NO

As of 13 August 2026, AI cannot decide whether to report a data breach to the ICO.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

n/ait cannot be self-verified.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsThe supplied tool information gives no price for a solicitor or data-protection professional to assess the breach.

If this goes wrong: your organisation misses a reportable breach or reports inaccurately, leaving it responsible for the regulatory and legal consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface gets you a draft, but you cannot verify it yourself. That is the catch.

    How to actually do it

    1. Open the ICO personal-data-breach guidance and your organisation's incident-response policy, and start an incident record.
    2. Gather the discovery time, suspected occurrence time, systems involved, data categories, affected people, access or disclosure evidence, containment actions and likely consequences.
    3. Remove unnecessary names and identifiers, then paste the factual incident record into the prompt and label every unknown item as unknown.
    4. Ask the chatbot to separate confirmed facts, assumptions, missing evidence and the relevant ICO reporting tests, with a source for each legal proposition.
    5. Compare every cited proposition and deadline against the current ICO guidance, and correct the incident facts against system logs, access records and the incident team’s evidence.
    6. Send the structured assessment and unresolved questions to your data-protection officer, solicitor or other qualified UK data-protection professional for the reporting decision.
    7. Record the decision, reasons, evidence, approval and timing in the incident register, then make any required ICO notification through the official ICO process.

    Prompt

    Act as a UK data-protection triage assistant, not the final decision-maker. Using the current official ICO guidance and UK GDPR principles available to you, analyse this suspected personal-data breach and produce: 1. a factual incident summary; 2. the facts that are still missing; 3. the relevant reporting tests and how each known fact bears on them; 4. arguments for and against notifying the ICO; 5. the questions a data-protection professional must answer; 6. the information needed for an ICO notification if notification is required; and 7. a clear provisional recommendation labelled 'not a legal conclusion'. Do not invent facts, thresholds, dates or affected-person numbers. Distinguish confirmed facts from assumptions, cite or name the official ICO source for each legal proposition, flag any uncertainty, and say when urgent escalation is needed. Do not decide that notification is unnecessary solely because the breach has been contained.
    
    Incident details:
    Organisation: [organisation name and sector]
    Date and time discovered: [date and time]
    Date and time the breach occurred or may have occurred: [date and time or unknown]
    What happened: [description]
    Personal data involved: [data types]
    Number and types of people affected: [details or unknown]
    Whether special-category or criminal-offence data was involved: [details or unknown]
    How the data was accessed, lost, altered or disclosed: [details]
    Likely consequences: [details]
    Containment and recovery steps: [details]
    Evidence available: [logs, messages, reports or other evidence]
    Current reporting deadline position: [what is known]
    
    Do not include unnecessary personal data. End by listing the exact points that must be checked against the ICO before any decision is recorded or notification is sent.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What makes this a NO: legal accountability, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification0
Liability0
Effort delta1
Total3 / 10

FAQ

Can ChatGPT tell me if I need to report a data breach to the ICO?
It can organise the facts and compare them with ICO guidance, but it should not make the final decision for you. Your organisation remains accountable, so a data-protection professional should decide an uncertain or serious case.
What data breach has to be reported to the ICO?
A personal-data breach must be reported where the UK GDPR reporting test is met, rather than simply because data was lost or exposed. Check the current ICO guidance against the type of data, the people affected, the likely consequences and the evidence available.
How long do I have to report a data breach to the ICO?
The UK GDPR sets a time limit for notifying the ICO where notification is required, so record when the breach was discovered and escalate immediately. Confirm the current deadline and any late-notification explanation against the ICO guidance before sending anything.
Is it safe to use AI to assess a data breach?
Use it to structure facts, identify missing evidence and prepare questions, not as the final decision-maker. This is not professional advice, and a solicitor or qualified data-protection professional should carry the risk in a serious or uncertain case.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.