C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-comms --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-subject-comms .claude/skills/breach-subject-comms && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .claude/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-commsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-comms --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/breach-subject-comms .agents/skills/breach-subject-comms && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .agents/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-comms --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/breach-subject-comms .cursor/skills/breach-subject-comms && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .cursor/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/breach-subject-comms--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-comms --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/breach-subject-comms .gemini/skills/breach-subject-comms && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .gemini/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-commsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/breach-subject-comms .github/skills/breach-subject-comms && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .github/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-subject-comms --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/breach-subject-comms .opencode/skills/breach-subject-comms && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "breach-subject-comms" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-subject-comms into .opencode/skills/breach-subject-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "breach-subject-comms", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
breach-subject-commsManages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms.
Breach Subject Comms is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Covers the high risk threshold, required notification content per Art. 34(2), exemptions under Art. 34(3), and breach notification letter templates for five scenarios. Keywords: data subject notification, Article 34, high risk, breach communication, GDPR.
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Breach Subject Comms loads about 4.6k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 2,485 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,485 words, ~4,616 tokens.
.claude/skills/breach-subject-comms/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Article 34 of the GDPR requires controllers to communicate a personal data breach to affected data subjects "without undue delay" when the breach is "likely to result in a high risk to the rights and freedoms of natural persons." This obligation is separate from and additional to the Art. 33 supervisory authority notification. The communication must be in clear and plain language, directly accessible to the affected individuals, and must contain specific information prescribed by Art. 34(2).
Art. 34 notification is triggered when the breach risk assessment yields a "high risk" determination. Per EDPB Guidelines 9/2022, Section 3.2, high risk is present when:
The data subject communication must contain, at minimum, the information specified in Art. 33(3)(b), (c), and (d):
A controller may be exempt from direct data subject notification in three circumstances:
The controller has applied appropriate technical and organisational protection measures that render the personal data unintelligible to any person who is not authorized to access it, such as encryption.
Requirements for this exemption:
The controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise.
Requirements for this exemption:
Individual notification would involve disproportionate effort, in which case a public communication or similar measure shall be made instead.
Requirements for this exemption:
Subject: Important Security Notice — Your Payment Information May Have Been Affected
Dear [Data Subject Name],
We are writing to inform you of a security incident that may have affected your personal and payment information held by Stellar Payments Group.
What happened: On 13 March 2026, we detected unauthorized access to our payment processing database. Our investigation determined that an external attacker gained access to a subset of customer payment records between 10 March and 13 March 2026.
What information was involved: Your name, email address, billing address, and payment card details (card number, expiry date, and CVV) associated with your Stellar Payments account were among the records accessed.
What we are doing:
What you can do:
Free credit monitoring: We are offering all affected customers 12 months of complimentary credit monitoring through Experian IdentityWorks. To enroll, visit stellarpayments.eu/breach-support and use activation code SPG-2026-PROTECT. Enrollment is available until 30 June 2026.
Contact us: If you have questions, our dedicated breach response team is available at:
Our Data Protection Officer, Dr. Elena Vasquez, can be reached at dpo@stellarpayments.eu or +49 30 7742 8001.
We sincerely regret this incident and are committed to preventing any recurrence.
Regards, Marcus Lindqvist Chief Executive Officer Stellar Payments Group
Subject: Important Notice Regarding Your Health Information
Dear [Data Subject Name],
We are contacting you to inform you of a security incident involving your health information held by Stellar Payments Group's employee wellness programme.
What happened: On 5 March 2026, we discovered that an employee in our IT department accessed the occupational health database without authorization between 1 February and 4 March 2026. This database contains health screening results and sick leave records for employees enrolled in our wellness programme.
What information was involved: Your name, employee number, date of birth, health screening results (including blood pressure, cholesterol, and BMI readings), and sick leave history for 2025-2026.
What we are doing:
What you can do:
Counselling support: We have arranged confidential counselling support through our Employee Assistance Programme (EAP) provider, Workplace Options, available 24/7 at +49 800 100 0287 (reference: SPG-Health-2026).
Contact us:
Regards, Dr. Elena Vasquez Data Protection Officer Stellar Payments Group
Subject: Action Required — Your Stellar Payments Account Credentials May Be Compromised
Dear [Data Subject Name],
We are writing to inform you that your Stellar Payments account login credentials may have been exposed in a security incident.
What happened: On 20 March 2026, our security monitoring systems detected that a database backup file containing customer account credentials was inadvertently stored on an unsecured cloud storage instance between 15 March and 20 March 2026.
What information was involved: Your email address, username, and hashed password for your Stellar Payments account. While passwords were stored in a hashed format (bcrypt with a cost factor of 12), we are treating this as a high-risk breach because sophisticated attackers may attempt to reverse the hashes.
What we are doing:
What you must do immediately:
Contact us:
Regards, Thomas Brenner Chief Information Security Officer Stellar Payments Group
Subject: Service Disruption Notice — Your Data Was Temporarily Unavailable
Dear [Data Subject Name],
We are writing to inform you of a security incident that temporarily affected access to your account data.
What happened: On 13 March 2026, Stellar Payments Group experienced a ransomware attack that encrypted portions of our customer database. This made your account data temporarily unavailable for approximately 36 hours while we restored systems from secure backups.
What information was affected: Your account data (name, contact details, transaction history, and account balance) was rendered inaccessible during the incident. Our forensic investigation has confirmed that no data was exfiltrated (copied or stolen) during the attack. The data was encrypted in place and has been fully restored.
What we are doing:
What you should do:
Contact us:
Regards, Marcus Lindqvist Chief Executive Officer Stellar Payments Group
Subject: Important Notice Regarding Your Employment Records
Dear [Data Subject Name],
We are writing to inform you of a security incident involving your employment records held by Stellar Payments Group.
What happened: On 1 March 2026, our data loss prevention system detected that a departing employee in the People Operations department transferred a file containing employee records to a personal cloud storage account on 27 February 2026. We immediately launched an investigation and recovered the data.
What information was involved: Your name, employee number, home address, personal email address, date of birth, salary information, bank account details for payroll, and national insurance/social security number.
What we are doing:
What you can do:
Free identity protection: We are providing all affected employees with 24 months of complimentary identity theft protection through Experian IdentityWorks, including dark web monitoring, credit monitoring, and EUR 25,000 identity theft insurance. Enrollment details are available on the HR portal under Benefits > Breach Support, or contact hr-confidential@stellarpayments.eu.
Contact us:
Regards, Dr. Elena Vasquez Data Protection Officer Stellar Payments Group
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-subject-comms of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Breach Subject Comms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Breach Subject Comms this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Breach Subject Comms is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms.
Breach Subject Comms fits situations like: tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a claude-code`. Or copy the skill folder (skills/privacy/breach-subject-comms in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-subject-comms in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a codex`. Or copy the skill folder (skills/privacy/breach-subject-comms in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-subject-comms in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-subject-comms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-subject-comms, .gemini/skills/breach-subject-comms, .github/skills/breach-subject-comms and .opencode/skills/breach-subject-comms in your project.
Going by SKILL.md and its folder, Breach Subject Comms needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Breach Subject Comms is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Breach Subject Comms: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.