GDPR Breach Notification Template for Ecommerce

Customer order or payment data exposed? Get a structured breach notice and customer alert fast.

Instant Ready in 30 seconds
€29.99 One-time payment
.docx file Professional format
Refund Not happy? Money back

Secure payment via Stripe. One-time charge, no subscription.

Example result

Here's what you get — a real example generated by the tool:

# DOCUMENT 1: ARTICLE 33 NOTIFICATION TO SUPERVISORY AUTHORITY ## 1. Organization Details Nordic Retail ApS, e-commerce retailer, acting as data controller for customer account data. ## 2. Nature of the Personal Data Breach On October 9, 2026 at approximately 15:00 CET, the IT team discovered that a database backup file had been stored in a publicly accessible cloud storage bucket since approximately September 29, 2026 (10 days of exposure). The breach was identified after an external security researcher reported the exposed bucket via email. Root cause: a misconfigured storage permission applied during a routine backup migration. ## 3. Categories and Approximate Number of Data Subjects Concerned Approximately 4,200 registered customer accounts. ## 4. Categories and Approximate Number of Personal Data Records Concerned Full names, email addresses, phone numbers, and bcrypt-hashed passwords for ~4,200 accounts. No financial card data or health data was included in the exposed backup. ## 5. Likely Consequences of the Breach Moderate risk of phishing and credential-stuffing attacks against affected individuals. Password hashes are unlikely to be reversed in the short term but pose a residual risk. No direct financial exposure identified. ## 6. Measures Taken or Proposed to Address the Breach Public access to the storage bucket was revoked within 1 hour of discovery. A forced password reset was triggered for all 4,200 affected accounts. Access logs are under review to determine if the data was accessed by unauthorized third parties beyond the reporting researcher. ## 7. Data Protection Officer / Contact Point jane@nordicretail.example, +45 00 00 00 00 ## 8. Cross-Border Processing To be confirmed by the organization — assess whether customers in other EU member states are affected and whether the lead supervisory authority mechanism applies. This document is a drafting aid, not legal advice. Have it reviewed by your DPO or legal counsel before submission. --- # DOCUMENT 2: ARTICLE 34 NOTICE TO AFFECTED DATA SUBJECTS Subject: Important security notice regarding your Nordic Retail account [Dear Customer], We are writing to inform you of a data security incident that may have affected your personal information. Between September 29 and October 9, 2026, a technical misconfiguration made a backup file containing your name, email address, phone number, and password (stored in encrypted form) temporarily accessible without authorization. What this means for you: there is a risk you could receive phishing emails or unauthorized login attempts using this information. What we have done: we immediately secured the exposed file, reset all potentially affected passwords, and are investigating the full scope of access. What we recommend you do: - Reset your password if you haven't already, and avoid reusing it elsewhere - Enable two-factor authentication if available - Be cautious of unexpected emails or calls referencing your account - Monitor your accounts for unusual activity over the coming weeks This document is a drafting aid, not legal advice. Have it reviewed by your DPO or legal counsel before submission. --- # DOCUMENT 3: INTERNAL INCIDENT LOG ## Breach Timeline | Date/Time | Event | Action Taken | Responsible | | --- | --- | --- | --- | | 2026-09-29 (est.) | Misconfigured bucket permissions applied during migration | None (undetected) | IT Infrastructure | | 2026-10-09 15:00 | External researcher reports exposed bucket | Report triaged | Security Team | | 2026-10-09 16:00 | Public access revoked | Bucket permissions corrected | IT Infrastructure | | 2026-10-09 18:00 | Forced password reset issued to all affected accounts | Reset emails sent | IT Infrastructure | | [TBC] | Access log review completed | Determine unauthorized access scope | Security Team | ## Record of Decisions | Decision | Rationale | | --- | --- | | Notify supervisory authority within 72 hours | Risk to rights and freedoms of data subjects cannot be ruled out | | Notify affected individuals directly | Password and contact data exposure creates phishing risk | ## Follow-Up Actions Required - [ ] Complete access log forensic review - [ ] Confirm whether other EU jurisdictions' authorities must be notified - [ ] Schedule post-incident review and update backup access policy

How it works

1

Fill in the form

2

Pay once — €29.99

3

Download your .docx file

Why this instead of doing it yourself?

