Agent skill

Ca Breach Notification

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law).

Apache-2.0Auto-check passedLegal & Compliance

Install Ca Breach Notification

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill ca-breach-notification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills ca-breach-notification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/ca-breach-notification .claude/skills/ca-breach-notification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ca-breach-notification
GitHub stars
297
Token cost
~2k tokens
SKILL.md length
953 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law).

  • Works in 7 steps: Name and contact information of the… → List of the types of personal… → Date of the breach (if known) and the… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Covered Data Elements — Cal.…, Notification Timing — "Most… and AG Notification — §1798.82(f), plus 7 more sections
  • Runs Python scripts from its folder

What it does

Ca Breach Notification is an agent skill from mukul975/Privacy-Data-Protection-Skills. Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law). Covers data elements triggering notification, timing requirements (most expedient time possible), AG notification for 500+ California residents, specific content and format requirements, and substitute notice provisions. Keywords: California, breach notification, Cal. Civ. Code 1798.82, attorney general, CCPA, data elements.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the ca-breach-notification skill to execute breach notification under California Civil Code Section 1798.82 (California data breach notification…”
  • “/ca-breach-notification”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Name and contact information of the notifying entity.
  2. List of the types of personal information that were or are reasonably believed to have been the subject of the breach.
  3. Date of the breach (if known) and the date of the notice.
  4. Whether notification was delayed as a result of a law enforcement investigation (if applicable).
  5. General description of the breach incident, if that information is possible to determine at the time of notice.
  6. Toll-free telephone numbers, addresses, and websites for the major credit reporting agencies (if the breach involved a Social Security…
  7. Statement about availability of a security freeze (if SSN is involved): information about the right to place a security freeze on credit…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ca Breach Notification loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 953 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 953 words, ~1,992 tokens.

Download SKILL.mdSave it as .claude/skills/ca-breach-notification/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ca-breach-notification
description
Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law). Covers data elements triggering notification, timing requirements (most expedient time possible), AG notification for 500+ California residents, specific content and format requirements, and substitute notice provisions. Keywords: California, breach notification, Cal. Civ. Code 1798.82, attorney general, CCPA, data elements.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
california, breach-notification, civil-code-1798-82, attorney-general, ccpa

Executing California Breach Notification

Overview

California was the first US state to enact a data breach notification law (SB 1386, 2003). Cal. Civ. Code §1798.82 requires any person, business, or state agency that owns or licenses computerized data containing personal information to notify California residents when unencrypted personal information has been (or is reasonably believed to have been) acquired by an unauthorized person. The California Attorney General must be notified when more than 500 California residents are affected.

Covered Data Elements — Cal. Civ. Code §1798.81.5(d)

A breach notification is triggered when an individual's first name or first initial and last name is combined with any of the following unencrypted or unredacted data elements:

Data ElementCategory
Social Security numberGovernment identifier
Driver's license number or California identification card numberGovernment identifier
Financial account number, credit card number, or debit card number, in combination with any required security code, access code, or passwordFinancial
Medical informationHealth
Health insurance informationHealth
Unique biometric data (fingerprint, retina, iris image, or other unique physical representation or digital representation used for authentication)Biometric
Information or data collected through automated license plate recognition systemsSurveillance
Genetic dataGenetic
A username or email address, in combination with a password or security question and answer that would permit access to an online accountCredentials
Tax identification numberGovernment identifier

Note: "Personal information" does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.

Notification Timing — "Most Expedient Time Possible"

Cal. Civ. Code §1798.82(a): Notification must be made "in the most expedient time possible and without unreasonable delay."

What Constitutes "Unreasonable Delay"
  • The statute does not define a specific number of days.
  • California AG guidance interprets this as requiring notification as soon as the investigation has progressed sufficiently to determine that notification is required.
  • Investigation and law enforcement coordination are recognized legitimate reasons for delay.
  • Internal approval processes and desire to prepare PR responses are NOT legitimate reasons for delay.
Law Enforcement Delay — §1798.82(c)

Notification may be delayed if a law enforcement agency determines that notification would impede a criminal investigation. The notification must be made "promptly" after the law enforcement agency determines notification will not compromise the investigation.

