Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI can only partly assess the severity of a personal data breach.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsNo price for a breach-assessment service is provided in the available tool data.
If this goes wrong, your organisation may make the wrong notification decision, leave affected people unprotected or create a poor record for later scrutiny.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the current ICO guidance on personal data breaches and your organisation's incident-response policy.
- Gather the incident timeline, categories and approximate volume of data, people affected, security controls, discovery method, containment actions and evidence of possible harm.
- Remove unnecessary personal data and paste the remaining facts and the relevant guidance into the prompt.
- Ask the model to produce the structured assessment, keeping confirmed facts, inferences and unknowns separate.
- Compare every stated fact and proposed route with the incident records, current ICO guidance and internal policy, correcting any unsupported statement.
- Send the assessment, evidence gaps and draft decision log to your DPO or a solicitor for the accountable decision, then record the decision and actions in the breach register.
Prompt
You are helping prepare an internal UK GDPR personal data breach assessment. This is not professional advice. Use only the facts and source material I provide, and do not invent missing details. Separate confirmed facts, reasonable inferences and unknowns. Assess the likely risk to individuals by considering the type and sensitivity of the personal data, the people affected, the number of records, the ease of identification, the circumstances of the breach, the likely consequences and the safeguards in place. Explain which facts support each conclusion and list the questions still requiring answers. Compare the facts with the current ICO guidance I provide or quote, and identify whether the evidence appears to support recording the breach, considering notification to the ICO, or considering communication to affected individuals. Do not make the final legal or organisational decision, and do not state a deadline or requirement unless it is supported by the supplied current guidance. Produce: 1) an incident summary, 2) a risk assessment, 3) unknowns and evidence gaps, 4) possible response routes with reasons, 5) a draft decision log for review by our DPO or solicitor, and 6) a short list of immediate actions. Incident facts: [PASTE FACTS HERE]. Current ICO guidance or internal policy: [PASTE SOURCE HERE].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover facts that your incident records, logs or staff interviews do not contain.
- AI cannot reliably resolve ambiguous evidence about the likelihood or seriousness of harm to individuals.
- AI cannot take responsibility for deciding whether your organisation should notify the ICO or affected people.
- AI cannot replace a DPO or solicitor when the breach is serious, disputed or likely to attract regulatory scrutiny.
What caps this at PARTLY: legal accountability, judgement under ambiguity and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 5 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT assess the severity of a data breach?
- It can organise the incident facts, apply a supplied UK GDPR framework and draft a risk assessment. It cannot take responsibility for the final notification decision, so your DPO or a solicitor should check a serious case.
- How do I know if a data breach is serious?
- Look at the type and sensitivity of the data, who was affected, how easily people could be identified, what harm could result and what safeguards were in place. Use current ICO guidance and your evidence, rather than accepting an AI conclusion on its own.
- Can AI tell me whether to report a data breach to the ICO?
- AI can set out the facts and explain which parts of the current ICO guidance appear relevant. It should not make the accountable decision for your organisation, and a serious case needs review by your DPO or a solicitor.
- Is it safe to put a data breach into an AI chatbot?
- Only use a service approved by your organisation and minimise or redact personal data before sharing anything. Check its data-handling terms and internal policy, because uploading the incident can create a separate confidentiality and privacy risk.
Nearby answers
- Can AI check if my UK business needs a data protection officer?YES
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI create a cookie consent banner for my website?PARTLY
- Can AI create a UK GDPR compliance checklist for my small business?PARTLY
- Can AI help me handle a UK GDPR subject access request?PARTLY
- Can AI write a GDPR-compliant data protection clause for a UK contract?NO
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.