Without this tool

  • Hours researching the right format
  • Start from a blank page
  • Miss industry-specific details
  • ChatGPT gives raw text, not a file

With BreachNotifyKit

  • Ready in 30 seconds
  • Professional format, ready to use
  • Domain-specific structure built in
  • Download a real .docx file

Frequently Asked Questions

What file format do I get?

You get a single professional .docx Word document containing three sections: the Article 33 supervisory authority notification, the Article 34 notice to affected individuals, and an internal incident log with a timeline table. Open it directly in Word, Google Docs, or any compatible editor.

Why is this cheaper than a data protection lawyer?

A data protection lawyer typically charges €150-300/hour, and breach response often takes several hours under time pressure. This tool generates a structured first draft of all three required documents for a one-time €29.99 — you still have the document reviewed by your DPO or counsel before submission, but you're not paying hourly rates to get from blank page to draft.

How fast do I get my documents?

Within 30 seconds of submitting the form. The output is designed for the 72-hour notification window under Article 33 — you can go from incident discovery to a structured draft notification in minutes, not days.

Is this legal advice?

No. This tool produces a structured drafting aid based on standard GDPR Article 33 and 34 requirements, not a legal opinion. Every document includes a reminder to have it reviewed by your DPO or legal counsel before submission to a supervisory authority.

Does this work for any EU country or the UK?

Yes. The documents are structured around the GDPR articles themselves (Article 33 and 34), which apply uniformly across the EU and in equivalent form under UK GDPR. You may need to adapt minor formatting to your specific national supervisory authority's submission portal.

What happens to the breach details I enter?

Your input is sent securely to generate your documents and is not stored or reused after your file is generated. Treat the generated documents as drafts you control — review and finalize them yourself before sending.

Can I get a refund?

Yes. If the generated documents don't meet your needs, contact us within 24 hours for a full refund, no questions asked.

More from PayOnceTools

ProposalForge
Describe your project, get a fully structured proposal with executive summary, deliverables, milestone timeline, and investment section — ready to send to your client.
€14.99
ContentCalendar90
Tell us your business and platforms — get a week-by-week content plan with specific post ideas, named recurring series, and monthly themes. No templates to fill, no blank Mondays.
€9.99
TradeQuote.pro
Fill in your job details, get a client-ready Word quote with itemized costs and VAT — one-time €12.99, no subscription, no templates to fiddle with.
€12.99
InvoicePack
Paste your invoice data, download a clean .xlsx with every field extracted — vendor, date, invoice number, net, VAT, total. One-time €14.99 vs $49/mo subscriptions.
€14.99
StockAlertSheet
Paste your SKU list, get a professional Excel planner with safety stock, reorder points, and EOQ for every product in 30 seconds — one-time €9.99 vs $50-200/mo WMS.
€9.99
TripExpense
Paste your trip expenses, get a formatted Excel report auto-categorized by type and client — ready to hand to finance. €7.99 once, not $15/month.
€7.99
StartupFinModel
Enter your metrics, get a complete 36-month Excel model with P&L, cash flow, and unit economics. One-time €24.99 — not a static template, not a subscription.
€24.99
CapTableKit
Enter founders, rounds, and option pool — get a professional Excel spreadsheet with dilution by round, fully diluted ownership, and exit waterfall. One-time €29.99 vs €2,400/year on Carta.
€29.99
StrategyKit 2026
Enter your goals and current metrics — get a professional strategy document with SWOT, KPI dashboard, and 90-day roadmap. One-time €19.99 vs $20/mo LivePlan.
€19.99
CrossTabReport
Paste your Google Forms, Typeform, or SurveyMonkey export, pick a segment, and download a professional Excel cross-tabulation report — no pivot tables, no $890/mo research software.
€12.99
OSSVatSheet
Enter your EU sales by country, get a filing-ready Excel VAT breakdown. One-time €16.99 — not another $50/mo invoicing subscription.
€16.99