Data Breach Customer Notification Letter: Drafting, Timing, and Legal Requirements

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
A data breach notification letter is one of the most legally consequential documents your organization will produce. Regulators review notification timing and content. Affected individuals make decisions about credit monitoring, account security, and fraud response based on what you tell them. Plaintiff attorneys analyze notification letters for admissions and omissions when evaluating class action viability. A letter that is drafted without legal counsel review, that uses vague language to minimize impact, or that arrives after the regulatory deadline creates compounding legal liability.
This guide covers the practical drafting process: what regulators require, what a well-drafted letter looks like, and the operational logistics of actually delivering notifications to thousands of affected individuals on a deadline.
The drafting process
Drafting should start the moment a breach is confirmed, not after the investigation concludes. Waiting for investigation completion before opening a document editor is the most common way teams miss regulatory deadlines, particularly the GDPR 72-hour authority notification window. The approach is to build the letter structure immediately using placeholders for facts still being determined, then fill them in as the investigation confirms each detail. This section covers three aspects of the drafting process: starting early with a placeholder-driven template, structuring the required content elements in the correct order, and completing the legal review before any version is distributed externally.
Draft early with placeholders for unknown facts
Begin drafting the notification letter as soon as the breach is confirmed, before the investigation is complete. Use placeholders for facts still being determined: [DATE RANGE OF BREACH: July X - July Y, 2026], [NUMBER OF AFFECTED INDIVIDUALS: approximately X], [DATA TYPES EXPOSED: see list below]. This approach ensures the legal structure and required elements are in place while facts are filled in as confirmed. Waiting for a complete investigation before drafting risks missing regulatory deadlines. The GDPR 72-hour authority notification specifically accommodates incomplete information: the regulation allows you to notify regulators with what you know and supplement later.
Required structure and language
Opening paragraph: what happened, when, and when you discovered it. Paragraph 2: what data types were involved (be specific: 'names, email addresses, hashed passwords, and billing address' is better than 'personal information'). Paragraph 3: what actions you have taken (systems secured, investigation engaged, law enforcement notified, monitoring deployed). Paragraph 4: what individuals should do to protect themselves (specific steps: enroll in offered credit monitoring, place a fraud alert, monitor account statements). Paragraph 5: contact information for questions (a dedicated email address and phone number, not a generic support inbox). Closing: any free remediation resources being offered (credit monitoring enrollment instructions with activation code).
Legal review and final approval
The final letter must be reviewed by legal counsel before distribution. Legal review focuses on: accuracy of factual statements (statements about breach timeline, scope, and cause will be examined in any regulatory inquiry or litigation), admissions of fault or negligence (avoid statements like 'due to our failure to encrypt...' that establish negligence without the benefit of legal context), completeness of required regulatory elements (verify all required disclosures are present), and consistency with regulator notification already submitted. The legal review is not about softening the letter — regulators respond poorly to obfuscation — but about ensuring what is said is accurate, complete, and legally defensible.
Multi-jurisdiction compliance checklist
Any breach affecting individuals in multiple US states or multiple countries requires a compliance analysis across every applicable jurisdiction before the notification letter is finalized. The fastest path to non-compliance in a multi-state breach is applying the requirements of your home state and assuming they satisfy all others. California, New York, and Illinois each have distinct personal information definitions, content requirements, and optional remediation mandates that differ from each other and from GDPR. This section covers the key state-by-state differences that most commonly affect multi-state breach notifications and the structural differences between GDPR and US state requirements that matter when drafting a single letter intended to satisfy both.
US state-by-state key differences
California (CCPA/CCRA): required to offer 12 months credit monitoring if SSNs were exposed, specific required content for online notices, plain language requirement. New York (SHIELD Act): broadest definition of 'private information' in the US, including biometric data and username/password combinations, 'most expedient time' standard. Illinois: 45-day deadline, must include specific AG notification. Texas: 60-day deadline, AG notification required. Check the NCSL breach notification law tracker for current requirements for each state where you have affected residents — laws change frequently. For multi-state breaches, create a compliance checklist with each state's specific requirements before sending.
GDPR vs. US state notifications: key structural differences
GDPR notifications are more prescriptive: required to describe the 'likely consequences' of the breach (what harm individuals might experience as a result), which is rare in US state laws. GDPR individual notification requires the DPO contact information. GDPR does not universally require individual notification — only when 'high risk' to rights and freedoms. US state laws typically do not require risk assessment — if the defined personal information types were exposed and not encrypted, notification is generally required regardless of risk assessment. For organizations subject to both: draft a single letter that satisfies GDPR requirements and layer on any US-specific required elements (credit monitoring offers, specific AG notification language) via supplemental content.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The bottom line
Data breach notification is a deadline-driven, legally-scrutinized process that rewards early preparation. Build a notification letter template before you experience a breach, with legal counsel review baked in, so that when a breach occurs your team is filling in facts rather than drafting from scratch under deadline pressure. Draft in parallel with the investigation rather than waiting for completion, using placeholders for unknown facts. Involve legal counsel in every version before external distribution. Make the letter genuinely useful to recipients — specific about what happened and what they should do — because notification letters that obscure facts invite regulatory enforcement and class action scrutiny while failing the people the notification was meant to protect.
