When a vendor incident exposes your customer data, your notification script determines whether you maintain trust or face a regulatory investigation. This template provides a structured approach for GDPR-compliant breach communications that inform without alarming and guide without exposing you to liability.
Purpose of the Template
This notification template addresses Article 34 GDPR obligations when a processor breach affects your data subjects. Use it when:
- A service provider's security failure exposes personal data you control.
- The breach creates a high risk to rights and freedoms, such as phishing exposure or identity theft potential.
- You need to notify affected individuals within 72 hours of becoming aware.
- You're coordinating notifications across multiple jurisdictions with different supervisory authorities.
The template balances three requirements: transparency about what happened, practical guidance for affected individuals, and protection of your ongoing investigation. It's designed for email delivery but can be adapted for postal mail, in-app notifications, or website banners.
Preparation Steps
Before customizing this template, gather:
- Breach scope data: Identify affected customer segments, data fields, and the number of records.
- Timeline confirmation: Document when the processor detected the incident, when they notified you, and when you confirmed the scope.
- Data categories at risk: Include full names, email addresses, phone numbers, dates of birth, and customer identifiers (not payment data or credentials).
- Supervisory authority reference number: Your notification to the relevant authority under Article 33.
- Remediation status: Actions taken by the processor, what you've verified, and what remains under investigation.
- Support contact method: Provide a dedicated email, phone line, or web form for breach-related questions.
Ensure legal counsel signs off on any statements about ongoing investigations, potential misuse, or remediation measures. Don't send notifications until your Article 33 notification is filed.
The Notification Template
Subject Line: Important Security Notice Regarding Your [Company] Account
Dear [Customer Name],
We're writing to inform you of a security incident that may affect your personal information.
What Happened
On [date], we learned that unauthorized individuals accessed a file containing customer data stored by our IT service provider, [Provider Name]. The incident occurred on [date of breach]. Our provider detected the access, secured the affected systems, and notified us immediately.
What Information Was Involved
The accessed file contained:
- Full name
- Email address
- Phone number
- Date of birth
- Customer account number
We have confirmed that passwords, payment information, billing addresses, and delivery addresses were not affected. Your account credentials remain secure.
What We're Doing
Our IT service provider has:
- Restored security to the affected systems.
- Engaged forensic experts to investigate the incident.
- Implemented additional monitoring.
We have notified [country-specific supervisory authority] as required under GDPR Article 33. Reference number: [if provided by authority].
What You Should Do
While we have no evidence of data misuse at this time, we recommend you take these precautions:
Watch for phishing attempts: Be cautious of emails, texts, or calls asking for personal information or directing you to click links. We will never ask you to verify account details via email.
Verify sender authenticity: Check the sender's email address carefully. Legitimate messages from us will come from [@companydomain.com].
Enable multi-factor authentication: If you haven't already, activate two-factor authentication on your account through [Settings > Security].
Monitor your accounts: Review your bank and credit card statements for unusual activity. Report any suspicious transactions immediately.
Consider a credit freeze: If available in your jurisdiction, a credit freeze prevents new accounts from being opened in your name.
Your Rights Under GDPR
You have the right to:
- Access the personal data we hold about you (Article 15).
- Request correction of inaccurate data (Article 16).
- Lodge a complaint with [supervisory authority name] if you believe your data protection rights have been violated.
Questions?
Contact our data protection team at [dedicated email] or [phone number]. We've established this channel specifically for breach-related inquiries and will respond within 48 hours.
We take the security of your information seriously and apologize for this incident. We're conducting a thorough review of our vendor security requirements to prevent similar incidents.
Sincerely,
[Name]
[Title]
[Company]
Customization Instructions
Adjust the data categories section to match what was actually exposed. If credentials or payment data were affected, escalate the guidance (immediate password reset, payment method replacement). Never minimize the risk to reduce alarm.
Modify the action steps based on your services. If you don't offer multi-factor authentication, remove that bullet and add relevant alternatives (password change, account activity review). Each recommendation must be actionable for the recipient.
Adapt the supervisory authority reference for each jurisdiction. German customers get BfDI details, Belgian customers get APD/GBA, Dutch customers get Autoriteit Persoonsgegevens. Don't send a single template across borders.
Revise the timeline if you learned of the breach in stages. GDPR requires notification "without undue delay" after you become aware. If you discovered partial scope on day one and full scope on day three, your notification should reflect when you had sufficient information to assess risk.
Customize the provider accountability statement based on your processor agreement. If your contract requires specific security measures that failed, legal counsel may advise strengthening this section. If the investigation is ongoing, keep the language general.
Validation Steps
Before you send:
Verify Article 33 filing is complete: You cannot notify data subjects before notifying the supervisory authority. Confirm your submission timestamp.
Cross-check data categories: Compare the template's "What Information Was Involved" section against your breach register entry. They must match exactly.
Test all links and contact methods: Send test messages to internal accounts. Confirm the dedicated support channel is staffed and trained on breach-specific FAQs.
Review for consistency: If you're sending variants by country or customer segment, ensure the core facts (dates, data types, remediation) stay consistent. Contradictions trigger regulatory scrutiny.
Confirm legal sign-off: Get written approval from counsel on investigation status statements, liability limitations, and any claims about remediation effectiveness.
After you send, log the notification in your breach register under Article 33(5). Record the send timestamp, recipient count, delivery method, and any bounce-backs or delivery failures. If you can't reach affected individuals via email, GDPR may require you to attempt postal notification or publish a public notice.
The Lidl incident demonstrates why this template matters: when a processor breach exposes customer data across Germany, Belgium, and the Netherlands, your notification becomes evidence of GDPR compliance. Write it carefully.