AG Notification — §1798.82(f)

RequirementDetail
Threshold500 or more California residents affected
MethodElectronic submission to the California AG's office (oag.ca.gov/privacy/databreach/reporting)
ContentSample copy of the individual notification letter
TimingConcurrent with or before individual notification

Individual Notification Content Requirements — §1798.82(d)

The notification must include:

  1. Name and contact information of the notifying entity.
  2. List of the types of personal information that were or are reasonably believed to have been the subject of the breach.
  3. Date of the breach (if known) and the date of the notice.
  4. Whether notification was delayed as a result of a law enforcement investigation (if applicable).
  5. General description of the breach incident, if that information is possible to determine at the time of notice.
  6. Toll-free telephone numbers, addresses, and websites for the major credit reporting agencies (if the breach involved a Social Security number, driver's license number, or California identification card number).
  7. Statement about availability of a security freeze (if SSN is involved): information about the right to place a security freeze on credit files under Cal. Civ. Code §1785.11.2.
Show full SKILL.md (400 more words)Show less

Format Requirements — §1798.82(d)

California has specific formatting requirements for breach notification letters:

  • Title: "Notice of Data Breach" — must be prominently displayed.
  • Headings: Must use the following headings (or substantially similar):
    • "What Happened"
    • "What Information Was Involved"
    • "What We Are Doing"
    • "What You Can Do"
    • "For More Information"
  • Font: 10-point type or larger.
  • Language: Written in plain, easily understood language.

Substitute Notice — §1798.82(j)

Substitute notice is permitted when:

  • The cost of individual notice exceeds $250,000; OR
  • The number of affected persons exceeds 500,000; OR
  • The entity does not have sufficient contact information.

Substitute notice must include ALL of the following:

  1. Email notice to affected persons for whom email addresses are available.
  2. Conspicuous posting on the entity's website.
  3. Notification to major statewide media.

Encryption Safe Harbor

Encrypted personal information is excluded from the notification requirement IF:

  • The encryption key has not been (and is not reasonably believed to have been) acquired by an unauthorized person.
  • The data was encrypted using an algorithm that meets industry standards (AES-128 or higher).

Interaction with CCPA/CPRA

The California Consumer Privacy Act (CCPA) as amended by CPRA provides a private right of action for data breaches under Cal. Civ. Code §1798.150:

  • Applies when "nonencrypted and nonredacted personal information" is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's failure to implement reasonable security.
  • Statutory damages: $100 to $750 per consumer per incident, OR actual damages (whichever is greater).
  • Must provide 30-day cure notice before filing suit.

Key Enforcement Actions

  • Hanna Andersson (2020): $400,000 settlement for delayed notification of a Magecart web-skimming breach affecting California consumers. AG cited failure to notify "in the most expedient time possible."
  • DoorDash (2020): AG investigation into breach affecting 4.9 million individuals. AG scrutinized the adequacy and timeliness of notification.
  • T-Mobile (2022): $350 million class-action settlement (national) with significant California consumer component. AG office monitored compliance with California-specific notification requirements.

Sample AG Submission Cover Letter

To: California Office of the Attorney General Privacy Enforcement Section oag.ca.gov/privacy/databreach/reporting

Re: Data Breach Notification — Stellar Payments Group Breach Date: 13 March 2026 California Residents Affected: 2,340

Pursuant to Cal. Civ. Code §1798.82(f), Stellar Payments Group hereby provides notice of a data breach affecting 2,340 California residents. Enclosed is a sample copy of the notification letter being sent to affected individuals. Individual notifications will be dispatched on 28 March 2026.

Contact: Dr. Elena Vasquez, DPO, dpo@stellarpayments.eu, +1 (202) 555-0142.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/ca-breach-notification of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Ca Breach Notification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ca Breach Notification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ca Breach Notification this skillmukul975/Privacy-Data-Protection-Skills297—~2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Ca Breach Notification

What does Ca Breach Notification do?

Executes breach notification under California Civil Code Section 1798.82 (California data breach notification law). Ca Breach Notification is an agent skill from mukul975/Privacy-Data-Protection-Skills.82 (California data breach notification law).

When should I use Ca Breach Notification?

Ca Breach Notification fits situations like: tasks that involve Privacy and GDPR.

How do I install Ca Breach Notification in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ca-breach-notification -a claude-code`. Or copy the skill folder (skills/privacy/ca-breach-notification in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/ca-breach-notification in your project. Claude Code loads it when a task matches its description.

How do I install Ca Breach Notification in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ca-breach-notification -a codex`. Or copy the skill folder (skills/privacy/ca-breach-notification in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/ca-breach-notification in your project. Codex loads it when a task matches its description.

Can I use Ca Breach Notification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ca-breach-notification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ca-breach-notification, .gemini/skills/ca-breach-notification, .github/skills/ca-breach-notification and .opencode/skills/ca-breach-notification in your project.

What does Ca Breach Notification need to run?

Going by SKILL.md and its folder, Ca Breach Notification needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Ca Breach Notification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ca Breach Notification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ca Breach Notification use?

Ca Breach Notification is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ca Breach Notification use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Ca Breach Notification?

Skills that share tags, products or a category with Ca Breach Notification: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ca Breach Notification?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.