Agent skill

Breach Multi Jurisdiction

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90…

Apache-2.0Auto-check passedLegal & Compliance

Install Breach Multi Jurisdiction

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-multi-jurisdiction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-multi-jurisdiction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-multi-jurisdiction .claude/skills/breach-multi-jurisdiction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-multi-jurisdiction
GitHub stars
301
Token cost
~2.6k tokens
SKILL.md length
1,170 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90…

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Jurisdiction Mapping —…, Conflict Resolution Framework and Lead Supervisory Authority…, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Breach Multi Jurisdiction is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the breach-multi-jurisdiction skill to manage coordinated breach notification across multiple legal jurisdictions including EU member states…”
  • “/breach-multi-jurisdiction”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Multi Jurisdiction loads about 2.6k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 134 tokens; SKILL.md has 1,170 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,170 words, ~2,570 tokens.

Download SKILL.mdSave it as .claude/skills/breach-multi-jurisdiction/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
breach-multi-jurisdiction
description
Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
multi-jurisdiction, cross-border-breach, notification-coordination, gdpr, us-state-laws

Managing Multi-Jurisdiction Breach Notification

Overview

When a data breach affects individuals across multiple legal jurisdictions, the controller must navigate overlapping and sometimes conflicting notification requirements. The EU GDPR imposes a 72-hour supervisory authority notification deadline; US state laws impose varying timelines and content requirements; and other jurisdictions (Canada, Australia, Brazil, Japan, South Korea) have their own regimes. This skill provides the framework for coordinated notification across jurisdictions.

Jurisdiction Mapping — Notification Requirements

European Union — GDPR (All Member States)
ElementRequirement
SA notification timeline72 hours from awareness (Art. 33(1))
SA notification thresholdUnless breach is "unlikely to result in a risk"
DS notification timelineWithout undue delay when "high risk" (Art. 34(1))
Lead SA determinationOne-stop-shop: Art. 56 lead SA based on main establishment
Cross-border mechanismLead SA notified; other concerned SAs informed via Art. 60
Content requirementsArt. 33(3)(a)-(d) for SA; Art. 34(2) for data subjects
United States — State Breach Notification Laws
StateTimelineAG NotificationThresholdKey Differences
CaliforniaMost expedient time possible, no unreasonable delayYes, if 500+ CA residentsName + specified data elementSubstitute notice for 500,000+ affected; specific template for health data
New YorkMost expedient time possible, no unreasonable delayAG, DFS, DOCS simultaneouslyPrivate information (name + data element)SHIELD Act: 30-day AG notification for NY residents
Texas60 days from determinationAG if 250+ TX residentsName + sensitive personal informationExpanded definition of sensitive data includes biometric identifiers
Florida30 days from determinationFDLE within 30 days if 500+Name + specified data elementOne of the shortest statutory deadlines
MassachusettsAs soon as practicableAG + OCABR simultaneouslyName + specified data elementRequires description of remedial services offered
IllinoisMost expedient time possible, no unreasonable delayAG if 500+ IL residentsName + specified data elementBIPA adds biometric data breach notification requirements
Virginia60 days from discoveryAG + affected individualsName + specified data elementVCDPA adds consumer data rights context
Colorado30 days from determinationAG within 30 days if 500+Name + specified data elementAmong the shortest deadlines alongside Florida
PennsylvaniaWithout unreasonable delayAG if notifyingName + specified data elementBroad definition of personal information
Washington30 days from discoveryAG within 30 days if 500+Name + specified data elementBiometric and health data included
Other International Jurisdictions
JurisdictionLawSA TimelineDS TimelineNotable
United KingdomUK GDPR + DPA 201872 hours (ICO)Without undue delayMirrors EU GDPR; ICO is sole SA
CanadaPIPEDA + provincial laws"As soon as feasible" to OPC"As soon as feasible"Real risk of significant harm (RROSH) threshold
AustraliaPrivacy Act 1988 (NDB scheme)30 days to OAICAs soon as practicable"Eligible data breach" = serious harm likely
BrazilLGPD"Reasonable time" to ANPD"Reasonable time"ANPD defines timeframes by regulation
JapanAPPIPromptly to PPC (3-5 days recommended)PromptlyMandatory for 1,000+ subjects or sensitive data
South KoreaPIPAWithin 72 hours to PIPCWithout delayMirrors GDPR timeline
SingaporePDPA3 calendar days to PDPCAs soon as practicableSignificant harm or significant scale threshold

Conflict Resolution Framework

Principle 1: Meet the Shortest Deadline First

When notification timelines conflict, always prepare to meet the shortest applicable deadline. This typically means:

  • EU/UK GDPR 72-hour deadline drives the primary notification timeline.
  • US state notifications are prepared in parallel and dispatched as soon as the statutory requirement is met.
  • The 72-hour GDPR notification often satisfies the "without unreasonable delay" standard in most US states.
Principle 2: Superset Content Approach

Prepare a single core notification document containing the superset of all content requirements across jurisdictions, then adapt for jurisdiction-specific formatting:

