DATA BREACH NOTIFICATION LETTER
Important legal-advice, jurisdiction and formality warning
This fictional letter is a worked example, not legal advice and not a universal notification or admission of liability. It is written by a controller established in England and Wales and refers to the UK GDPR and Data Protection Act 2018. The organisation must investigate the actual incident, assess the risk to every affected person, coordinate any processor and regulator notifications, preserve evidence and update this letter as facts change. A recipient should not assume that every risk or remedy is covered here. Obtain advice from a suitably qualified data-protection professional before sending or relying on this wording.
Sent by email and post on 22 August 2026
To: Daniel Oliver Mercer 17 Wren Close Reading RG1 8QS
From: Cedarline Ticketing Services Limited Company number 14820931 1 Station Crescent, Reading RG1 1LX Data Protection Officer: Amelia Hart Email: dpo@cedarline.example.test Telephone: 0118 555 0148
Subject: Important notice about your Cedarline account data
Dear Mr Mercer,
We are writing to tell you about a security incident involving information held in your Cedarline account. We are sorry that this happened and for the concern it may cause. Cedarline Ticketing Services Limited is the controller for the customer account information described in this letter. We are notifying you because our investigation indicates that your record was included in the affected customer export.
What happened
On 9 August 2026 at 09:12, our monitoring identified an unusual download from a customer-support workstation. At 09:37, our security team disabled the workstation account and its active sessions. By 13:20, we had confirmed that an attacker had obtained a support agent's password through a targeted phishing message and had used the account to download a report between 08:54 and 09:11 that morning. Multi-factor authentication was not enabled on that legacy account. The account was created for Leah Morton, a Cedarline support agent, and no evidence shows that Leah intentionally accessed or disclosed the report.
The downloaded report contained approximately 18,420 customer records. Your record contained your name, postal address, email address, telephone number, the last four digits of the payment card used for your March 2026 booking, booking reference CL-260314-7782, travel dates of 14 to 16 March 2026, and the event name Riverbank Chamber Weekend. The report did not contain your full card number, security code, account password, identity document, bank account number or special-category data. We have not found evidence that those fields were present in the report.
Our investigation has not established that the file was published publicly or that a particular person used your record. We cannot, however, rule out copying by the unauthorised downloader. The realistic risks are targeted phishing, convincing-looking booking messages, unwanted contact and attempts to use the booking details to appear credible. The last four card digits cannot by themselves authorise a card payment, but they may be used in a social-engineering attempt.
What we have done
By 10:05 on 9 August we disabled the compromised account, revoked its sessions, reset credentials for all support users and blocked the report-export function. By 16:40 we had enabled multi-factor authentication for the remaining support accounts and applied an additional approval step to bulk downloads. We engaged Northstar Incident Response LLP on 10 August, preserved relevant logs and began a forensic review. The report was removed from our internal storage copies by 11 August, except for protected evidence retained for the investigation.
We notified the Information Commissioner's Office on 12 August 2026, within the applicable period after establishing that the incident was likely to create a risk to individuals. The ICO reference is IC-2026-48172. We have also notified our payment-services provider and our cyber insurer. We will provide further information to the ICO if the investigation identifies a material change.
We will complete a remedial review by 30 September 2026. It includes testing all export permissions, reviewing supplier and support access, completing phishing-resistant authentication for privileged users, refreshing staff training and verifying that retained reports have a documented deletion period. We will not ask you for your password or full card details in any follow-up communication.
What you should do
Please be cautious about emails, calls or messages that use the booking reference or claim that a refund, ticket or account problem requires a payment or password. Cedarline will not ask for your full card number, security code or password by email or telephone. If a message seems suspicious, do not click its link; contact us through the details on our official website, cedarline.example.test, or telephone 0118 555 0148. You may wish to contact your card issuer if you see an unrecognised payment, although we have no evidence that full payment-card information was exposed.
Check your email and payment accounts for unusual activity, use a unique password for Cedarline and enable multi-factor authentication wherever it is offered. If you reused a Cedarline password elsewhere, change it on those other services immediately. You can report suspected fraud to Action Fraud at 0300 123 2040 or actionfraud.police.uk. We will not ask you to pay for credit monitoring; based on the information currently involved, we are not providing a monitoring subscription because the report did not include full payment or identity-document data. We will reconsider that assessment if new facts show a higher risk.
Your rights and contact
You may contact Amelia Hart, our Data Protection Officer, at dpo@cedarline.example.test or by post to Cedarline Ticketing Services Limited, 1 Station Crescent, Reading RG1 1LX. Please quote incident reference CL-SEC-2026-08 and do not include full payment-card details. We will answer questions about your record and can provide reasonable assistance if you believe your data has been misused. We may need to verify your identity before disclosing account-specific information.
This notice does not limit any right you have under the UK GDPR, Data Protection Act 2018, contract or other law, and it is not an admission that Cedarline is liable for every consequence described. You may complain to the Information Commissioner's Office at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, by telephone on 0303 123 1113 or through ico.org.uk. We would welcome the opportunity to answer your concerns first, but you are entitled to contact the ICO directly.
We will update our incident page if the facts materially change and will contact you again if we identify a further risk requiring communication. We sincerely regret the incident and the loss of confidence it may cause.
Yours sincerely,
Amelia Hart Data Protection Officer Cedarline Ticketing Services Limited
Signature: ____________________ Date: 22 August 2026