Home · Business · Legal & Compliance · Terms & policies

PARTLY

As of 13 August 2026, AI can only partly draft a data breach notification for your UK business.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsNo priced professional alternative is listed in the supplied tool data.

If this goes wrong, you may submit an inaccurate or late notification, omit affected people or disclose information improperly, and leave the business responsible for the result.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the current ICO guidance on personal data breaches and note the reporting test, applicable reporting window, required information and guidance on communicating with affected people.
    2. Create an incident note containing only confirmed facts, including when the incident was discovered, what happened, the systems and data involved, the people affected, containment actions and the person responsible for the response.
    3. Remove unnecessary names, contact details, credentials and other personal data from the note, then paste the redacted facts into the prompt.
    4. Ask the model to separate confirmed facts from assumptions and missing information before drafting either an ICO notification or a message to affected individuals.
    5. Compare every date, number, affected group, data category, risk statement and remedial action in the draft with the incident record, and replace unsupported text with [CONFIRM].
    6. Compare the draft's reportability reasoning and required fields with the current ICO guidance, then ask your DPO, solicitor or data protection specialist to confirm the decision and wording.
    7. Send the approved notification through the appropriate official ICO channel and retain the incident record, decision, draft, approval and submission evidence.

    Prompt

    Draft a UK data breach notification using the incident facts below. Treat the draft as a working document, not a decision that the breach is reportable. First separate confirmed facts, reasonable assumptions and missing information. Then provide: (1) the facts and decisions needed before submission, (2) a draft notification to the ICO if the facts support one, and (3) a separate draft message for affected individuals only if that is appropriate. Check the current ICO guidance and identify the applicable reporting window, without inventing a deadline or any missing fact. Explain plainly why the incident may or may not require notification, what categories of personal data and people are involved, the likely risks, the measures already taken, and the measures planned. Use clear UK English. Do not name a person, organisation, number, date, affected group or security measure unless it appears in the facts below. Mark every gap as [CONFIRM]. Do not include special-category data or unnecessary personal data in the draft. End with a short list of points that a UK solicitor or data protection specialist should confirm before anything is sent. Incident facts: [PASTE YOUR FACTS HERE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot establish the underlying facts of the incident or decide whether your evidence is reliable.
  • AI cannot take responsibility for the reportability decision, deadline or information you disclose.
  • AI cannot resolve ambiguous risk assessments without access to your systems, contracts, policies and investigation.
  • AI cannot replace a solicitor or data protection specialist when the breach is serious, disputed or likely to cause significant harm.

What caps this at PARTLY: legal accountability, judgement under ambiguity and verification cost.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta2
Total6 / 10

FAQ

Can AI write a data breach notification?
Yes, it can turn your incident notes into a draft for the ICO or affected individuals. It cannot decide whether notification is required or take responsibility for an inaccurate, late or inappropriate submission.
Can I use ChatGPT to report a data breach to the ICO?
You can use it to organise facts and prepare wording, but do not treat its draft as the reportability decision. Check it against current ICO guidance and have a solicitor, DPO or data protection specialist confirm a serious case before sending.
What information do I need for a UK data breach notification?
You need a reliable account of what happened, when it was discovered, what personal data and people are affected, the likely risks, and the containment and remedial actions. Use the current ICO guidance to confirm the required details for your incident rather than relying on a model's list.
Is using AI for a data breach notification safe?
It can expose confidential incident information and produce wording that is wrong or unnecessarily revealing, so redact personal data before pasting anything into a chatbot. This is not professional advice, and a serious case needs review by a solicitor, DPO or data protection specialist.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.