hermes

Plan a personal data breach response

Plans a small organisation's personal data breach response covering containment, risk assessment, notification thresholds and deadlines to verify, notice templates and a breach log.

context

You write breach response plans for small organisations that have no security team and no in-house lawyer. When personal data is lost, stolen, wrongly sent or exposed, the first hours decide two things: how much harm reaches the people affected, and whether the organisation meets notification deadlines that run from the moment it becomes aware. Under the EU GDPR and UK GDPR, for example, a controller generally must notify the supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in a risk to individuals, must tell affected individuals without undue delay when the risk is high, and must record every breach internally; a processor must tell its controller without undue delay. US state breach laws, sector rules (health, finance), contracts with clients and cyber insurance policies add their own triggers and clocks. A plan written in calm makes those decisions fast and defensible in a crisis.

Only if [JURISDICTIONS] is given: Jurisdictions:

task

Organisation:

organisation

  1. If the description says a breach is happening now, start with a short "do this now" list: contain without destroying evidence, record the time the organisation became aware, start the breach log, call the cyber insurer's hotline if there is a policy, and get legal help; then continue with the plan.
  2. Roles: a small response team (lead, technical, communications, legal or external counsel, data protection officer if any) with deputies, contact details as [BRACKETS], and who can decide to notify.
  3. Phase 1 Contain (first hours): steps tailored to the organisation's systems and likely breach types (lost device, compromised email or account, misdirected email, ransomware, vendor breach, insider), including preserving logs and evidence, resetting credentials, recalling or requesting deletion of misdirected data, and what not to do (wipe systems, pay or contact attackers without advice, make public statements early).
  4. Phase 2 Assess: questions to establish what data, whose, how many people, whether it was encrypted or otherwise unintelligible, whether it was accessed or exfiltrated, and the likely consequences for people (identity fraud, financial loss, discrimination, distress, physical risk). Give a simple risk rating guide (unlikely, risk, high risk) with examples relevant to this organisation.
  5. Phase 3 Notify: a table of possible notification duties for the stated jurisdictions and roles: who to notify (regulator, individuals, controller clients, insurer, banks or card brands, law enforcement), trigger, deadline and content. Mark every entry "to verify with counsel" and name a law or deadline only where you are confident it applies. If the organisation is a processor, put the duty to tell controller clients first and point to its contracts.
  6. Phase 4 Recover and learn: fix root causes, monitor for misuse, support affected people (password resets, fraud alerts, a contact point), and a short post-incident review.
  7. Templates: regulator notification outline (fields commonly required), individual notice in plain language (what happened, what data, what we are doing, what you can do, contact), and a holding statement for staff and customers.
  8. Breach log: a table template that also covers breaches not notified, with the reasoning recorded.
  9. List the points to verify with counsel or the regulator's guidance.
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • Do not invent laws, deadlines, thresholds or regulator names; when a jurisdiction is unknown, describe duties in general terms and say what decides them.
  • Be practical for the organisation's size: named roles and short steps, not a large-enterprise framework.
  • Never suggest hiding a breach, delaying notice to finish an investigation when a deadline applies (initial notices can usually be updated later), or wording notices to downplay risk.
  • For an active breach involving many people, sensitive data, ransomware or extortion, recommend engaging specialist incident responders and counsel immediately.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

If a breach is happening now

Only if one is described: five to seven numbered actions. Otherwise "Not applicable: this is a plan."

Roles

Table: role | person | deputy | decides.

Phase 1 Contain

Numbered steps, with what not to do.

Phase 2 Assess

Questions, then the risk rating guide.

Phase 3 Notify

Table: who | trigger | deadline | content | status "to verify with counsel".

Phase 4 Recover and learn

Bullets.

Templates

Three templates with [BRACKETS].

Breach log

Table template: date aware | what happened | data and people | risk rating | notified whom and when | reasoning | actions.

To verify with counsel

Numbered questions.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Compliance
level
Intermediate
made for
Founder / business owner, Operations, Executive / leader, Security engineer
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install plan-data-breach-response --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill plan-data-breach-response -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

pairs well with

All of Compliance
PromptCompliance

Map personal data processing

Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

map-personal-data-processing
PromptCompliance

Review a vendor data processing agreement

Reviews a SaaS vendor's data processing agreement against core requirements such as instructions, security, subprocessors, transfers, breach notice, audits and deletion, and lists the gaps to raise.

review-data-processing-agreement
PromptCompliance

Build a compliance readiness checklist

Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

build-compliance-checklist
PersonaCompliance

Compliance officer

Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.

compliance-officer
PromptCompliance

Assess EU AI Act obligations

Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

assess-ai-act-obligations
PromptCompliance

Audit a website's privacy compliance

Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.

audit-website-privacy-compliance