Frequently asked questions
What are the required elements of a data breach notification letter?
Common required elements across major frameworks: (1) Description of what happened (the incident type and how data was exposed). (2) Types of personal information involved (specifically named: name, SSN, financial account numbers, medical information, etc. — do not say 'certain personal data' without specifics). (3) Steps the company has taken to address the breach (systems secured, investigation conducted, law enforcement notified). (4) Steps individuals can take to protect themselves (monitor accounts, credit freeze, fraud alerts). (5) Contact information for questions. (6) Free credit monitoring or identity theft protection if required by state law (several states mandate this for SSN breaches). Each jurisdiction may require additional specific elements.
What are the notification deadlines I need to meet?
Key deadlines: GDPR: 72 hours to notify the supervisory authority, 'without undue delay' to affected individuals (typically interpreted as within 30 days). HIPAA: 60 days after discovery to notify individuals, same-day or within 10 business days for media notification if 500+ state residents affected, HHS annual reporting for smaller breaches (under 500 individuals). California (CCPA/CCRA): most expedient time possible, generally interpreted as 30-45 days. New York SHIELD Act: in the most expedient time and without unreasonable delay. Most US states: 30-90 days depending on the state. For multi-state breaches: apply the strictest deadline across all states where affected residents live — if California (no specific deadline), New York (reasonable), and Illinois (45 days) are all implicated, meeting the 45-day Illinois deadline is the safest approach.
Who do I notify and in what order?
Notification sequence: (1) Regulators (where required): GDPR supervisory authority within 72 hours, HHS for HIPAA breaches, state attorney generals for many US state laws — these often must be notified before or simultaneously with individual notifications. (2) Law enforcement: optional but advisable for criminal breaches; in some regulated industries (financial) mandatory. (3) Affected individuals: notify using last known contact information (email for online service, physical mail as backup). (4) Credit reporting agencies: required by some state laws for breaches involving SSNs. (5) Media: required under HIPAA if 500+ residents of a single state are affected. (6) Business partners and downstream processors: if the breach affects their customers through your systems.
How do I write a notification letter that is legally protective but honest?
Involve legal counsel in drafting before finalizing. Key principles: Be specific about data types exposed (vague language like 'certain personal information may have been accessed' satisfies no regulator and creates distrust). Describe what happened accurately but concisely, without speculating about attacker motives or unconfirmed facts. Avoid admissions of fault beyond what is factually established (the investigation may still be ongoing). Include a specific date or date range for when the breach occurred and when you discovered it. State clearly what you have done to secure the breach (not what you plan to do — actions already completed are more credible). Provide genuine remediation resources (a real credit monitoring offer, a real helpline, not just boilerplate).
What is the GDPR breach notification to the supervisory authority, and is it different from the individual notification?
GDPR requires two separate notifications: Article 33 (to the supervisory authority within 72 hours) and Article 34 (to affected individuals without undue delay). The supervisory authority notification must include: nature of the breach, categories and approximate number of data subjects, categories and approximate number of records, contact details of the DPO, likely consequences of the breach, measures taken or proposed. Individual notification (Article 34) is required when the breach is 'likely to result in a high risk' to individuals' rights and freedoms, meaning not every breach requires individual notification (low-risk breaches require only the authority notification). The individual notification must describe consequences and remediation in clear, plain language.
How do I send breach notification letters to tens of thousands of affected users?
Operational logistics: build the affected-user list from your database with verified contact information (deduplicate, remove bounced emails). For email notification: use a transactional email provider (SendGrid, Postmark, AWS SES) with authentication (SPF, DKIM, DMARC) to ensure deliverability and avoid spam classification. Use a dedicated sending domain different from your main domain so phishing attempts cannot easily mimic the notice. For physical mail (required in some jurisdictions and as a backup for users without valid emails): use a mail fulfilment vendor and confirm NCOA (National Change of Address) processing. Include a unique verification code in each letter so recipients can verify the notice is legitimate. For large volumes (100,000+ affected), set up a dedicated breach inquiry phone line before sending — notification triggers a surge of calls.
What is substitute notice and when can I use it?
Substitute notice is a less costly notification alternative permitted under some state laws and HIPAA when the cost of individual notification would exceed a defined threshold, when the company does not have sufficient contact information for all affected individuals, or when the number affected is very large. Typically involves: posting a conspicuous notice on the company's website for a specified period, notifying major statewide media, and notifying applicable state agencies. HIPAA allows substitute notice for individuals whose contact information is insufficient. Some state laws allow substitute notice only when the number of affected residents exceeds a threshold (e.g., 100,000 in California). Substitute notice does not eliminate the individual notification requirement — it satisfies it for individuals you cannot reach directly.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
