LIVE · v3.3 STABLE
BUILD 2026.07.25
ART. 33 · 34
AGPL-3.0 · 13 EVAL CASES · 132 ASSERTIONS

INCIDENT
RESPONSE
with LEGAL
JUDGEMENT.

Structures the first hours after a security incident. breach qualification triage, ENISA severity scoring, Art. 33/34 legal bridge, 72-hour notification clock, lead SA determination, EDPB-template evidence file, AI Act Art. 73 intersection, and audit-ready document generation — in a single guided workflow.

GDPR ART. 33   ·   GDPR ART. 34   ·   EDPB GUIDELINES 9/2022   ·   EDPB GUIDELINES 01/2021   ·   EDPB TEMPLATE 2026   ·   ENISA SEVERITY METHODOLOGY   ·   EU AI ACT ART. 73   ·   DPA CONTRACTUAL DEADLINES   ·   ONE-STOP-SHOP   ·   BFDI   ·   LFDI   ·   CNIL   ·   GARANTE   ·   GDPR ART. 33   ·   GDPR ART. 34   ·   EDPB GUIDELINES 9/2022   ·   EDPB GUIDELINES 01/2021   ·   EDPB TEMPLATE 2026   ·   ENISA SEVERITY METHODOLOGY   ·   EU AI ACT ART. 73   ·   DPA CONTRACTUAL DEADLINES   ·   ONE-STOP-SHOP   ·   BFDI   ·   LFDI   ·   CNIL   ·   GARANTE
§ 01 · CAPABILITIES

SIX PRIMITIVES.
One SKILL.

Each capability is documented separately, tested separately, and called by the workflow at the right moment. Compose them or invoke individually.

01
ENISA + LEGAL BRIDGE
Full SE = (DPC × EI) + CB formula as decision support, bridged in writing to the Art. 33(1) risk and Art. 34(1) high-risk legal tests.
02
EDPB EVIDENCE FILE
Filled breach dossier mirroring the EDPB Template [2026] — all 7 sections, incident taxonomy, attachments inventory. Draft-status flagged.
03
EDPB CASE MATCHING
18 documented breach scenarios from EDPB Guidelines 01/2021, applied as analogies with their limits stated.
04
STRATEGIC ADVISORY
Senior counsel-level analysis: hidden risks, SA strategy, leverage points, and unencrypted Art. 9 data flags.
05
AI ACT ART. 73
Serious incident screening for high-risk AI systems: Art. 3(49) definition, 15/10/2-day deadlines, market surveillance authority routing.
06
DOCUMENT GENERATION
Audit-ready .docx output: evidence file, Art. 33 notification, Art. 34 communication + decision memo, handoff package, follow-up & withdrawal.
§ 02 · WORKFLOW

FROM INPUT
to ARTEFACT.

Fifteen structured steps. The human stays accountable; the skill carries the structure, the citations, and the document trail.

01
Disclaimer & input hygiene
Non-blocking disclaimer plus confidentiality guardrails: anonymised samples, privilege preservation, facts vs. assumptions.
02
Breach qualification triage
Is this even a personal data breach (Art. 4(12))? Security-incident-only cases exit the GDPR workflow with documentation.
03
Intake mode selection
Guided (questions one by one), Fast Path (11 data points at once), or Emergency (<12h on the clock).
04
Role determination
Track A (controller) or Track B (processor: notify controller without undue delay, handoff package — no phantom 72h).
05
T0 validation
Anchor the 72-hour clock. Resolve ambiguity between detection, confirmation, and discovery.
06
ENISA risk assessment
DPC × EI + CB with labeled flags: SCALE, VULNERABLE, CROSS-BORDER, ENCRYPTED, MALICIOUS.
07
Art. 33/34 legal bridge
Score → facts → safeguards → statutory conclusions, in writing. The score presumes; the bridge decides.
08
EDPB case matching
Map the facts to one of 18 documented EDPB scenarios — as analogies, limits stated.
09
AI Act intersection
Is a high-risk AI system in the chain? If yes, screen Art. 73 serious incident reporting obligations.
10
Parallel-regime screen
NIS2, DORA, eIDAS, ePrivacy, criminal, insurance, works council — identified, not over-analysed.
11
Cross-border determination
Genuine cross-border processing test, lead SA via one-stop-shop, or every SA for non-EU controllers.
12
Art. 34 decision module
High-risk test, exceptions 34(3)(a)/(b)/(c), communication strategy, decision memo.
13
Mitigation playbook & advisory
Case-specific actions with owners and deadlines, plus senior-counsel strategic advisory.
14
Evidence file & documents
EDPB-template-aligned evidence file plus .docx outputs: notifications, logs, handoff, follow-up, withdrawal.
15
Post-notification tracking
Ongoing case management — follow-ups, withdrawal, closure — until the SA closes the file.
§ 03 · MODES

