Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly report a data breach to the ICO.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
30 minutesto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe available tool data gives no price for a comparable breach-reporting service.
If this goes wrong, you can submit an incomplete or unjustified notification, mishandle sensitive information, or delay a decision for which your organisation remains accountable.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.
How to actually do it
- Open the current personal data breach reporting guidance and reporting route on the ICO website, and keep the page available for comparison.
- Open your incident record, investigation notes, access logs and relevant system reports, then make a redacted timeline with confirmed times, systems, data types, affected groups and containment actions.
- Remove unnecessary names, addresses, credentials, customer records and security secrets before pasting the timeline and organisation details into the prompt.
- Paste the redacted facts into the prompt and ask the model to separate confirmed facts, inferences and missing information before drafting anything.
- Compare every date, time, system, data category, affected-group description and containment action in the draft with the incident record, correcting or deleting anything unsupported.
- Compare the draft's questions and proposed answers with the current ICO reporting form and guidance, and record any point where the model could not establish the answer.
- Send the checked draft and evidence list to your data protection lead or other responsible professional, who must decide whether notification is required and submit the report through the ICO route if appropriate.
Prompt
Help me prepare, but not submit, a potential personal data breach notification to the UK Information Commissioner's Office. Use only the incident facts and documents I provide, and do not invent dates, times, people, systems, numbers, affected individuals, risk assessments or decisions. If you cannot access current ICO guidance, say so and identify what I must check on the ICO website. First separate confirmed facts, reasonable inferences and missing information. Then produce: 1) a short incident summary, 2) a list of information still needed, 3) a draft response organised by the questions in the current ICO reporting process, 4) a list of statements that need evidence, and 5) questions for our data protection lead. Do not decide that notification is or is not legally required unless that conclusion follows directly from current ICO guidance and the facts supplied. Flag every uncertainty. Do not include unnecessary personal data or special category data in the draft. Incident details: [paste a redacted factual timeline, evidence summary and internal notes here]. Organisation details: [organisation name, sector and contact role].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot access your logs, ticketing systems, backups or forensic evidence unless you provide approved extracts.
- AI cannot take responsibility for the notification decision, the accuracy of the report or any missed regulatory action.
- AI cannot reliably resolve uncertain facts about the breach, including what data was exposed or who was affected.
- AI cannot safely receive unredacted personal data, credentials or security material through an ordinary public chatbot.
- AI cannot submit the notification as your accountable organisation or replace your data protection lead's judgement.
What caps this at PARTLY: legal accountability, private data access and judgement under ambiguity.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI report a data breach to the ICO?
- Not by itself. AI can organise your evidence and draft answers, but your organisation must decide whether notification is required and submit an accurate report through the ICO's reporting route.
- What information do I need to report a data breach to the ICO?
- You normally need a factual account of what happened, when it happened, what personal data was involved, who may be affected, what harm is possible, and what you have done to contain and remedy the incident. Use your incident records and the current ICO reporting form to identify the exact fields, rather than asking AI to fill gaps.
- Is it safe to paste a data breach into ChatGPT?
- Do not paste unnecessary personal data, credentials, security secrets or unredacted incident evidence into an ordinary public chatbot. Use a redacted summary and follow your organisation's approved data handling rules before using AI.
- Do I need a solicitor or data protection specialist to report a breach?
- A data protection lead or DPO should handle the decision, and a data protection solicitor may be needed for a serious or disputed case. This is not professional advice, and AI should not replace the person who carries the organisation's legal accountability.
Nearby answers
- Can AI help me secure a business laptop?PARTLY
- Can AI help me secure cloud storage for my business?PARTLY
- Can AI check my business cybersecurity compliance with UK GDPR?NO
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI detect a data breach in my business?NO
- Can AI identify cybersecurity risks in my small business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.