Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI cannot detect a personal data breach in your business.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe supplied commercial data gives no price for a specialist breach-detection service.
If this goes wrong, you miss a serious incident or mishandle notification and your business carries the resulting regulatory, financial and reputational consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open your incident register, relevant access logs, security alerts, data inventory, processor records and breach response policy, and gather only the material connected with the suspected event.
- Redact names, contact details, account identifiers, credentials and unnecessary personal data, then label each document with its source and time period.
- Paste the redacted material into a chatbot with the prompt above and ask it to keep confirmed facts separate from assumptions and unknowns.
- Compare the generated timeline and affected-data list against the original logs, alerts and records, correcting every unsupported claim and recording the evidence for each confirmed fact.
- Ask the relevant IT or security lead to confirm whether access, loss, alteration, disclosure or unavailability actually occurred and to preserve the underlying evidence.
- Send the corrected incident summary, evidence list and open questions to your data protection officer or a solicitor who handles UK data protection, and have them decide the legal classification and any required notification or communication.
Prompt
Act as an incident-triage assistant, not a solicitor or data protection officer. Analyse the redacted incident information below and do not invent facts. Separate confirmed facts, reasonable inferences and unknowns. Produce: 1) a concise incident timeline, 2) the systems, people and data potentially affected, 3) signs that personal data may have been accessed, lost, altered, disclosed or made unavailable, 4) the evidence still needed, 5) a list of containment actions for the relevant IT or security team, 6) questions for the system owner and processor, 7) a cautious assessment of whether this may be a personal data breach under UK GDPR, with the reasons and uncertainties, and 8) a checklist for a data protection officer or solicitor to decide whether notification or communication is required. Do not decide that no breach occurred merely because evidence is missing. Do not give a notification deadline, legal conclusion or advice unless it is checked against current official UK guidance. State clearly that the business remains responsible for the decision. This is not professional advice. Incident details: [PASTE REDACTED INCIDENT REPORT]. Relevant logs or alerts: [PASTE REDACTED LOG EXTRACTS]. Data inventory or records of processing: [PASTE REDACTED DESCRIPTION]. Breach response policy: [PASTE RELEVANT POLICY].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot see unauthorised activity that is absent from the records you provide or detect an incident across systems it cannot access.
- AI cannot establish the facts where logs are incomplete, contradictory or controlled by a processor or supplier.
- AI cannot make the accountable UK GDPR decision about notification or communication on behalf of your business.
- AI cannot carry the consequences of a missed breach, an incorrect assessment or an unsupported notification decision.
What makes this a NO: legal accountability, private data access and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 3 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT tell me if I have had a data breach?
- It can organise supplied evidence and flag signs of unauthorised access, loss, alteration, disclosure or unavailability. It cannot monitor your systems or take responsibility for deciding whether the event is a reportable UK GDPR breach.
- What should I give AI to check for a data breach?
- Give it a redacted incident report, relevant logs, security alerts, your data inventory, processor information and breach response policy. Do not paste passwords or unnecessary personal data, and confirm important facts against the original systems.
- Do I have to report a personal data breach?
- That depends on the facts, the likely risk to individuals and current UK GDPR requirements, so do not rely on an AI conclusion alone. This is not professional advice; ask your data protection officer or a solicitor who handles UK data protection to make or confirm the decision.
- Can AI handle a data breach for my business?
- AI can help assemble a timeline, identify missing evidence and draft an internal triage summary. It cannot gather every fact, contact affected people, make the accountable legal decision or replace your data protection officer or solicitor.
Nearby answers
- Can AI create UK GDPR training for my staff?PARTLY
- Can AI act as my business's data protection officer?NO
- Can AI check if my UK business needs a data protection officer?YES
- Can AI check my email marketing consent process under UK PECR?PARTLY
- Can AI create a personal data breach response plan?PARTLY
- Can AI decide whether my UK business needs a DPIA?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.