THREE PATHS.
One OUTCOME.

Match the workflow to the situation. The skill router picks automatically; you can override.

GUIDED
Walkthrough mode. Questions one at a time. Recommended when you are uncertain or this is the first time.
FAST PATH
Dump 11 data points in one go. Skill returns a full assessment without further questions.
EMERGENCY
Less than 12 hours on the clock. Skill compresses the workflow to the must-do steps.
§ 04 · ANATOMY

WHAT'S
IN the SKILL.

Single-folder skill. SKILL.md is the runtime spec; references hold the knowledge corpus; evals hold the proof.

breach-sentinel/
├── evals  # Test cases + assertions
│   └── evals.json  # 13 cases, 132 assertions
├── references  # Reference corpus
│   ├── art34-communication.md
│   ├── edpb-cases.md
│   ├── edpb-template-evidence-file.md
│   ├── enisa-methodology.md
│   ├── mitigation-playbook.md
│   ├── parallel-regimes.md
│   ├── post-notification-tracking.md
│   ├── strategic-advisory.md
│   ├── templates.md
│   └── web-research.md
├── CHANGELOG.md  # Version history
├── README.md  # Deployment guide
└── SKILL.md  # Main skill instructions
§ 05 · DEPLOYMENT

INSTALL
and INVOKE.

Two deployment surfaces. The skill auto-triggers on relevant keywords once installed.

CLAUDE.AI USER SKILLS

  1. Settings → Profile → Custom Skills
  2. Upload the entire breach-sentinel/ folder
  3. Skill auto-triggers on relevant keywords

CLAUDE CODE / MCP

  1. Copy folder to your skills directory:
cp -r breach-sentinel/ \
   ~/.claude/skills/user/
§ 06 · OUTPUTS

WHAT YOU
get BACK.

Every output is documented, version-pinned, and traceable to its source citation.

EDPB evidence file (.docx)
Filled breach dossier mirroring the EDPB Template [2026] — every field answered, open, or N/A. Portal-transcription ready.
Assessment dashboard
Structured view: triage verdict, role, T0, clock status, ENISA calculation, legal bridge, evidence posture, SA identified.
Art. 33 notification (.docx)
Regulator-ready document with facts, categories, consequences, mitigation measures — formatted for direct submission.
Art. 34 communication + decision memo (.docx)
Plain-language data subject notification plus the documented high-risk and exception analysis behind it.
Processor handoff package
Track B: incident facts, data scope, evidence inventory, non-binding risk view — everything the controller needs.
Internal compliance log
Always produced. Required under Art. 33(5) even when SA notification is not.
§ 07 · EVALS

TESTED
before SHIPPED.

Every release runs against a fixed test suite. Assertions check numeric consistency, citation accuracy, and decision-tree branches.

