Data Breach Notification Decision Memo
In the first days of an incident, once forensics has preliminary findings, to organize the facts and structure the jurisdiction-by-jurisdiction notification decision.
When an incident hits, legal has to answer a deceptively simple question under time pressure: who must be told, and by when? The answer turns on facts that are still emerging, such as which data elements were involved, whether they were encrypted, whether anyone actually accessed them, and where the affected people live, and on statutes that differ by jurisdiction in definitions, exceptions and timing.
This prompt keeps the forensic facts and the affected-data inventory in separate tags, then asks for a decision memo. Claude quotes each established fact, separates exposure from evidence of access, groups the affected population by residence, and builds a notification table with one row per jurisdiction. Every statutory deadline, threshold and definition is left as a placeholder, so the table shows the structure of the decision without inventing the law. A dated timeline ties each decision to the open forensic question it depends on, and draft notices give the team a head start.
Breach notification law changes often, and a wrong deadline is an expensive mistake. Claude is not a source for statutory requirements here: counsel must verify each jurisdiction's statute and any sector or contractual obligation, confirm the privilege approach, and make the notification decisions. The memo is a working draft for attorney review.
The Prompt
I am counsel to [ORGANIZATION] analyzing whether a security incident triggers notification obligations. Our role for the affected data: [OWNER / CONTROLLER / VENDOR / PROCESSOR]. Relevant contracts with notice obligations: [LIST OR "NONE KNOWN"]. Regulated sectors or data types: [e.g., health, financial, children's data, none known]. <incident_facts> [PASTE FORENSIC SUMMARY, INCIDENT TICKET, TIMELINE NOTES AND ANY VENDOR NOTICE] </incident_facts> <affected_data> [PASTE THE DATA ELEMENT INVENTORY AND RESIDENCY COUNTS FOR AFFECTED INDIVIDUALS, IF AVAILABLE] </affected_data> Prepare a decision memo with: 1. Facts established, each quoted from the source, and facts still unknown. 2. Data analysis: which data elements were involved, whether they were encrypted or otherwise protected and whether keys were exposed, and the evidence of access or acquisition versus mere exposure. 3. Affected population by state or country of residence. 4. Notification analysis table, one row per jurisdiction: Jurisdiction | Statute [STATE STATUTE] | Covered data elements involved? | Risk-of-harm or other exception potentially relevant? | Individual notice | Regulator / attorney general notice | Other notices (credit agencies, contract counterparties) | Timing [VERIFY]. Do not state any statutory deadline, threshold or definition from memory; put [VERIFY] wherever it would go. 5. Decision points and timeline: a dated list of when we learned key facts and which decisions depend on each open forensic question. 6. Draft notices: a short regulator notice and an individual notice, both with bracketed placeholders for facts not yet confirmed. 7. Open items for forensics, insurance and communications. Flag inconsistencies across the sources. This is a privileged draft for attorney review [CONFIRM PRIVILEGE STRUCTURE]; every legal requirement must be verified against current law.
Example Output
A decision memo with quoted facts, a data and encryption analysis, residency counts, a per-jurisdiction notification table with every legal requirement marked for verification, a decision timeline and draft notices.
Illustrative example — names, figures, and facts are fictional.
BREACH NOTIFICATION DECISION MEMO (PRIVILEGED DRAFT FOR ATTORNEY REVIEW) Organization: Fernhill Learning Co. | Role: data owner 1. FACTS ESTABLISHED "Unauthorized access to the student-records bucket from Aug 28 to Sept 2" (forensic summary, p. 1). "Exfiltration of approximately 4 GB confirmed by egress logs" (p. 2). UNKNOWN: whether the exfiltrated files included the archived enrollment folder. 2. DATA ANALYSIS Elements: names, email addresses, dates of birth, account usernames and hashed passwords. Passwords were hashed; whether hashing counts as encryption or otherwise unreadable data under each statute: [VERIFY]. Encryption: bucket "encrypted at rest"; forensics notes the attacker used a valid access key, so at-rest encryption likely did not protect the data [CONFIRM]. Access: acquisition evidenced by egress logs, not exposure only. 3. AFFECTED POPULATION State A: 3,140 | State B: 610 | State C: 92 | Unknown residence: 418 4. NOTIFICATION TABLE Jurisdiction | Statute | Covered elements? | Exception? | Individual | Regulator/AG | Other | Timing State A | [STATE STATUTE] | Username + password: [VERIFY] | [VERIFY] | [VERIFY] | [VERIFY threshold] | Contract: district customers | [VERIFY] State B | [STATE STATUTE] | [VERIFY] | [VERIFY] | [VERIFY] | [VERIFY] | | [VERIFY] 5. DECISION TIMELINE Sept 2: incident contained. Sept 4: exfiltration confirmed (starts internal clock analysis [VERIFY trigger]). Pending: archive folder scope determines whether more elements are in play. 6. DRAFT INDIVIDUAL NOTICE (EXCERPT) "On [DATE], we learned that an unauthorized party accessed..." 7. OPEN ITEMS Forensics: archive folder scope. Insurance: notice to carrier per policy [CONFIRM]. Inconsistency: ticket says "Aug 30 start," forensic summary says Aug 28.
Tips
- •Keep the memo inside the privilege structure your incident team set up, and confirm with counsel how drafts should be labeled and shared.
- •Separate what forensics has confirmed from what it suspects. The memo is designed to show which decisions depend on each open question.
- •Fill every [VERIFY] cell from the current statute, not from memory or a secondary summary that may be out of date.
- •Check contracts and sector rules as well as breach statutes; customer and vendor agreements often impose shorter notice windows.
- •Rerun the prompt as forensic findings change. The output is always a draft for attorney review.
Frequently Asked Questions
Why won't the memo state notification deadlines?
Because getting them wrong is costly and the rules change. Deadlines, triggering events, harm thresholds and regulator-notice requirements vary across jurisdictions and are amended regularly. The prompt has Claude build the full decision structure and mark every legal requirement for verification, so the numbers in the final memo come from the current statutes, not from a model's memory.
Is a memo drafted with Claude privileged?
Privilege depends on how the incident response is structured, who directs the work and how documents are handled, not on the drafting tool. Follow your incident counsel's protocol for labeling and distribution, use a plan with appropriate confidentiality protections, and confirm the approach with counsel before circulating drafts.
Can this handle a vendor breach where we are the customer?
Yes. Paste the vendor's notice and your contract terms, and set your role to data owner or controller. The memo will separate what the vendor has confirmed from what it has not, flag the contractual notice and cooperation obligations, and list the questions to send the vendor before you can complete the jurisdiction table.
Related Prompts
Get New Prompts Like This Every Week
Join the free Claude for Lawyers newsletter — weekly prompts, tutorials, and practice-specific guides.