Agent skill

Breach Documentation

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required.

Apache-2.0Auto-check passedLegal & Compliance

Install Breach Documentation

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-documentation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-documentation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-documentation .claude/skills/breach-documentation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-documentation
GitHub stars
295
Token cost
~2.4k tokens
SKILL.md length
1,118 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required.

  • Works in 4 steps: Instant availability: The register must… → Completeness verification: Monthly… → Cross-reference integrity: Each register… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Mandatory Documentation…, Notification Decision… and Register Structure and…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Breach Documentation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Audit readiness. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Audit readiness

Example prompts

  • “Use the breach-documentation skill to maintain the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether…”
  • “/breach-documentation”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Instant availability: The register must be exportable in a structured format (CSV, JSON, PDF) within 24 hours of a supervisory authority…
  2. Completeness verification: Monthly self-audit to verify all reported security incidents were assessed for personal data impact and, where…
  3. Cross-reference integrity: Each register entry must link to supporting documentation (risk assessment form, SA notification copy, DS…
  4. Trend reporting: The register must support generation of trend reports showing: breach frequency over time, breach types, root cause…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Documentation loads about 2.4k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 1,118 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,118 words, ~2,397 tokens.

Download SKILL.mdSave it as .claude/skills/breach-documentation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
breach-documentation
description
Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
breach-register, article-33-5, documentation, accountability, audit, remedial-actions

Maintaining Breach Documentation Records

Overview

Article 33(5) of the GDPR requires every controller to document all personal data breaches, regardless of whether the breach triggered supervisory authority notification. The documentation must include "the facts relating to the personal data breach, its effects and the remedial action taken" and must "enable the supervisory authority to verify compliance with this Article." This creates a comprehensive breach register that serves as a primary accountability document under Art. 5(2).

Mandatory Documentation Requirements — Art. 33(5)

Facts Relating to the Breach

Every breach register entry must document:

FieldDescriptionExample
Breach reference numberUnique sequential identifierSPG-BREACH-2026-003
Discovery date and timeUTC timestamp when controller became aware13 March 2026, 14:30 UTC
Breach date and timeUTC timestamp of the breach itself (if different from discovery)13 March 2026, 11:15 UTC
Breach typeConfidentiality, integrity, availability, or combinedAvailability (primary), Confidentiality (under investigation)
Breach descriptionFactual narrative of what occurredLockBit 3.0 ransomware encrypted production customer database cluster. Attack vector: compromised service account obtained via spear-phishing.
Affected systemsSystems involved in the breachdb-prod-eu-west-01 through db-prod-eu-west-04
Data subject categoriesTypes of individuals affectedIndividual account holders, business account holders, joint account holders
Data subject countApproximate number of affected individuals15,230
Personal data categoriesTypes of data compromisedNames, postal addresses, emails, payment card last-4, transaction histories, account balances
Record countApproximate number of affected records48,720
Root causeIdentified cause of the breachStale privileged service account + phishing + push-fatigue MFA bypass
Containment timestampWhen the breach was contained13 March 2026, 12:45 UTC
Effects of the Breach
FieldDescriptionExample
Risk assessment scoreAggregate score from the risk assessment methodology18/24
Risk levelResulting risk determinationApproaching high risk
Actual harm identifiedAny confirmed harm to data subjectsNo confirmed harm as of assessment date
Potential harmLikely consequences if data is misusedFinancial fraud, identity theft, targeted phishing
Duration of impactHow long data subjects were affected36 hours (database unavailability); ongoing (potential confidentiality impact)
Remedial Actions Taken
FieldDescriptionExample
Containment measuresImmediate actions to stop the breachNetwork isolation, credential revocation, backup restoration
Remediation measuresLonger-term corrective actionsMFA upgrade to FIDO2, service account lifecycle management, network segmentation
Remediation statusCurrent status of each action4 of 7 measures completed; 3 in progress
Remediation deadlineTarget completion date15 June 2026

Notification Decision Documentation

Every breach entry must also record the notification decision and rationale:

FieldDescription
Art. 33 SA notification decisionRequired / Not required
Art. 33 notification rationaleWhy notification was or was not required (reference risk assessment)
Art. 33 notification dateDate and time of SA notification (if applicable)
SA reference numberReference number assigned by the supervisory authority
SA follow-up statusAny follow-up inquiries or actions from the authority
Art. 34 DS notification decisionRequired / Not required / Exempt under Art. 34(3)
Art. 34 notification rationaleWhy DS notification was or was not required
Art. 34 notification dateDate of DS communication (if applicable)
Art. 34 notification methodChannels used (email, postal, public communication)

Register Structure and Maintenance

Single Centralized Register

All breaches must be recorded in a single centralized register maintained by the DPO's office. Stellar Payments Group uses a dedicated module in the OneTrust Privacy Management Platform with the following access controls:

  • Write access: DPO, Deputy DPO, Privacy Incident Coordinator
  • Read access: CISO, General Counsel, Internal Audit, Board Audit Committee
  • No access: Business unit managers, IT operations staff (access to individual breach records provided on a need-to-know basis via separate reports)
All Breaches Documented — Including Non-Notifiable

The register must include every personal data breach, regardless of severity or whether SA/DS notification was triggered. This explicitly includes:

  • Misdirected emails containing personal data (even single-recipient incidents)
  • Temporary availability breaches resolved from backup
  • Unsuccessful exfiltration attempts where personal data was targeted but not accessed
  • Breaches at processors that affected the controller's data
  • Physical breaches (lost devices, unauthorized office access)
Show full SKILL.md (470 more words)Show less
Retention Period

Breach register entries are retained for a minimum of 7 years from the date of breach closure. This accounts for:

  • The 5-year statute of limitations for GDPR enforcement actions in most EU member states
  • The need to demonstrate patterns (or absence of patterns) to supervisory authorities
  • Litigation time limits for data subject compensation claims under Art. 82

After the 7-year retention period, entries are anonymized (data subject counts retained, specific identifiers removed) and maintained indefinitely for trend analysis.

Audit Readiness

Supervisory Authority Access — Art. 33(5)

The breach register must be available to the supervisory authority "on request." Audit readiness requires:

  1. Instant availability: The register must be exportable in a structured format (CSV, JSON, PDF) within 24 hours of a supervisory authority request.
  2. Completeness verification: Monthly self-audit to verify all reported security incidents were assessed for personal data impact and, where applicable, added to the register.
  3. Cross-reference integrity: Each register entry must link to supporting documentation (risk assessment form, SA notification copy, DS notification copy, investigation report, remediation evidence).
  4. Trend reporting: The register must support generation of trend reports showing: breach frequency over time, breach types, root cause categories, notification rates, and remediation completion rates.
Annual Breach Register Review

The DPO conducts an annual review of the breach register covering:

  1. Completeness: Are all known breaches documented? Cross-reference against the security incident management system.
  2. Accuracy: Sample 20% of entries and verify accuracy against source documentation.
  3. Timeliness: Were entries created within 72 hours of breach discovery?
  4. Remediation closure: Are remediation actions tracked to completion? Flag overdue actions.
  5. Pattern identification: Are there recurring breach types or root causes indicating systemic issues?
  6. Board reporting: Prepare an annual breach summary report for the Board Audit Committee.

Integration with Other Records

Related RecordIntegration Point
Art. 30 RoPALink affected processing activities to the breach entry
DPIA RegisterUpdate DPIAs for affected processing activities with breach as risk event
Vendor RegisterUpdate processor risk assessment if breach originated at a processor
Training RecordsDocument post-breach training delivered to relevant personnel
Audit LogReference internal audit findings related to the breach
Insurance RecordsLink to cyber insurance claim reference (if applicable)

Common Documentation Deficiencies

  1. Breaches documented in security incident systems but not in the Art. 33(5) register: The security incident ticket is not a substitute for the breach register entry.
  2. Missing notification decision rationale: Recording "not notified" without documenting why the breach was assessed as unlikely to result in risk.
  3. Incomplete remediation tracking: Remedial actions listed but never updated to reflect completion status.
  4. Delayed documentation: Entries created weeks after the breach, making it difficult to demonstrate timely awareness and response.
  5. No processor breach entries: Breaches that occur at processors but affect the controller's data are not recorded in the controller's register.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-documentation of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Breach Documentation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Documentation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Documentation this skillmukul975/Privacy-Data-Protection-Skills295—~2.4kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Breach Documentation

What does Breach Documentation do?

Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Breach Documentation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required.

When should I use Breach Documentation?

Breach Documentation fits situations like: tasks that involve Privacy and GDPR; tasks that involve Audit readiness.

How do I install Breach Documentation in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-documentation -a claude-code`. Or copy the skill folder (skills/privacy/breach-documentation in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-documentation in your project. Claude Code loads it when a task matches its description.

How do I install Breach Documentation in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-documentation -a codex`. Or copy the skill folder (skills/privacy/breach-documentation in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-documentation in your project. Codex loads it when a task matches its description.

Can I use Breach Documentation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-documentation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-documentation, .gemini/skills/breach-documentation, .github/skills/breach-documentation and .opencode/skills/breach-documentation in your project.

What does Breach Documentation need to run?

Going by SKILL.md and its folder, Breach Documentation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Breach Documentation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Documentation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Breach Documentation use?

Breach Documentation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Documentation use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Breach Documentation?

Skills that share tags, products or a category with Breach Documentation: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 526 stars) and Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Documentation?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.