State Data Breach Notification Letter
ARIZONA DATA-INCIDENT NOTIFICATION PREPARATION PACKET
DO NOT SEND OR FILE: This packet collects facts and source decisions. It is not the operative notice.
1. Incident and Matter Record
| Field | Verified Entry |
|---|---|
| Matter / incident name | [________________________________] |
| Reporting entity exact legal name | [________________________________] |
| Entity role under review | [________________________________] |
| Incident discovered | [__/__/____] [TIME / ZONE] |
| Incident began / ended | [________________________________] |
| Unauthorized access, acquisition, disclosure, use, loss, or other event | [________________________________] |
| Systems, locations, and vendors involved | [________________________________] |
| Arizona residents potentially involved | [________________________________] |
| Other jurisdictions potentially involved | [________________________________] |
| Responsible counsel | [________________________________] |
| Incident-response lead | [________________________________] |
| Law-enforcement contact or request | [________________________________] |
2. Current Official Source Register
| Source Set | Official URL / Record | Version / Currency Date | Incident Effect | Reviewer / Date |
|---|---|---|---|---|
| Arizona data-breach statute | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Current Arizona Attorney General instructions, form, or portal | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Current resident-notice content and method source | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Current regulator and consumer-reporting notification source | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Federal or sector-specific privacy and security law | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Contract, policy, insurance, or regulator obligation | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Other state, tribal, territorial, or foreign law | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
☐ Pending, enacted, and recently effective amendments were checked.
☐ Current agency contact information and submission method were confirmed.
3. Entity Role and Data-Control Map
| Data Set / System | Owner / Licensee / Controller | Maintainer / Processor / Vendor | Contract Notice Route | Arizona Role Decision | Evidence |
|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
Owner/licensee or other upstream notification required: [________________________________]
Downstream service-provider or vendor notification required: [________________________________]
4. Person and Data-Element Analysis
Do not treat a general label such as “personal data,” “PII,” “health data,” or “credentials” as a statutory conclusion.
| Person / Cohort | Residence Source | Data Element | Combination / Identifier | Encryption and Key Status | Current Definition / Subsection | Included? |
|---|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [YES / NO / UNCERTAIN] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [YES / NO / UNCERTAIN] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [YES / NO / UNCERTAIN] |
Public-record, encrypted-data, good-faith, or other exclusion analysis: [________________________________]
5. Event, Acquisition, and Risk Analysis
| Issue | Fact and Evidence | Current Source / Standard | Conclusion | Reviewer |
|---|---|---|---|---|
| Unauthorized actor or invalid authorization | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Access, acquisition, disclosure, use, loss, or possession | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Security, confidentiality, or integrity effect | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Identity theft, fraud, misuse, harm, or risk standard | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Good-faith employee or agent route | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Encryption, key, tokenization, or redaction route | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Written no-notice or exception determination | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
6. Notification Decision Matrix
| Recipient / Communication | Trigger | Count / Threshold Rule | Deadline and Start Event | Delay / Exception | Required Method | Decision |
|---|---|---|---|---|---|---|
| Arizona resident | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Arizona Attorney General | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Consumer reporting agency | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Owner, licensee, controller, or upstream party | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Sector regulator or federal agency | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Insurer, law enforcement, customer, or contract party | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
Master deadline source and calculation record: [________________________________]
Law-enforcement delay request, scope, authority, and release: [________________________________]
7. Operative Resident-Notice Content Map
Draft the operative notice only after counsel completes this table from the current source.
| Content Item | Required / Optional / Prohibited | Approved Incident Fact | Source / Reviewer | Final Notice Location |
|---|---|---|---|---|
| Reporting entity identity and contact | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Incident description | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Incident and discovery dates or ranges | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Data categories involved | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Entity response and mitigation | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Individual protective steps | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Regulator, consumer-reporting, and identity-theft resources | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Credit monitoring or restoration offer | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Call-center and accessibility information | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Information excluded from resident notice | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
8. Operative Regulator Submission Map
| Submission Field / Attachment | Current Requirement | Approved Fact / Record | Confidentiality Treatment | Final Submission Location |
|---|---|---|---|---|
| Reporting entity and contact | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Incident chronology | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Resident and nationwide counts | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Data categories and affected systems | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Resident-notice timing, method, and template | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Investigation, containment, and remediation | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Law-enforcement, insurer, vendor, and regulator coordination | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Other required attachment or certification | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
9. Delivery, Accessibility, and Substitute Notice
| Method | Permitted Source and Conditions | Recipient Data Quality | Vendor / Channel | Test and Approval | Delivery Evidence |
|---|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] | |
| Electronic | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Telephone or other direct method | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Substitute notice | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| Accessible or translated format | [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
10. Accuracy and Communication Controls
☐ Each statement is supported by the incident investigation and approved evidence.
☐ No statement of “no fraud,” “no misuse,” containment, eradication, encryption, or affected count exceeds the evidence.
☐ Consumer, regulator, employee, customer, media, insurer, vendor, and law-enforcement communications are reconciled.
☐ Privilege, work-product, confidentiality, public-records, and litigation-hold issues were reviewed.
☐ URLs, telephone numbers, enrollment codes, hours, deadlines, and agency contacts were tested immediately before release.
☐ Translation, disability access, deceased persons, minors, returned mail, and undeliverable notices were addressed.
11. Operative Document and Approval Record
This packet remains non-operative. List each separately approved notice or filing.
| Document / Submission | Version | Recipient / Channel | Legal Approval | Sent / Filed Record |
|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [________________________________] | [________________________________] |
12. Completion Checklist
☐ Current official Arizona law and Attorney General procedure were read and recorded
☐ Entity role, resident status, data elements, combinations, encryption, access, acquisition, and risk were analyzed
☐ Resident, regulator, consumer-reporting, owner/licensee, sector, contract, and other-state routes were separated
☐ Every deadline uses the correct trigger, delay rule, and current source
☐ Required, optional, and prohibited content is mapped for each recipient
☐ Delivery, substitute notice, accessibility, translation, and proof records are complete
☐ Operative notices and submissions were separately drafted, approved, tested, and sent through current channels
END OF NON-OPERATIVE PREPARATION PACKET
About this template
- Last updated
- August 29, 2026
- Citations checked
- August 29, 2026
- Jurisdiction
- Arizona
- Category
- Legal Letters & Correspondence
Formal legal letters create a written record, trigger response deadlines, and often preserve rights under a statute or contract. Cease-and-desist letters, notice letters, and formal responses all have their own expected format, and the language used can mean the difference between a quick resolution and a courtroom fight. Well-drafted correspondence also documents that you tried to resolve things reasonably, which matters if the dispute escalates later.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 29, 2026.
Draft your State Data Breach Notification Letter in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.