skills/legal/data-breach-consumer-notice/SKILL.md
Drafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produces compliance scoping tables, data-element disclosures, remediation summaries, and consumer protection guidance tailored to incident facts and recipient cohorts. Use for multi-state breach letters, consumer breach notification, security incident notice, PII exposure notice, or sector-specific breach compliance.
npx skillsauth add casemark/skills data-breach-consumer-noticeInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a legally compliant consumer breach notice letter tailored to incident facts, affected data types, and multi-state statutory requirements.
Map each affected jurisdiction to its requirements:
| State | Statute/Regime | Notice Deadline | Required Content Add-ons | Delivery Method | Regulator Notice | |---|---|---|---|---|---| | {State} | {Cite} | {Days} | {State-specific items} | {Mail/Email/Substitute} | {AG/Agency, date} |
Draft to the most stringent standard across all jurisdictions. Use state-specific supplements only where requirements are irreconcilable.
| Data Category | Affected? | Scope | |---|---|---| | Name and contact info | Yes/No | {Detail} | | SSN or government ID | Yes/No | {Detail} | | Financial account or card data | Yes/No | {Detail} | | Medical or health info | Yes/No | {Detail} | | Login credentials | Yes/No | {Detail} | | Other personal data | Yes/No | {Specify} |
If different cohorts had different exposure, flag the need for individualized letter variants.
| Action | Status | Details | |---|---|---| | Containment | Done/In progress | {Summary} | | Forensic investigation | Done/In progress | {Vendor, scope} | | Law enforcement notice | Yes/No | {Agency, date} | | Security enhancements | Done/In progress | {Controls} | | Regulator notice | Yes/No | {Agency, date} |
Use the following sections in order:
Formatting: official letterhead, 12-point readable font, 1–2 pages, accessible format if electronic.
| Issue | Resolution | |---|---| | Conflicting state deadlines | Use the shortest deadline; document the conflict and rationale | | Unknown data elements for some recipients | Draft a general-population variant covering all possible elements; refine as forensics complete | | Law enforcement delay request | Document the request, defer notice per statute, resume on clearance or statutory expiry | | Substitute notice threshold unclear | Check state-specific thresholds (typically 500K+ affected or $250K+ cost); document the analysis | | Sector regime overlap (e.g., HIPAA + state) | Satisfy both; HIPAA 60-day ceiling does not override shorter state deadlines |
Key changes from the original:
development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.