All sample legal documents

Sample Data Breach Notification Letter

A worked UK GDPR notification to an affected customer explaining a fictional personal-data breach, risks, containment, support and complaint rights.

Jurisdiction: Illustrative United Kingdom data-breach notification — UK GDPR, Data Protection Act 2018, ICO guidance and facts must be checked

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

DATA BREACH NOTIFICATION LETTER

Important legal-advice, jurisdiction and formality warning

This fictional letter is a worked example, not legal advice and not a universal notification or admission of liability. It is written by a controller established in England and Wales and refers to the UK GDPR and Data Protection Act 2018. The organisation must investigate the actual incident, assess the risk to every affected person, coordinate any processor and regulator notifications, preserve evidence and update this letter as facts change. A recipient should not assume that every risk or remedy is covered here. Obtain advice from a suitably qualified data-protection professional before sending or relying on this wording.

Sent by email and post on 22 August 2026

To: Daniel Oliver Mercer 17 Wren Close Reading RG1 8QS

From: Cedarline Ticketing Services Limited Company number 14820931 1 Station Crescent, Reading RG1 1LX Data Protection Officer: Amelia Hart Email: dpo@cedarline.example.test Telephone: 0118 555 0148

Subject: Important notice about your Cedarline account data

Dear Mr Mercer,

We are writing to tell you about a security incident involving information held in your Cedarline account. We are sorry that this happened and for the concern it may cause. Cedarline Ticketing Services Limited is the controller for the customer account information described in this letter. We are notifying you because our investigation indicates that your record was included in the affected customer export.

What happened

On 9 August 2026 at 09:12, our monitoring identified an unusual download from a customer-support workstation. At 09:37, our security team disabled the workstation account and its active sessions. By 13:20, we had confirmed that an attacker had obtained a support agent's password through a targeted phishing message and had used the account to download a report between 08:54 and 09:11 that morning. Multi-factor authentication was not enabled on that legacy account. The account was created for Leah Morton, a Cedarline support agent, and no evidence shows that Leah intentionally accessed or disclosed the report.

The downloaded report contained approximately 18,420 customer records. Your record contained your name, postal address, email address, telephone number, the last four digits of the payment card used for your March 2026 booking, booking reference CL-260314-7782, travel dates of 14 to 16 March 2026, and the event name Riverbank Chamber Weekend. The report did not contain your full card number, security code, account password, identity document, bank account number or special-category data. We have not found evidence that those fields were present in the report.

Our investigation has not established that the file was published publicly or that a particular person used your record. We cannot, however, rule out copying by the unauthorised downloader. The realistic risks are targeted phishing, convincing-looking booking messages, unwanted contact and attempts to use the booking details to appear credible. The last four card digits cannot by themselves authorise a card payment, but they may be used in a social-engineering attempt.

What we have done

By 10:05 on 9 August we disabled the compromised account, revoked its sessions, reset credentials for all support users and blocked the report-export function. By 16:40 we had enabled multi-factor authentication for the remaining support accounts and applied an additional approval step to bulk downloads. We engaged Northstar Incident Response LLP on 10 August, preserved relevant logs and began a forensic review. The report was removed from our internal storage copies by 11 August, except for protected evidence retained for the investigation.

We notified the Information Commissioner's Office on 12 August 2026, within the applicable period after establishing that the incident was likely to create a risk to individuals. The ICO reference is IC-2026-48172. We have also notified our payment-services provider and our cyber insurer. We will provide further information to the ICO if the investigation identifies a material change.

We will complete a remedial review by 30 September 2026. It includes testing all export permissions, reviewing supplier and support access, completing phishing-resistant authentication for privileged users, refreshing staff training and verifying that retained reports have a documented deletion period. We will not ask you for your password or full card details in any follow-up communication.

What you should do

Please be cautious about emails, calls or messages that use the booking reference or claim that a refund, ticket or account problem requires a payment or password. Cedarline will not ask for your full card number, security code or password by email or telephone. If a message seems suspicious, do not click its link; contact us through the details on our official website, cedarline.example.test, or telephone 0118 555 0148. You may wish to contact your card issuer if you see an unrecognised payment, although we have no evidence that full payment-card information was exposed.

Check your email and payment accounts for unusual activity, use a unique password for Cedarline and enable multi-factor authentication wherever it is offered. If you reused a Cedarline password elsewhere, change it on those other services immediately. You can report suspected fraud to Action Fraud at 0300 123 2040 or actionfraud.police.uk. We will not ask you to pay for credit monitoring; based on the information currently involved, we are not providing a monitoring subscription because the report did not include full payment or identity-document data. We will reconsider that assessment if new facts show a higher risk.

Your rights and contact

You may contact Amelia Hart, our Data Protection Officer, at dpo@cedarline.example.test or by post to Cedarline Ticketing Services Limited, 1 Station Crescent, Reading RG1 1LX. Please quote incident reference CL-SEC-2026-08 and do not include full payment-card details. We will answer questions about your record and can provide reasonable assistance if you believe your data has been misused. We may need to verify your identity before disclosing account-specific information.

This notice does not limit any right you have under the UK GDPR, Data Protection Act 2018, contract or other law, and it is not an admission that Cedarline is liable for every consequence described. You may complain to the Information Commissioner's Office at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, by telephone on 0303 123 1113 or through ico.org.uk. We would welcome the opportunity to answer your concerns first, but you are entitled to contact the ICO directly.

We will update our incident page if the facts materially change and will contact you again if we identify a further risk requiring communication. We sincerely regret the incident and the loss of confidence it may cause.

Yours sincerely,

Amelia Hart Data Protection Officer Cedarline Ticketing Services Limited

Signature: ____________________ Date: 22 August 2026

Create a version for your situation

Create a tailored Data Breach Notification Letter