Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly decide whether to report a data breach.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsNo price for a UK data-protection professional is provided in the supplied tool data.

If this goes wrong: your organisation misses a required notification or sends an inaccurate one, leaving it with the regulatory and operational consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open GOV.UK and find the current ICO guidance on personal data breaches, alongside your organisation's incident-response and data-protection policies.
    2. Create a factual incident timeline containing discovery time, containment actions, systems affected, data categories, approximate number of people affected and likely consequences, removing unnecessary personal identifiers.
    3. Ask the incident lead, IT team and relevant data owner for the missing facts, and record unknown or disputed points instead of filling them in.
    4. Paste the redacted facts, the relevant policy and the copyable prompt into a chatbot, then require citations to the current ICO pages it used.
    5. Compare every cited reporting requirement and timing point against the live ICO guidance and your own policy, correcting any unsupported statement in the draft.
    6. Send the decision matrix and incident record to your DPO, privacy lead or data-protection solicitor for the accountable decision, and follow the approved reporting route if they decide notification is required.
    7. Store the final decision, evidence, guidance links, decision-maker and reasons in the incident record, including why reporting was or was not chosen.

    Prompt

    Help me assess whether this personal data breach may need reporting in the UK. This is decision support only, not professional advice, and you must not make the final decision for my organisation.
    
    Use the current ICO guidance on personal data breaches, found through GOV.UK or the ICO website, as the primary source and cite the exact page or section for every important conclusion. If the guidance has changed, say so and use the current version. Do not invent facts, deadlines, thresholds or legal duties. Do not treat an absence of information as proof that no risk exists.
    
    First, list the facts that are known, unknown and disputed. Then identify the missing facts that could change the decision. Assess separately:
    1. the likelihood and seriousness of risk to people;
    2. whether notification to the ICO appears required;
    3. whether communication to affected people appears necessary;
    4. any relevant timing or record-keeping requirements in the current ICO guidance.
    
    Give me a short decision matrix with the evidence for and against each route: notify the ICO, notify affected people, notify neither, or obtain urgent specialist advice. Mark each conclusion as fact, guidance-based inference, or unresolved judgement. State clearly where a data-protection professional or our DPO must decide.
    
    Create a neutral incident decision record with these headings: incident summary, discovery time, containment, data involved, people affected, likely consequences, safeguards, risk assessment, guidance consulted, decision, decision-maker, reasons, actions, owner and review time.
    
    Incident facts:
    [Paste only the minimum necessary information, with names, addresses, account details and other unnecessary identifiers removed]
    
    Organisation policy or incident procedure:
    [Paste the relevant policy]
    
    Do not send, submit or contact anyone. Do not claim that a breach is reportable unless the evidence and current ICO guidance support that conclusion.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot establish the facts of an incident that your logs, suppliers or investigators have not yet confirmed.
  • AI cannot take accountability for the decision to notify the ICO or affected people.
  • AI cannot resolve ambiguous risk judgements where the consequences depend on context, safeguards and the people affected.
  • AI cannot replace your DPO, privacy lead or data-protection solicitor in a serious or disputed case.
  • AI can cite outdated or misread guidance, so a draft is not evidence that the current ICO position has been applied correctly.

What caps this at PARTLY: legal accountability, judgement under ambiguity and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability0
Effort delta1
Total4 / 10

FAQ

Can AI decide if I need to report a data breach?
Partly. AI can organise the facts, compare them with current ICO guidance and draft a decision record, but your organisation's accountable decision-maker must make the final call. This is not professional advice, and a serious or uncertain case needs your DPO, privacy lead or a data-protection solicitor.
How do I know if a data breach must be reported to the ICO?
You need to assess the likely risk to people's rights and freedoms using the current ICO guidance, the data involved, who was affected, the safeguards in place and the likely consequences. AI can structure that assessment, but it cannot reliably settle an ambiguous case or transfer responsibility for the decision.
Can ChatGPT report a data breach to the ICO for me?
No. A chatbot can help draft the information and questions for an ICO notification, but it cannot submit the report as your accountable organisation or confirm that the facts and legal assessment are correct. Have the draft checked and sent through your approved incident process.
Is it safe to paste a data breach into an AI chatbot?
Not if the material contains unnecessary personal, confidential or security-sensitive information. Redact identifiers, credentials, exploit details and anything not needed for the assessment, and follow your organisation's AI, confidentiality and incident-response policies before using an external service.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.