Free Tool

Data Breach Notification Letter Template
thirteen sections that turn blank-page drafting into a counsel-ready artefact across every regulator clock

A free, copy-ready data breach notification letter template for CISOs, GRC and compliance teams, privacy officers, incident response leads, SOC managers, internal security teams, AppSec teams, vulnerability management teams, security operations leaders, and disclosure committees. Thirteen structured sections covering letter header and regime in scope and version control, notified-party identification and delivery channel, discovery and confirmation and the regulator-clock chronology, scope and data categories and affected-party counts, cause and root cause and the confirmed-versus-suspected distinction, affected-party impact and realised harm and the risk-of-harm assessment, protective measures recommended and company-funded protective offer, points of contact and the named hotline and inbound inquiry handling, regime-specific carve-outs and statutory exceptions invoked, legal hold and privilege treatment and counsel-reviewed evidence, signature block and named title and named effective date, framework expectations evidenced by the artefact, and lifecycle and supplemental notifications and post-closure obligations. Variant blocks cover GDPR Articles 33 and 34, NIS2 Article 23 early warning and incident notification and final report, SEC Item 1.05 Form 8-K cybersecurity disclosure narrative, the HIPAA Breach Notification Rule across the individual, Secretary, media, and business associate variants, DORA Articles 19 and 20 progression schedule, state breach-notification laws in the United States, the PCI DSS account data compromise pathway, the cyber insurance notice-of-claim pattern, the law-enforcement coordination letter, and the contractual customer notification clause variant. Aligned with ISO/IEC 27001:2022 Annex A 5.24 through 5.28, SOC 2 CC7.3 and CC7.4, NIST SP 800-61 Rev. 2 incident handling, NIST SP 800-53 IR-4 through IR-8, ISO/IEC 27035 incident management, UK PRA SS1/21 and SS2/21 operational resilience and outsourcing, APRA CPS 234, MAS Technology Risk Management Guidelines, FFIEC Information Security Booklet, OCC Heightened Standards, NYDFS Part 500, FINRA cybersecurity obligations, FTC Health Breach Notification Rule, and Gramm-Leach-Bliley Act Safeguards Rule where in scope.

No credit card required. Free plan available forever.

Loading tool...

Run breach notification on the live engagement record, not on a hurried Word document

SecPortal opens a breach engagement at the moment a triggering event is suspected so the named incident commander, the named legal counsel, the named disclosure committee chair, the named privacy officer, the named clock chronology, the named materiality determination chain, the named letter drafts, the named counsel review timestamps, and the named delivery confirmations all live on one workspace record with a named-actor activity log. Free plan available.

No credit card required. Free plan available forever.