Home · Business · Legal & Compliance · Data protection & GDPR

PARTLY

As of 13 August 2026, AI can only partly draft an ICO data breach notification.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

30 minutesto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsNo price is supplied in the available tool data for a specialist alternative.

If this goes wrong: your organisation submits an incomplete or inaccurate notification, misses the relevant reporting deadline or misjudges the risk to individuals.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.

    How to actually do it

    1. Open the current ICO personal data breach reporting guidance and notification form, and save the sections that describe the information the form asks for.
    2. Gather the incident report, security logs, discovery and containment timeline, processor communications, data inventory and records of affected people and data categories.
    3. Remove unnecessary personal data, credentials and confidential contents from those records, then separate confirmed facts from estimates and unresolved questions.
    4. Paste the prompt and the cleaned facts into a chatbot, including the ICO guidance or form text so the draft can be compared with the current source.
    5. Compare each drafted answer with the incident records and ICO form, replacing unsupported estimates with [MISSING] and checking every time, count, data category and contact detail.
    6. Send the draft and unresolved questions to your DPO or a data protection solicitor for the notification decision, risk assessment and approval before anyone submits it to the ICO.
    7. If approval is given, paste the checked answers into the ICO reporting form and retain the evidence, review decisions and submitted version in the incident file.

    Prompt

    Draft a UK GDPR personal data breach notification for the ICO using only the information supplied below and the current ICO guidance or form text I provide. Do not invent, infer or fill gaps with assumptions. Mark every missing fact as [MISSING] and list the exact evidence needed to resolve it.
    
    First, produce a short incident summary. Then draft the notification in the same order as the ICO form, covering:
    - the controller's name, contact details and data protection contact
    - what happened and when it was discovered
    - the categories and approximate number of affected individuals
    - the categories and approximate volume of personal data involved
    - the likely consequences for individuals
    - the measures already taken and planned to contain, remedy and reduce harm
    - whether affected individuals have been or will be informed
    - the reason for any delay or decision not to notify, if relevant
    
    Separate confirmed facts, reported facts and unresolved questions. Do not decide that notification is or is not legally required. Instead, identify the facts that affect that decision and flag any point for review by our DPO or a data protection solicitor. Do not include unnecessary personal data, names, addresses, passwords, access tokens or full records. Use plain UK English and keep the draft suitable for pasting into the ICO reporting form.
    
    Organisation details:
    [ORGANISATION AND CONTACT DETAILS]
    
    Incident facts and timeline:
    [INCIDENT RECORDS, DISCOVERY TIME, CONTAINMENT ACTIONS AND CURRENT STATUS]
    
    Affected people and data:
    [CATEGORIES AND APPROXIMATE COUNTS, WITH SOURCES]
    
    Risk assessment and communications:
    [KNOWN OR SUSPECTED CONSEQUENCES, SUPPORT OFFERED AND COMMUNICATIONS]
    
    ICO guidance or form text:
    [PASTE CURRENT SOURCE MATERIAL HERE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot investigate logs, interview staff or establish the true scope of a breach.
  • AI cannot make the organisation's notification decision or carry responsibility for the deadline and accuracy.
  • AI cannot reliably assess the seriousness of harm to affected individuals where evidence is incomplete or changing.
  • AI cannot replace a DPO or data protection solicitor when the breach involves serious risk, disputed facts or difficult legal judgement.

What caps this at PARTLY: legal accountability, verification cost and real time truth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT draft an ICO data breach notification?
Yes, it can produce a structured first draft from your incident facts and the ICO form fields. It cannot investigate the breach, decide whether notification is required or take responsibility for what your organisation submits.
Do I need a solicitor to report a data breach to the ICO?
Not every notification needs a solicitor, but a DPO or data protection solicitor should review a serious, uncertain or high-risk case. The organisation remains accountable for the decision and the information sent to the ICO.
What information does AI need to draft an ICO breach notification?
Give it the incident timeline, discovery and containment details, affected people and data categories, approximate numbers, likely consequences, mitigation and contact details. Supply evidence for each fact and do not paste unnecessary personal data, credentials or full records.
Is it safe to use AI for an ICO data breach notification?
It is suitable for organising a redacted set of facts into a draft, not for making the legal or risk assessment. This is not professional advice, and a serious case needs review by your DPO or a data protection solicitor before submission.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.