Back to Resources
Customer / Regulator Breach Notification: visual preview
Template

Customer / Regulator Breach Notification

GDPR, CCPA, HIPAA-Aligned Notification Templates

Overview

When a data breach occurs, organizations face strict regulatory deadlines for notifying affected individuals and regulatory authorities. Getting the notification wrong, whether through delayed timing, incomplete information, or unclear language, can turn a manageable incident into a reputational and legal crisis. This resource provides ready-to-adapt templates for customer and regulator breach notifications, aligned with the requirements of GDPR, CCPA/CPRA, HIPAA, and SEC regulations.

Notification Framework by Regulation

RegulationAuthority notificationIndividual notificationTimeline
GDPRSupervisory authority (DPA)Data subjects if high risk to rights and freedoms72 hours to authority
CCPA/CPRACalifornia AG if 500+ CA residentsAll affected CA residentsWithout unreasonable delay
HIPAAHHS OCR, media if 500+ in a stateAffected individuals60 days from discovery
SEC (8-K)SEC filingInvestors via public disclosure4 business days from materiality determination
State breach lawsState AG (varies by state)Affected residents (varies by state)30 to 90 days depending on state

Customer Notification Template Elements

  • Clear description of what happened and when it was discovered
  • Types of personal data involved in the breach
  • Steps already taken to contain and investigate the breach
  • What the organization is doing to prevent recurrence
  • Specific steps customers should take to protect themselves
  • Credit monitoring or identity protection services offered
  • Dedicated contact information for questions and support
  • Timeline for follow-up communications

Regulator Notification Template Elements

  • Nature of the personal data breach including categories and approximate number of records
  • Name and contact details of the Data Protection Officer or equivalent
  • Description of likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate effects
  • Timeline of discovery, containment, and notification
  • Whether affected individuals have been or will be notified
  • Supporting documentation and evidence preservation summary

Tone and Language Guidelines

Breach notifications are not marketing documents. Use plain language that affected individuals can understand without a law degree. Be honest about what happened, take responsibility, and avoid minimizing the incident. Do not use phrases like "sophisticated attack" to shift blame. State the facts, explain what you are doing about it, and tell people exactly what they need to do to protect themselves. Have legal counsel review every notification before distribution, but do not let legal review strip out the human element entirely.

Multi-Jurisdiction Coordination

Most organizations operate across multiple jurisdictions, each with its own breach notification requirements. Build a regulatory map during incident response that identifies every applicable law based on the location of affected individuals, not just where the organization is headquartered. Coordinate notification timing so that regulatory authorities are informed before or simultaneously with affected individuals. Track all notification deadlines in a single dashboard and assign a notification coordinator to prevent missed filings.

Frequently asked questions