13
Test Cases
132
Assertions
100%
Coverage Required
01
We had a misdirected email incident yesterday
10 ASSERTS
02
URGENT: We've been hit by ransomware
11 ASSERTS
03
I'm the DPO at a cloud hosting provider (we're a processor)
10 ASSERTS
04
One of our employees lost their company laptop on public transport in Berlin yes...
10 ASSERTS
05
We had a data breach at our SaaS platform that serves customers across the EU
10 ASSERTS
06
EMERGENCY! We discovered a breach 64 hours ago and we've been investigating but
10 ASSERTS
07
We operate an AI-powered medical diagnosis assistant (classified as high-risk un...
11 ASSERTS
08
I'm the DPO at a large Austrian insurance company headquartered in Vienna
10 ASSERTS
§ 08 · REGULATORY BASIS

WHAT IT
cites.

Every legal verdict resolves to one of these instruments. No invented articles, no synthetic recitals.

GDPR Articles 33 & 34
Personal data breach notification obligations.
EDPB Guidelines 9/2022 v2.0
Personal data breach notification under Regulation 2016/679.
EDPB Guidelines 01/2021 v2.0
Examples regarding personal data breach notification.
EDPB Template [2026] v1.0
Breach notification template — draft, public consultation until 5 Aug 2026.
ENISA Severity Methodology
Risk assessment formula and scoring framework.
EU AI Act (Reg. 2024/1689)
Art. 73 serious incident reporting for high-risk AI systems.
§ 09 · TRUST

EVERY STEP,
auditable.

The trace is the product. Nothing happens off the record — no hidden tool calls, no silent retrieval, no opaque chain-of-thought.

§
Source-anchored output.
Every ENISA score, every SA determination, every legal verdict traces back to a cited authority.
VERIFIED
Reproducible decisions.
Pin a build; recreate the assessment years later for litigation or audit defence.
IMMUTABLE
Validation before generation.
Numeric consistency, T0 logic, and arithmetic checks run before any document ships.
ENFORCED
**
EU-native.
Built around BfDI/LfDI routing, EDPB cases, and Member State enforcement patterns. Not retrofitted.
NATIVE

Breach Sentinel — Deployment Guide

📄 View the interactive skill page →

See CHANGELOG.md for version history.

Overview

GDPR Breach Response Sentinel — an advanced incident response skill for Claude that provides:

  • Breach qualification triage — "is this even a personal data breach?" gate before the workflow
  • ENISA severity assessment with borderline score analysis, bridged to the Art. 33/34 statutory legal tests
  • EDPB-template-aligned breach evidence file mirroring the EDPB Template [2026] for breach notification (draft, public consultation)
  • EDPB case matching against 18 documented breach scenarios (as analogies, with limits stated)
  • Dedicated Art. 34 decision module — high-risk test, all three Art. 34(3) exceptions, communication strategy
  • Strategic case advisory — senior counsel-level analysis and recommendations
  • Dynamic web research for enforcement precedents and SA-specific guidance, with source discipline
  • Flexible mitigation playbooks tailored to the specific incident
  • SA contact directory with jurisdiction-specific portal lookup
  • AI Act Art. 73 intersection for breaches involving high-risk AI systems
  • Sectoral parallel-regime screen (NIS2, DORA, eIDAS, ePrivacy, insurance, works council)
  • Audit-ready .docx document generation (evidence file, Art. 33, Art. 34, compliance logs, follow-up/withdrawal, etc.)
  • Post-notification case tracking
  • Processor track done right — notify controller without undue delay (Art. 33(2)), contractual DPA windows, handoff package; no phantom 72h processor deadline

File Structure

breach-sentinel/
├── SKILL.md                              # Main skill instructions (deploy this)
├── evals/
│   └── evals.json                        # 13 test cases, 132 assertions
└── references/
    ├── enisa-methodology.md              # ENISA scoring tables, legal bridge, worked examples
    ├── edpb-template-evidence-file.md    # EDPB Template [2026] field map + evidence file builder
    ├── art34-communication.md            # Art. 34 decision framework incl. all 34(3) exceptions
    ├── parallel-regimes.md               # AI Act Art. 73 depth + NIS2/DORA/eIDAS/etc. screen
    ├── edpb-cases.md                     # 18 EDPB breach case scenarios + analogy rules
    ├── templates.md                      # 17 document templates (Art. 33/34, handoff, follow-up …)
    ├── strategic-advisory.md             # Advisory framework, principles, tone examples
    ├── mitigation-playbook.md            # Design principles, output format, action categories
    ├── post-notification-tracking.md     # Tracking dashboard template
    └── web-research.md                   # Search query templates, source discipline, DE routing

