breach-multi-jurisdiction skill
Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.
Is the breach-multi-jurisdiction skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the breach-multi-jurisdiction skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/breach-multi-jurisdiction ~/.claude/skills/breach-multi-jurisdiction
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Managing Multi-Jurisdiction Breach Notification
Overview
When a data breach affects individuals across multiple legal jurisdictions, the controller must navigate overlapping and sometimes conflicting notification requirements. The EU GDPR imposes a 72-hour supervisory authority notification deadline; US state laws impose varying timelines and content requirements; and other jurisdictions (Canada, Australia, Brazil, Japan, South Korea) have their own regimes. This skill provides the framework for coordinated notification across jurisdictions.
Jurisdiction Mapping — Notification Requirements
European Union — GDPR (All Member States)
United States — State Breach Notification Laws
Other International Jurisdictions
Conflict Resolution Framework
Principle 1: Meet the Shortest Deadline First
When notification timelines conflict, always prepare to meet the shortest applicable deadline. This typically means:
- EU/UK GDPR 72-hour deadline drives the primary notification timeline.
- US state notifications are prepared in parallel and dispatched as soon as the statutory requirement is met.
- The 72-hour GDPR notification often satisfies the "without unreasonable delay" standard in most US states.
Principle 2: Superset Content Approach
Prepare a single core notification document containing the superset of all content requirements across jurisdictions, then adapt for jurisdiction-specific formatting:
Principle 3: Parallel Execution Tracks
Manage notifications through parallel workstreams:
Track 1: EU/UK GDPR (72-hour priority)
- Lead SA notification within 72 hours
- Phased notification under Art. 33(4) if investigation is ongoing
- Art. 34 data subject notification within 7 days of high-risk determination
Track 2: US State Notifications (varies by state)
- AG notifications for each state where affected residents reside
- Individual notifications per state-specific requirements
- Substitute notice where individual notification is not feasible
Track 3: Other International Jurisdictions
- OAIC notification (Australia) within 30 days
- OPC notification (Canada) as soon as feasible
- Other jurisdictions as applicable
Lead Supervisory Authority Determination
For Stellar Payments Group with main establishment in Berlin, Germany:
- Lead SA: Berliner Beauftragte für Datenschutz und Informationsfreiheit
- Concerned SAs: Any SA in an EU member state where affected data subjects reside
- One-stop-shop mechanism: The lead SA coordinates with concerned SAs under Art. 60
- Exception: If the breach relates solely to an establishment in another member state, or substantially affects data subjects only in that state, the local SA may be the competent authority under Art. 56(2)
Notification Coordination Checklist
Pre-Notification (Within 24 Hours of Awareness)
- [ ] Determine which jurisdictions are affected based on data subject residency analysis
- [ ] Map applicable notification laws for each jurisdiction
- [ ] Identify the shortest notification deadline and set as primary driver
- [ ] Assign jurisdiction-specific notification leads (EU: DPO; US: General Counsel; APAC: Regional Privacy Manager)
- [ ] Engage external counsel in each jurisdiction as needed
EU/UK Track (72-Hour Deadline)
- [ ] Identify lead SA and prepare notification form
- [ ] Complete Art. 33(3) content requirements
- [ ] Submit notification to lead SA within 72 hours
- [ ] If cross-border, inform lead SA that multiple member states are affected
- [ ] Prepare Art. 34 data subject notification in languages of affected member states
US Track (Varies by State)
- [ ] Determine affected residents per state using postal/billing addresses
- [ ] For each state with 500+ affected residents, prepare AG notification
- [ ] Draft individual notification letters per state content requirements
- [ ] Include credit monitoring offer where required (SSN/financial data states)
- [ ] Engage outside US counsel for state-specific compliance review
- [ ] Submit AG notifications per each state's required timeline
- [ ] Dispatch individual notifications per each state's required timeline
International Track
- [ ] Prepare OAIC notification (Australia) within 30 days
- [ ] Prepare OPC notification (Canada) "as soon as feasible"
- [ ] Assess other jurisdictions (Brazil, Japan, South Korea, Singapore) based on affected populations
- [ ] Engage local counsel for jurisdiction-specific requirements
Coordination with Law Enforcement
In some jurisdictions, law enforcement authorities may request a delay in data subject notification to avoid prejudicing a criminal investigation:
- EU: EDPB Guidelines 9/2022 acknowledge that law enforcement may request delay; the controller should document the request and comply while still notifying the SA within 72 hours.
- US: Many state laws explicitly permit delay at law enforcement request. The delay must be documented and notification must proceed promptly upon law enforcement clearance.
- Best practice: Always notify the supervisory authority/AG on time even if data subject notification is delayed at law enforcement request.
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway