Skip to main content

External & Customer Notifications

Customer breach notifications and press statements.

External Communication Templates

When a cyber security incident affects customers, the public, or external stakeholders, clear and transparent communication is essential. CrownSync Playbooks provides external communication templates for customer breach notifications, press statements, and customer FAQ documents. These templates are designed to meet UK regulatory disclosure requirements while helping your organisation manage reputational risk.

External templates are pre-populated with your organisation name, contact details, and incident reference information. They appear within playbooks at the phase where external communication is recommended and are also accessible from the Communications section.

Customer Breach Notification

Under UK GDPR Article 34, organisations must notify affected individuals when a personal data breach is likely to result in a high risk to their rights and freedoms. The customer breach notification template helps you communicate this clearly, compassionately, and in compliance with ICO guidance.

The template includes:

  • What happened— A plain-language description of the breach without unnecessary technical jargon
  • What data was involved— The categories of personal data affected, presented in terms customers can understand
  • What you are doing about it— Steps your organisation has taken to contain the breach and prevent recurrence
  • What customers should do— Specific, actionable steps such as changing passwords, monitoring accounts, or being alert to phishing attempts
  • How to get help— Contact details for your support team and links to relevant resources such as the ICO and Action Fraud
  • DPO contact details— Your Data Protection Officer's name, email, and phone number

Legal Review Recommended

Customer breach notifications carry significant legal and reputational implications. CrownSync strongly recommends that your legal team reviews the notification before it is sent. The template provides a solid foundation, but your legal advisors should confirm the language is appropriate for your specific circumstances.

Press Statement — Initial

The initial press statement template is designed for use when news of an incident becomes public or is likely to attract media attention. It provides a brief, factual statement that acknowledges the situation without speculating about causes, impact, or blame.

The template structure follows established crisis communication principles:

  • Acknowledgement that an incident has occurred
  • Confirmation that the organisation is investigating and responding
  • Assurance that affected parties are being notified
  • Statement that further updates will be provided as more information becomes available
  • Contact details for media enquiries

Tip

Prepare your initial press statement early, even if you do not expect media attention. Having an approved statement ready means you can respond within minutes if journalists make contact, rather than scrambling to draft something under pressure.

Press Statement — Follow-Up

The follow-up press statement template is used after the initial statement, typically once the investigation has progressed and more details can be shared. It provides a more comprehensive update while maintaining a measured, professional tone.

The follow-up statement covers:

  • Updated summary of what happened and the root cause (if known)
  • Scope of the incident — systems, data, and customers affected
  • Remediation steps completed and any remaining actions
  • Support available to affected customers or parties
  • Steps taken to prevent recurrence
  • Contact details for further media enquiries

Customer FAQ

The customer FAQ template provides a structured question-and-answer document that can be published on your website, shared with your support team, or sent directly to affected customers. It anticipates the most common questions customers ask following a data breach or service disruption.

Standard questions covered in the template include:

  • What happened and when did it occur?
  • Is my data affected? What type of data was involved?
  • What is the organisation doing to fix this?
  • What should I do to protect myself?
  • Will I be compensated?
  • How do I make a complaint?
  • Who can I contact for more information?
  • Has this been reported to the ICO?
  • How will I know when the issue is fully resolved?

The FAQ template is designed to be published alongside your customer breach notification. It reduces the volume of individual enquiries to your support team by proactively answering the questions customers are most likely to ask.

Next Steps

All external communication templates can be customised to match your organisation's tone and brand. For guidance on editing, saving, and resetting templates, see Customising Templates. For regulatory notification templates (ICO, FCA, PRA), see Regulatory Templates.

Was this page helpful?