How to Communicate a Data Breach
A practical guide to data breach communication: who to tell and in what order, what to say to affected people, what to leave out, and how to handle the questions that follow.
Good data breach communication tells affected people, clearly and as soon as you reliably can, what happened, what information was involved, what you are doing about it, what they should do to protect themselves and where to get help. Your lawyer and forensic investigators should lead on the facts and the legal deadlines. Your job is to make sure every message is accurate, consistent and useful to the person reading it.
This guide covers the communication side. It isn’t legal advice, and breach notification rules vary by state and sector, so bring in counsel experienced in data privacy before anything goes out.
Start with the rules that apply to you
All 50 states have breach notification laws that require organizations to tell people when certain personal information is compromised. They differ on what counts as personal information, what counts as a breach, how quickly you must notify, and whether you must also tell the state attorney general or other agencies. Some set a fixed number of days; many say “without unreasonable delay.” Which laws apply usually depends on where the affected people live, not where your business is.
Some sectors add their own rules on top. Two common examples:
- Healthcare. Under the HIPAA Breach Notification Rule, covered entities and their business associates must notify affected individuals of breaches of unsecured protected health information without unreasonable delay and within 60 days of discovery. They must also notify the Department of Health and Human Services, and breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets there.
- Public companies. SEC rules adopted in 2023 require public companies to disclose a cybersecurity incident on Form 8-K within four business days of determining that it is material.
Financial services, government contractors, education and other sectors can have their own requirements, and contracts with customers or partners often include notification clauses too. The legal deadlines shape the communication timeline, which is why the lawyer comes first.
Who leads: legal, forensics and communications
In the first hours, three groups need to work as one team.
- Legal counsel decides what the law requires, when, and to whom, and reviews every external message.
- Forensic investigators establish what happened, what systems and data were affected and whether the attacker still has access. Until they have findings, most of what anyone “knows” is a guess.
- Communications turns confirmed facts into plain-English messages, keeps every audience consistent, and prepares for questions.
Name one decision-maker who signs off on external statements. Conflicting messages from different departments do more damage than a short wait.
Who to tell, and in what order
The exact order depends on your legal obligations, but a typical sequence looks like this.
- Internal leadership and the response team. Brief the people who need to act, and tell them what not to discuss outside the team.
- Law enforcement, where appropriate. The FTC’s guidance for businesses suggests contacting local police, and the FBI or Secret Service where local police lack the expertise. Law enforcement may occasionally ask you to delay notification so as not to disrupt an investigation; your lawyer will handle that conversation.
- Insurers, banks and business partners. Your cyber insurer may have notification requirements and approved vendors. Banks and card processors may need to watch for fraud. If you hold data on behalf of other companies, they need to know.
- Regulators, as required. State attorneys general, sector regulators and others, on the timelines your lawyer confirms.
- Affected people. The notification letter or email, backed by a call center and FAQ page ready on the day it goes out.
- All staff. Just before or at the same time as the public notice, so employees don’t learn about it from the news and know where to send questions.
- The public and media. A statement on your website and, if the story is likely to be reported, a prepared response for journalists.
If news of the incident leaks before you’re ready to notify, a short holding statement buys time without committing to facts you haven’t confirmed. Our guide to writing a holding statement includes a template for a data incident.
What to say in a breach notice
The FTC’s data breach guidance for businesses lists what a notice should explain. Written for the person receiving it, that becomes five questions.
| Question | What to cover |
|---|---|
| What happened? | How and when the incident occurred and when you discovered it, in plain language. |
| What information was involved? | The specific types of data for this person: names, addresses, Social Security numbers, card numbers, health information. Be precise. |
| What are you doing about it? | Steps taken to contain it and prevent a repeat, and any support you are offering, such as credit monitoring or identity protection. |
| What should I do? | Concrete actions: watch statements, place a fraud alert or credit freeze, change passwords, be wary of phishing that mentions the breach. The FTC points consumers to IdentityTheft.gov for recovery steps. |
| Where do I get help? | A dedicated phone number, email address and FAQ page, with hours. |
Put the most important information first. Many people read only the first paragraph, so “your Social Security number was involved, and here’s what to do” belongs at the top.
What not to say
- Don’t speculate. Don’t guess at the number of people affected, who was responsible or what data was taken. Numbers that go up later are remembered as a cover-up.
- Don’t say “there is no evidence of misuse” unless it’s true and checked. Only use it if investigators have actually looked and found none, and be ready for it to change. If you haven’t looked, say what you do know.
- Don’t minimize. “A small number of records” or “a sophisticated attack” reads as deflection.