Content ElementGDPR Art. 33(3)California CC §1798.82New York GBL §899-aaTexas BCC §521.053
Nature of breachRequiredRequiredRequiredRequired
Data categories affectedRequiredRequired (specific elements)RequiredRequired
Data subject countRequired (approximate)Not required but recommendedRequiredRequired
DPO/contact detailsRequiredContact details requiredContact details requiredContact details required
Likely consequencesRequiredNot explicitly requiredNot explicitly requiredNot explicitly required
Measures takenRequiredRemedial actions requiredRemedial actions requiredRequired
Credit monitoring offerNot required (but common)Required for SSN/financialRecommendedRequired for SSN
SA notification referenceRequiredAG notification requiredAG notification requiredAG notification required
Show full SKILL.md (475 more words)Show less
Principle 3: Parallel Execution Tracks

Manage notifications through parallel workstreams:

Track 1: EU/UK GDPR (72-hour priority)

  • Lead SA notification within 72 hours
  • Phased notification under Art. 33(4) if investigation is ongoing
  • Art. 34 data subject notification within 7 days of high-risk determination

Track 2: US State Notifications (varies by state)

  • AG notifications for each state where affected residents reside
  • Individual notifications per state-specific requirements
  • Substitute notice where individual notification is not feasible

Track 3: Other International Jurisdictions

  • OAIC notification (Australia) within 30 days
  • OPC notification (Canada) as soon as feasible
  • Other jurisdictions as applicable

Lead Supervisory Authority Determination

For Stellar Payments Group with main establishment in Berlin, Germany:

  • Lead SA: Berliner Beauftragte für Datenschutz und Informationsfreiheit
  • Concerned SAs: Any SA in an EU member state where affected data subjects reside
  • One-stop-shop mechanism: The lead SA coordinates with concerned SAs under Art. 60
  • Exception: If the breach relates solely to an establishment in another member state, or substantially affects data subjects only in that state, the local SA may be the competent authority under Art. 56(2)

Notification Coordination Checklist

Pre-Notification (Within 24 Hours of Awareness)
  • Determine which jurisdictions are affected based on data subject residency analysis
  • Map applicable notification laws for each jurisdiction
  • Identify the shortest notification deadline and set as primary driver
  • Assign jurisdiction-specific notification leads (EU: DPO; US: General Counsel; APAC: Regional Privacy Manager)
  • Engage external counsel in each jurisdiction as needed
EU/UK Track (72-Hour Deadline)
  • Identify lead SA and prepare notification form
  • Complete Art. 33(3) content requirements
  • Submit notification to lead SA within 72 hours
  • If cross-border, inform lead SA that multiple member states are affected
  • Prepare Art. 34 data subject notification in languages of affected member states
US Track (Varies by State)
  • Determine affected residents per state using postal/billing addresses
  • For each state with 500+ affected residents, prepare AG notification
  • Draft individual notification letters per state content requirements
  • Include credit monitoring offer where required (SSN/financial data states)
  • Engage outside US counsel for state-specific compliance review
  • Submit AG notifications per each state's required timeline
  • Dispatch individual notifications per each state's required timeline
International Track
  • Prepare OAIC notification (Australia) within 30 days
  • Prepare OPC notification (Canada) "as soon as feasible"
  • Assess other jurisdictions (Brazil, Japan, South Korea, Singapore) based on affected populations
  • Engage local counsel for jurisdiction-specific requirements

Coordination with Law Enforcement

In some jurisdictions, law enforcement authorities may request a delay in data subject notification to avoid prejudicing a criminal investigation:

  • EU: EDPB Guidelines 9/2022 acknowledge that law enforcement may request delay; the controller should document the request and comply while still notifying the SA within 72 hours.
  • US: Many state laws explicitly permit delay at law enforcement request. The delay must be documented and notification must proceed promptly upon law enforcement clearance.
  • Best practice: Always notify the supervisory authority/AG on time even if data subject notification is delayed at law enforcement request.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-multi-jurisdiction of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Breach Multi Jurisdiction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Multi Jurisdiction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Multi Jurisdiction this skillmukul975/Privacy-Data-Protection-Skills301—~2.6kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Breach Multi Jurisdiction

What does Breach Multi Jurisdiction do?

Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90…. Breach Multi Jurisdiction is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes.

When should I use Breach Multi Jurisdiction?

Breach Multi Jurisdiction fits situations like: tasks that involve Privacy and GDPR.

How do I install Breach Multi Jurisdiction in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-multi-jurisdiction -a claude-code`. Or copy the skill folder (skills/privacy/breach-multi-jurisdiction in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-multi-jurisdiction in your project. Claude Code loads it when a task matches its description.

How do I install Breach Multi Jurisdiction in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-multi-jurisdiction -a codex`. Or copy the skill folder (skills/privacy/breach-multi-jurisdiction in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-multi-jurisdiction in your project. Codex loads it when a task matches its description.

Can I use Breach Multi Jurisdiction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-multi-jurisdiction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-multi-jurisdiction, .gemini/skills/breach-multi-jurisdiction, .github/skills/breach-multi-jurisdiction and .opencode/skills/breach-multi-jurisdiction in your project.

What does Breach Multi Jurisdiction need to run?

Going by SKILL.md and its folder, Breach Multi Jurisdiction needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Breach Multi Jurisdiction access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Multi Jurisdiction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Breach Multi Jurisdiction use?

Breach Multi Jurisdiction is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Multi Jurisdiction use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Breach Multi Jurisdiction?

Skills that share tags, products or a category with Breach Multi Jurisdiction: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Multi Jurisdiction?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.