Home · Business · Operations & Logistics · SOPs & process docs

PARTLY

As of 13 August 2026, AI can only partly create a personal data breach response plan for a UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsTaskade is an AI outlining, tasks and team agents workspace that can help organise a response plan.

If this goes wrong: the business follows an incomplete process, delays a required response or mishandles personal data during the incident.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the business's current information security, incident management, privacy, retention and supplier policies, then remove live personal data and collect the relevant redacted text.
    2. Gather the current role titles, escalation contacts, key systems, processors, out-of-hours arrangements, backup arrangements and approved communication channels.
    3. Paste the redacted business details and policies into a chatbot with the copyable prompt, and ask it to create the plan without inventing missing facts.
    4. Export the draft into the business's SOP format, then replace every placeholder with a confirmed role, contact route, system or supplier detail.
    5. Compare the response process and notification decision record against current ICO guidance, the business's processor contracts, insurance terms and internal reporting requirements.
    6. Ask the data protection lead or a UK data protection solicitor to check the legal decision points, notification wording and handling of high-risk incidents.
    7. Run the proposed exercise scenario with the relevant staff, record where the process fails, and update the plan, contacts and incident log templates before approving it.

    Prompt

    Create a practical personal data breach response plan for a UK business.
    
    Business type: [business type]
    Business size and locations: [details]
    Data held: [categories of personal data, using redacted descriptions only]
    Main systems and suppliers: [systems, cloud services and processors]
    Incident reporting route: [email address, phone number or ticketing route]
    People and roles: [named role titles, not unnecessary personal data]
    Existing policies: [paste relevant redacted policy text]
    Working hours and out-of-hours arrangements: [details]
    
    Produce:
    1. A short purpose and scope section.
    2. A numbered response process from initial report through closure.
    3. A responsibility table covering the incident lead, IT or security, data protection lead, communications, senior management and any processor.
    4. Immediate containment and evidence-preservation actions.
    5. A fact-gathering checklist that does not ask staff to paste live personal data into this chat.
    6. A decision record for assessing risk to individuals and whether regulatory or individual notification may be required. Do not decide that a notification is legally required without stating the facts still needed and the point that must be escalated.
    7. Draft internal, processor, regulator and affected-person communication templates with clearly marked placeholders.
    8. An incident log, decision log and post-incident review checklist.
    9. A short exercise scenario for testing the plan.
    
    Use plain UK English. Separate confirmed facts from assumptions and open questions. Do not invent contacts, systems, deadlines or legal conclusions. Flag every item that needs checking against current ICO guidance, the business's contracts and its insurance requirements. This is not professional advice. State clearly where a serious case needs a UK data protection solicitor or other qualified data protection professional. Format the result so it can be copied into an internal SOP.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot know which systems, processors, contacts and approval routes are actually current inside the business.
  • AI cannot take responsibility for deciding whether the facts create a legal notification duty or risk to individuals.
  • AI cannot preserve evidence, contain an account, investigate logs or contact a supplier during a live incident.
  • AI cannot replace a data protection professional's judgement on a serious or unusual breach.
  • AI does not prove that staff can follow the plan under time pressure; the business still has to exercise it.

What caps this at PARTLY: legal accountability, regulated advice and verification cost.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta2
Total6 / 10

FAQ

Can ChatGPT write a data breach response plan?
Yes, it can draft the structure, action lists, roles, logs and communication templates. It cannot know your live systems or take responsibility for the legal decisions, so a data protection lead or solicitor should check the finished plan.
What should a UK business do after a personal data breach?
Record the incident, contain it, preserve evidence, establish what happened and assess the risk to people using the business's approved process. Check the current ICO guidance and escalate a serious case to a UK data protection solicitor or qualified data protection professional.
Can AI decide whether I need to report a data breach?
No. AI can organise the facts and produce a decision record, but it cannot safely make the accountable legal decision from incomplete or changing incident information. This is not professional advice.
Is it safe to put breach details into an AI chatbot?
Do not paste unnecessary personal data, credentials, confidential investigation material or unredacted incident records into a general chatbot. Use redacted information, follow your business's approved AI and data handling policy, and obtain specialist advice before using an external service for sensitive material.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.