- Don’t blame a vendor in the first notice. Even if a supplier was the source, customers gave their data to you. Explain the vendor’s role later, factually, if it matters.
- Don’t bury it. A vague subject line or a notice hidden in a newsletter looks like an attempt to avoid attention.
A sample notification
This is an illustrative structure, not a legal template. Your lawyer should adapt it to the laws that apply to you.
Suggested subject line: “Important notice about your personal information.”
We are writing to tell you about a security incident that involved some of your personal information. On [date], we discovered that an unauthorized person had accessed one of our customer databases between [date] and [date]. The information involved for you included your name, mailing address and date of birth. Your payment card details were not stored in this system. We shut off the access the same day, brought in an independent forensic firm, and have added [specific control]. We are offering you [length] of free credit monitoring; to enroll, visit [link] and use code [code]. We also recommend you review your account statements and consider placing a fraud alert or credit freeze with the credit bureaus. We will never ask for your password or full card number by phone or email. If you have questions, call [number] between [hours] or visit [FAQ page]. We are sorry this happened. [Name, title]
An apology belongs in a breach notice, but keep it short and let the practical help do the work. If the breach resulted from a clear failure, a fuller apology may follow later; our guide on how to write a public apology covers what makes one land.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditSet up the FAQ page and call center before you notify
The notice will generate questions, and the worst outcome is people calling a general line that knows nothing. Have these ready on the day notices go out:
- A dedicated FAQ page linked from your homepage, with a clear date and a note of when it was last updated.
- A call center or hotline with trained staff and a script approved by counsel. Many cyber insurers can arrange this through approved vendors.
- A process for updates, so new facts reach the FAQ page, the scripts and the social media team at the same time.
A useful FAQ page usually answers, in this order: what happened; what information was involved; how to tell if I was affected; what you’re doing; what I should do; how to enroll in any monitoring offered; how to spot scam messages; and who to contact. Link to the credit bureaus and IdentityTheft.gov rather than paraphrasing their advice.
A worked example
This is an illustrative scenario, not a real case.
A regional home services company learns that a compromised employee email account was used to access a shared folder of customer invoices. Outside counsel is engaged the same day and brings in a forensic firm. Over the next two weeks, investigators confirm the folder held names, addresses and, for some customers, bank account numbers used for direct debit.
Counsel maps which states the affected customers live in and which notification rules and deadlines apply. Meanwhile, the communications lead drafts the notice, an FAQ page and a call script. The company tells its bank and insurer, then sends notices with two versions: one for customers whose bank details were involved, with specific steps and an offer of credit monitoring, and one for those whose name and address only were exposed. The FAQ page and hotline go live the same morning, and all staff get a briefing an hour before.
A local reporter calls that afternoon. The company gives the same facts as the notice, says what has changed, and points to the FAQ page. It doesn’t estimate how many people might be affected beyond what investigators have confirmed.
After the notice: search results and reviews
A breach can leave a long tail online. News coverage, state attorney general breach listings and forum threads may rank for your company name, and some customers will leave reviews about it.
- Reply to reviews about the breach with the same facts, a link to the FAQ page and a way to get help. Don’t argue about the severity.
- Keep your own page current, with a closing update when the investigation ends, so the most accurate account of the incident is yours.
- Ask for corrections only where coverage is factually wrong. Our guide on handling negative press coverage covers how.
- Publish evidence of change over the following months, such as security improvements or certifications, so there is newer, accurate content for search engines and customers to find.
If the incident is shaping how customers see you months later, our crisis management service can help plan the communication and the recovery of your search results and reviews.
Frequently asked questions
How soon do you have to notify people of a data breach?
It depends on the laws that apply. State laws vary, with some setting a specific number of days and others requiring notice without unreasonable delay. Sector rules can add their own deadlines, such as HIPAA’s outer limit of 60 days from discovery for covered entities. Your lawyer should confirm the deadlines for your situation.
Should we notify people before the investigation is finished?
Often you’ll need to. Investigations can take weeks, and legal deadlines don’t always wait for them. Share what you have confirmed, say clearly what you are still investigating, and commit to updating people when you know more.
Do we have to offer credit monitoring?
Not always, though a few state laws require free credit monitoring or identity theft protection when Social Security numbers are exposed. The FTC recommends offering at least a year of free credit monitoring when Social Security numbers or financial information are involved. Ask your lawyer what applies to you.
Should the CEO send the breach notice?
A notice signed by a named senior leader reads as more accountable than one from “the team,” and a CEO statement can help when the breach is large or widely reported. The content still matters more than the signature.