Data Breach Notification Letters — Writing Vocabulary
Learn to write legally sound, empathetic data breach notification letters.
0 / 14 completed
1 / 14
Under GDPR, within how many hours must a personal data breach be reported to the supervisory authority (if it risks individuals' rights)?
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach that risks individuals' rights and freedoms.
2 / 14
Which information is required in a GDPR Article 34 breach notification to affected individuals?
GDPR Article 34 requires: nature of the breach, DPO contact details, likely consequences, and measures taken or proposed to address the breach.
3 / 14
Which language register is appropriate for a data breach notification letter?
A breach notification must be clear and plain for the recipient to understand their risk, empathetic in tone, legally complete, and include concrete steps the recipient should take.
4 / 14
What is 'customer reassurance language' in breach communication?
Reassurance language describes what you have done to secure systems and protect users, and offers concrete support (credit monitoring, dedicated helpline) — without minimising the event.
5 / 14
What should you NOT do in a data breach notification letter?
Using passive voice to obscure responsibility ('data was accessed by an unauthorised party') undermines trust. Be direct about what happened and take responsibility.
6 / 14
PR Description
During a code review of the new user authentication API, you identify a potential vulnerability that could expose customer data. You need to draft a PR description that clearly informs the team about the breach and guides them on how to proceed. Which phrasing best achieves this while maintaining a professional tone suitable for a formal notification?
The correct answer utilizes formal and precise language, highlighting the severity of the situation ('Urgent', 'potential exposure') and clearly stating the required action ('Requires immediate attention'). The other options are too informal (e.g., "FYI") or lack the necessary detail to convey the seriousness of a data breach notification – developers need to understand the potential impact and how it needs to be handled immediately.
7 / 14
PR Description
During a code review of the new user authentication API, you identify a potential vulnerability that could expose customer data. You need to draft a PR description that clearly informs the team about the breach and guides them on how to proceed. Which phrasing best achieves this while maintaining a professional tone suitable for a formal notification?
The correct answer utilizes formal and precise language, highlighting the severity of the situation ('Urgent', 'potential exposure') and clearly stating the required action ('Requires immediate attention'). The other options are too informal (e.g., "FYI") or lack the necessary detail to convey the seriousness of a data breach notification – developers need to understand the potential impact and how it needs to be handled immediately.
8 / 14
PR Description
During a code review of the new user authentication API, you identify a potential vulnerability that could expose customer data. You need to draft a PR description that clearly informs the team about the breach and guides them on how to proceed. Which phrasing best achieves this while maintaining a professional tone suitable for a formal notification?
The correct answer utilizes formal and precise language, highlighting the severity of the situation ('Urgent', 'potential exposure') and clearly stating the required action ('Requires immediate attention'). The other options are too informal (e.g., "FYI") or lack the necessary detail to convey the seriousness of a data breach notification – developers need to understand the potential impact and how it needs to be handled immediately.
9 / 14
PR Description
During a code review of the new user authentication API, you identify a potential vulnerability that could expose customer data. You need to draft a PR description that clearly informs the team about the breach and guides them on how to proceed. Which phrasing best achieves this while maintaining a professional tone suitable for a formal notification?
The correct answer utilizes formal and precise language, highlighting the severity of the situation ('Urgent', 'potential exposure') and clearly stating the required action ('Requires immediate attention'). The other options are too informal (e.g., "FYI") or lack the necessary detail to convey the seriousness of a data breach notification – developers need to understand the potential impact and how it needs to be handled immediately.
10 / 14
Sarah, a junior developer on the team, has just discovered a potential data breach affecting user email addresses. She needs to draft a concise Slack message to alert her manager and the security team. Which of the following phrases best conveys urgency and requires immediate action?
The key here is conveying urgency and seriousness. Option A is too casual; Option C is vague and doesn't explicitly state a breach. Option D focuses on investigation without highlighting the critical nature of the situation. Option B clearly communicates the severity and prompts immediate action, which is vital in a data breach scenario.
11 / 14
You're drafting a PR description to announce a vulnerability discovered during code review of a new payment processing API. The vulnerability involves exposing sensitive transaction IDs. Which statement best reflects the appropriate tone and level of detail?
This situation demands transparency and acknowledging potential risk. Option A is too understated. Option C misrepresents the issue. Option D focuses on functionality, ignoring the security concern. Option B appropriately highlights the vulnerability and necessitates further scrutiny, aligning with best practices for PR descriptions related to security vulnerabilities.
12 / 14
A company is preparing a data breach notification letter to affected customers. Which of the following elements is MOST crucial to include regarding *customer reassurance*?
While all options touch upon aspects of communication, Option 1 directly addresses customer reassurance by stating concrete actions taken. Option A is a standard statement but lacks specifics. Option B reiterates commitment without detail. Option C deflects responsibility and avoids the core issue. Option D offers compensation, which can be perceived as minimizing the severity.
13 / 14
During a standup meeting, you're discussing a recent data breach notification. What should you *avoid* stating to avoid causing undue panic or misinterpretation?
Option A provides a reassuring update without specifics. However, option B avoids revealing crucial information – the *number* of affected users – which can fuel speculation and anxiety. Option C focuses on negative consequences, potentially escalating concern unnecessarily. Option D is a factual statement within the context of legal strategy.
14 / 14
You are drafting an API response message to be sent to a user after they have reported a suspected data breach. The response should include details about the incident and steps taken to mitigate the impact. Which of the following statements is MOST appropriate?
Option A expresses regret but doesn't offer concrete information. Option C is overly reassuring without detailing actions taken. Option D is vague and lacks specifics. Option B provides a balanced response – acknowledging the vulnerability, outlining immediate action, and promising updates, demonstrating transparency and responsibility.
What does the "Data Breach Notification Letters — Writing Vocabulary" exercise cover?
Learn to write legally sound, empathetic data breach notification letters.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
How many questions are in "Data Breach Notification Letters — Writing Vocabulary"?
This exercise has 14 questions. Each one gives instant feedback with an explanation, so you can see exactly why an answer is right or wrong.
Do I need to create an account to save my progress?
No account is required. The progress bar and score are tracked in your browser for the current session -- the exercise is designed to be a quick, repeatable drill rather than something you resume later.
What happens if I get an answer wrong?
You'll see the correct answer highlighted immediately, along with a short explanation of why it's correct. Wrong answers aren't penalized beyond your score, and you can keep going through every question.
How is this exercise different from reading an article?
Articles explain vocabulary and concepts through prose, while exercises like this one are interactive drills -- multiple-choice questions -- that test and reinforce your recall of specific terms and phrasing.
Can I retry this exercise?
Yes -- use the "Try again" button on the results screen to reset your score and go through all the questions again from the start.
Where can I find more External Crisis Communication exercises?
Browse the full External Crisis Communication hub for related drills, or check the site-wide exercises index for other IT English topics.
Is this exercise suitable for beginners?
This exercise assumes basic familiarity with IT terminology. If a term feels unfamiliar, check the site Glossary for a plain-English definition before attempting the questions.
How often is new content like this published?
New exercises are added regularly across all categories, alongside new vocabulary sets and articles. Check back on the exercises hub to see what's new.