GDPR Breach Response Sentinel
Skill Verified ActiveElite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a data breach or security incident, (2) User asks about breach notification obligations or deadlines, (3) User mentions "72 hours", Art. 33, Art. 34, or notification requirements, (4) Discussion involves security incidents affecting personal data, (5) User needs breach risk assessment using ENISA methodology, (6) User mentions "Data Breach" or "Incident" or "Data Leakage" or "Ransomeware" or "Exfiltration", (7) User needs to determine Controller vs Processor obligations, (8) Cross-border breach scenarios requiring Lead SA determination, (9) User needs a mitigation playbook or immediate response recommendations, (10) User needs to generate audit-ready breach documentation (.docx).
To guide users through complex data breach notification procedures under GDPR, ensuring legal compliance and mitigating risks with expert-level analysis and documentation.
Features
- ENISA severity assessment with borderline score analysis
- EDPB case matching and strategic advisory
- Dynamic web research for regulatory intelligence
- Audit-ready .docx document generation (SA notifications, subject communications)
- Post-notification tracking and mitigation playbook creation
Use Cases
- When a data breach is reported and GDPR notification obligations need assessment.
- When needing to generate formal Art. 33 SA notifications or Art. 34 subject communications.
- When requiring expert guidance on risk assessment methodologies like ENISA and EDPB.
- When needing to understand cross-border notification requirements and SA contact details.
Non-Goals
- Providing legal advice (disclaimer included)
- Performing technical incident remediation
- Replacing consultation with qualified legal counsel or DPO
Workflow
- Display disclaimer and wait for acknowledgment.
- Check emergency status and offer mode selection (Guided, Fast Path, Emergency).
- Collect breach details via questions or user input.
- Perform ENISA risk assessment and EDPB case matching.
- Conduct dynamic web research for regulatory intelligence.
- Provide Strategic Case Advisory and SA contact details.
- Generate audit-ready documents (.docx or .md).
- Offer post-notification tracking.
Practices
- Legal Compliance
- Incident Response
- Documentation Generation
- Regulatory Analysis
Prerequisites
- Access to Claude AI environment
- User-provided details about the data breach incident
Installation
First, add the marketplace
/plugin marketplace add lawvable/awesome-legal-skills/plugin install gdpr-breach-sentinel-oliver-schmidt-prietz@lawvableQuality Score
VerifiedTrust Signals
Similar Extensions
Master Claude for Legal
100Master skill for legal teams using Claude. Loads the right reference for the user's question (privilege configuration, MCP hardening, verification, long documents, practice-area patterns, skill authoring) and routes to specialized starter skills (NDA triage, version diff, meeting brief, citation verification, status synthesis). Auto-invokes when the user mentions legal work, contracts, redlines, NDAs, privilege, attorney-client, court filings, depositions, regulatory compliance, or asks how to set up Claude for a law firm or in-house legal team.
Gdpr Dsgvo Expert
100GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, and data subject rights management.
Compliance Anthropic
99Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding to data subject access or deletion requests, assessing cross-border data transfer requirements, or evaluating privacy compliance.
GDPR Compliance for Marketing
99Ensure GDPR compliance for marketing activities including consent management, data processing, privacy notices, and data subject rights
Dpia Sentinel Oliver Schmidt Prietz
98GDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklists/whitelists. Triggers: "DPIA", "DSFA", "Datenschutz-Folgenabschätzung", "impact assessment", "Art. 35", "do I need a DPIA", descriptions of new high-risk processing (profiling, AI, biometrics, large-scale monitoring, special category data), Art. 36 prior consultation questions, national blacklist/whitelist queries.
Prepare Inspection Readiness
100Prepare an organisation for regulatory inspection by assessing readiness against agency-specific focus areas (FDA, EMA, MHRA). Covers warning letter and 483 theme analysis, mock inspection protocols, document bundle preparation, inspection logistics, and response template creation. Use when a regulatory inspection has been announced or is anticipated, when a periodic self-assessment is due, when new systems have been implemented since the last inspection, or after a significant audit finding that may attract regulatory attention.