.
Free preview.
- Free preview: every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”.
- Locked until you unlock it: download, copy and print.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Data Breach Notification Letter Generator
When personal data is lost, stolen, exposed or locked away, the clock starts the moment you become aware of it. Enter the facts once — what happened, when, the data and the people involved, the likely consequences and what you are doing — and the generator writes every notice the laws you tick can require: the notification to the supervisory authority under GDPR Article 33, the plain-language notice to the people affected under Article 34, the report to the UK’s Information Commissioner, India’s intimations to the Data Protection Board and to each affected Data Principal under rule 7 of the DPDP Rules, a general notice for other countries — and the incident record that Article 33(5) asks you to keep, with a timeline of what was known when and the reasons for your decisions.
The checks flag what is missing before you send: the contact point, the reasons for a notification later than 72 hours, a high risk with no notice to the people affected, dates in the wrong order. The free preview shows every page as marked images, with your own facts and the first part of the wording readable; the DOCX, PDF, text file, copying and printing need a Premium pass. Nothing you type leaves your browser.
How to use it
- Tick the laws that apply — the GDPR, the UK GDPR, India’s DPDP Rules, another country — and the documents you need. Choose under Make whether to make them all in one file or one at a time.
- Enter your organisation and the contact point people and the authority can ask — usually your data protection officer — and, for the GDPR, the supervisory authority you notify.
- Describe what happened, when — when it began, when it was discovered and when you became aware — the data and the people, your risk assessment and why you made it, the likely consequences and what you have done and will do. Date the notices: only a dated notification says it is made within 72 hours.
- Add the timeline of what was known and done, read the Checks, and fix anything marked “Fix”.
- With a Premium pass, use Download DOCX or Download PDF and send each notice the way its recipient asks — many authorities, the ICO included, take them through an online form; without one, the page shows the free preview.
Examples
Online shop · backup bucket publicly readable for six days · about 18,400 customers · names, contact details and order histories · became aware 14 June 2027 at 19:30 · high risk
An Article 33 notification to the supervisory authority with the nature, the categories and approximate numbers, the contact point, the likely consequences and the measures, made “within 72 hours of that time”; a plain-language notice to the customers with advice on phishing; and an incident record with the timeline and the deadline (17 June 2027 at 19:30).
Became aware on 14 June 2027 · the notice goes out six days later
The check stops the export until the reasons for the delay are given; the notification then states them, as Article 33(1) requires.
DPDP ticked · ransomware on the order system · about 2,300 Data Principals
The intimation to the Data Protection Board (nature, extent, timing, location, likely impact), the detailed report with the six items of rule 7(2)(b), and the intimation to each Data Principal with the safety measures they can take and a contact.
Common uses
- Privacy and security teams under the 72-hour clock, who need the authority notice and the customer letter at the same time.
- Small businesses and charities without an in-house lawyer, working from the incident facts.
- Organisations with customers in the EU, the UK and India, who must notify under several laws at once.
- Keeping the record of every breach — including those that need no notification — that Article 33(5) requires.
What the GDPR asks for
- The supervisory authority (Article 33): without undue delay and, where feasible, within 72 hours of becoming aware — unless the breach is unlikely to result in a risk to people. A later notification gives the reasons for the delay. It describes the nature of the breach with the categories and approximate numbers of people and of records, the contact point (the data protection officer), the likely consequences and the measures taken or proposed. Information you do not have yet can follow in phases (Article 33(4)).
- The people affected (Article 34): without undue delay when the breach is likely to result in a high risk, in clear and plain language, with the contact point, the likely consequences and the measures. It is not needed when the data was unintelligible to others (for example encrypted with a safe key), when later measures mean the high risk is no longer likely, or when individual notices would take disproportionate effort — then a public communication instead.
- The record (Article 33(5)): every breach, notified or not, with its facts, effects and remedial action.
You become aware when you are reasonably sure that a security incident has compromised personal data. A controller outside the EU, with no lead authority, notifies the authority of every Member State where affected people live (EDPB Guidelines 9/2022).
The UK GDPR and the ICO
The same rules apply under the UK GDPR, with the Information Commissioner’s Office as the authority. The ICO takes reports through its online form, within 72 hours where feasible, and asks organisations to report early and update later when the picture is still incomplete. The report this tool writes holds the answers the form asks for — what happened, when and how you found out, who is affected, what you are doing and who to contact — and stays with your record.
India: rule 7 of the DPDP Rules
Under section 8(6) of the DPDP Act and rule 7 of the DPDP Rules (applicable from 13 May 2027), every personal data breach — there is no “unlikely to result in a risk” exception — is intimated:
- to each affected Data Principal, without delay, through her user account or the contact she registered: what happened, with its nature, extent and timing; the consequences relevant to her; the measures taken; the safety measures she can take; and a business contact;
- to the Data Protection Board, without delay: the nature, extent, timing and location of the breach and its likely impact;
- to the Board again within 72 hours, or a longer period it allows on a written request: updated and detailed information, the facts and reasons that led to it, the measures to mitigate risk, findings about who caused it, the remedial measures against recurrence and a report on the intimations to Data Principals.
A data breach is also a cyber incident to report to CERT-In within six hours (CERT-In Directions, direction (ii) and Annexure I).
Other countries and US states
Many countries and US states have their own breach rules — who must be told, what the notice says and the deadline, often with a regulator or attorney general to inform as well. The general notice uses the headings most of them expect (what happened, what information was involved, what we are doing, what you can do, how to contact us): adapt it to the law of each place where affected people live.
Limitations
- A generic template, not legal advice. Whether a breach must be notified, and to whom, depends on the facts, your contracts and the law of every place affected people live — have a lawyer review the notices before you send them.
- It writes the notices; it does not send them or submit an authority’s online form.
- The 72 hours are counted on the clock you enter, without daylight-saving changes. For exact deadlines in any time zone, use the Breach Notification Deadline Calculator.
- Sector rules can add duties and shorter deadlines — NIS2, health, telecoms and financial regulators, CERT-In — and are not written here.
Privacy
Everything you type stays in your browser and is never uploaded or stored by MySmartCoPilot. If you tick Keep a draft in this browser, the form is saved in this browser’s local storage until you untick it — leave it off on a shared computer.
Frequently asked questions
What do I get without a pass?
Without a pass, Data Breach Notification Letter Generator shows every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded, copied or printed. A Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
How long do I have to report a data breach?
Under the GDPR and the UK GDPR, without undue delay and where feasible within 72 hours of becoming aware of it; later, with the reasons for the delay. Under India’s DPDP Rules, the Board is told without delay and gets a detailed report within 72 hours, unless it allows longer. People affected are told without undue delay (GDPR, when the risk is high) or without delay (DPDP, every breach).
Do I have to tell the people affected?
Under the GDPR, when the breach is likely to result in a high risk to them — unless the data was unintelligible to others, later measures removed the high risk, or individual notices would take disproportionate effort (then a public notice). Under the DPDP Rules, every affected Data Principal is told. The notice says what happened, what it may mean for them, what you are doing, what they can do and who to contact.
What if I do not have all the facts within 72 hours?
Notify anyway with what you know, say it is a first notification and send the rest in phases without undue further delay (Article 33(4)). The ICO calls this reporting early and updating later. Tick “this is a first notice” and the notification says so.
What should the incident record contain?
The facts of the breach, its effects and the remedial action taken (Article 33(5)), and in practice the timeline of what was known when, your risk assessment and why you did or did not notify. Keep one for every breach, including those you were not required to report.
Do I need a pass?
To download the DOCX or PDF, copy the text or print, yes: a Premium pass unlocks every Premium tool. Without a pass you see a free preview of your own documents: every page as marked images, with your facts and the first part of the wording readable.
Is what I type uploaded?
No. The notices are put together in your browser; nothing about the incident is sent anywhere or stored by MySmartCoPilot.