gdpr-breach-72h-enlisted
Install: claude install-skill matematicsolutions/awesome-matematic-skills-en
# GDPR Breach 72h EN - personal data breach response (Art. 33-34)
## Philosophy
In a breach, the clock and the documented reasoning are what matter. This skill runs a **documented**
decision tree and produces drafts; the **decision to notify and the act of sending belong to the
controller/DPO**. No guessing - missing inputs for the risk assessment are flagged as gaps, not filled.
## Step 1 - Is it a breach, and which type
A breach is a breach of security leading to accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to personal data (Art. 4(12)). Classify: **confidentiality**
(disclosure/access), **integrity** (alteration), **availability** (loss/destruction). Often combined.
## Step 2 - Risk assessment to rights and freedoms
Factors (EDPB 9/2022, formerly WP250): type of breach, nature/sensitivity/volume of data, ease of
identification, severity of consequences (identity theft, financial loss, discrimination, reputational
harm), special characteristics of individuals (children, patients), number of individuals affected.
Output: `risk: none / present / high`.
## Step 3 - Notify the SA (Art. 33) - 72h COUNTER
- **The clock starts on AWARENESS** of the breach (not the event). Deadline: **72 hours**.
- Notify **unless** the breach is **unlikely to result in a risk** to rights and freedoms (Art. 33(1)).
No notification => justify and document.
- **After the deadline** => notify with reasons for the delay (Art. 33(1) sentence 2).
-