As of 13 August 2026, AI cannot decide whether to report a data breach to the ICO.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe supplied tool information gives no price for a solicitor or data-protection professional to assess the breach.
If this goes wrong: your organisation misses a reportable breach or reports inaccurately, leaving it responsible for the regulatory and legal consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open the ICO personal-data-breach guidance and your organisation's incident-response policy, and start an incident record.
- Gather the discovery time, suspected occurrence time, systems involved, data categories, affected people, access or disclosure evidence, containment actions and likely consequences.
- Remove unnecessary names and identifiers, then paste the factual incident record into the prompt and label every unknown item as unknown.
- Ask the chatbot to separate confirmed facts, assumptions, missing evidence and the relevant ICO reporting tests, with a source for each legal proposition.
- Compare every cited proposition and deadline against the current ICO guidance, and correct the incident facts against system logs, access records and the incident team’s evidence.
- Send the structured assessment and unresolved questions to your data-protection officer, solicitor or other qualified UK data-protection professional for the reporting decision.
- Record the decision, reasons, evidence, approval and timing in the incident register, then make any required ICO notification through the official ICO process.
Prompt
Act as a UK data-protection triage assistant, not the final decision-maker. Using the current official ICO guidance and UK GDPR principles available to you, analyse this suspected personal-data breach and produce: 1. a factual incident summary; 2. the facts that are still missing; 3. the relevant reporting tests and how each known fact bears on them; 4. arguments for and against notifying the ICO; 5. the questions a data-protection professional must answer; 6. the information needed for an ICO notification if notification is required; and 7. a clear provisional recommendation labelled 'not a legal conclusion'. Do not invent facts, thresholds, dates or affected-person numbers. Distinguish confirmed facts from assumptions, cite or name the official ICO source for each legal proposition, flag any uncertainty, and say when urgent escalation is needed. Do not decide that notification is unnecessary solely because the breach has been contained. Incident details: Organisation: [organisation name and sector] Date and time discovered: [date and time] Date and time the breach occurred or may have occurred: [date and time or unknown] What happened: [description] Personal data involved: [data types] Number and types of people affected: [details or unknown] Whether special-category or criminal-offence data was involved: [details or unknown] How the data was accessed, lost, altered or disclosed: [details] Likely consequences: [details] Containment and recovery steps: [details] Evidence available: [logs, messages, reports or other evidence] Current reporting deadline position: [what is known] Do not include unnecessary personal data. End by listing the exact points that must be checked against the ICO before any decision is recorded or notification is sent.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot establish what actually happened when logs, forensic evidence or staff accounts conflict.
- AI cannot take accountability for deciding whether the breach is likely to result in a risk to people's rights and freedoms.
- AI cannot replace a data-protection professional's judgement where the data, harm or scope of the breach is ambiguous.
- AI can cite outdated or misapplied guidance, and the error may not be visible to someone without specialist knowledge.
What makes this a NO: legal accountability, verification cost and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 3 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT tell me if I need to report a data breach to the ICO?
- It can organise the facts and compare them with ICO guidance, but it should not make the final decision for you. Your organisation remains accountable, so a data-protection professional should decide an uncertain or serious case.
- What data breach has to be reported to the ICO?
- A personal-data breach must be reported where the UK GDPR reporting test is met, rather than simply because data was lost or exposed. Check the current ICO guidance against the type of data, the people affected, the likely consequences and the evidence available.
- How long do I have to report a data breach to the ICO?
- The UK GDPR sets a time limit for notifying the ICO where notification is required, so record when the breach was discovered and escalate immediately. Confirm the current deadline and any late-notification explanation against the ICO guidance before sending anything.
- Is it safe to use AI to assess a data breach?
- Use it to structure facts, identify missing evidence and prepare questions, not as the final decision-maker. This is not professional advice, and a solicitor or qualified data-protection professional should carry the risk in a serious or uncertain case.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.