Every company that handles customer data will eventually have to write one of these. The instinct, understandably, is to hand it to counsel and let the legal team own the language, because the stakes are regulatory and the downside of saying the wrong thing is a lawsuit. That instinct is correct about who should review the document. It is wrong about who the document is actually for.
A breach notice has exactly one reader who matters commercially: the customer deciding, in the sixty seconds it takes to read the email, whether to stay. That customer is not weighing your liability exposure. They are weighing whether the people who run this company are the kind who tell them things straight, or the kind who make them read between legal hedges to find out what actually happened.
The tell is always the same
Legally-optimized breach notices share a pattern: passive voice, vague scope (“certain information may have been accessed”), and a timeline that starts with “we recently discovered” without saying when the incident actually occurred relative to the discovery. Every one of those choices is defensible in a deposition and corrosive to trust, because a reader who has seen a breach notice before recognizes the hedging instantly. It reads as a company protecting itself first and the customer second, even when that is not what happened internally.
What the better version does differently
The disclosures that actually hold a customer base together say, plainly: here is what happened, here is when we found out, here is exactly what was and was not exposed, here is what we have already done about it, and here is what you should do right now. Specificity is not a legal risk when the facts support it - it is the only thing that reads as competence under pressure. A company that can describe its own failure precisely is a company that understands its own systems, and customers register that, even in a bad moment.
The sequencing that actually works
This does not mean skipping legal review. It means the founder or the person customers trust drafts the human version first, with the facts as known, and legal edits for accuracy and exposure rather than rewriting for caution. Draft for trust, then clear for risk - not the other way around. The companies that get this backwards usually find out the cost later, in churn that shows up weeks after the incident is already closed, once the news is old but the memory of how it was handled is not.