Deployment

Claude.ai (User Skills)

  1. Go to Settings → Profile → Custom Skills (or equivalent)
  2. Upload the entire breach-sentinel/ folder structure
  3. The skill will auto-trigger when you mention data breaches, Art. 33/34, "Datenpanne", or related topics

Claude Code / Custom MCP Setup

  1. Copy the breach-sentinel/ folder to your skills directory: bash cp -r breach-sentinel/ /path/to/your/skills/user/breach-sentinel/
  2. Ensure the skill is registered in your configuration

Usage

Quick Start

Just tell Claude about a breach:

"We just discovered that an external attacker exfiltrated our customer database. About 2,000 records with names, emails, and payment data. We're based in Munich. This happened yesterday at 3pm."

The skill will activate and walk you through the assessment.

Trigger Phrases

  • "We had a data breach" / "Datenpanne" / "Datenschutzverletzung"
  • "Do we need to notify the SA?" / "72 hours" / "Art. 33"
  • "Help me assess this breach" / "ENISA assessment"
  • "Generate breach notification documents"

Modes

Mode When to Use
Guided You're unsure about details; skill asks questions one by one
Fast Path You have all the facts; dump them and get an instant assessment
Emergency <12 hours remaining on notification clock

Capabilities Summary

Feature Description
Breach Qualification Triage Gate before the workflow: security incident vs. personal data breach (Art. 4(12))
ENISA Severity Calculation Full SE = (DPC × EI) + CB with contextual adjustments — as decision support
Art. 33/34 Legal Bridge Written bridge from score → facts → safeguards → statutory conclusions in every assessment
EDPB Evidence File Filled dossier mirroring the EDPB Template [2026] (draft) — all 7 sections, portal-ready
Art. 34 Decision Module High-risk test, exceptions 34(3)(a)/(b)/(c), communication strategy, decision memo
Evidence Posture Facts / assumptions / unknowns discipline with confidence level in every assessment
Borderline Score Analysis Extra scrutiny for scores near 2.0/3.0/4.0 thresholds
EDPB Case Matching Maps to 18 documented scenarios from Guidelines 01/2021 — as analogies with stated limits
Strategic Advisory Senior counsel-level analysis: hidden risks, SA strategy, leverage points
Dynamic Web Research Current enforcement precedents and SA guidance, with source discipline rules
SA Contact Lookup Finds notification portal URLs and jurisdiction-specific requirements
Germany SA Routing Correctly routes to BfDI vs. LfDI/LDA based on entity type
Mitigation Playbook Case-specific, flexibly structured action plan with owners and deadlines
AI Act Integration Art. 73 serious incident screening (definition, deadlines, applicability) for AI breaches
Parallel-Regime Screen NIS2, DORA, eIDAS, ePrivacy, criminal, insurance, contractual, works council
Processor Track Art. 33(2) without-undue-delay duty, contractual DPA windows, handoff package
Document Generation Audit-ready .docx files — 17 templates incl. follow-up, withdrawal, late-notification
Post-Notification Tracking Ongoing case management dashboard incl. follow-up and withdrawal milestones

Regulatory Basis

Document Reference
GDPR Articles 33 & 34 Breach notification obligations
EDPB Guidelines 9/2022 v2.0 Personal data breach notification
EDPB Guidelines 01/2021 v2.0 Examples regarding breach notification
EDPB Template [2026] v1.0 Personal data breach notification template — DRAFT, public consultation until 5 Aug 2026
ENISA Severity Methodology Risk assessment formula and scoring
EU AI Act (Reg. 2024/1689) Art. 73 serious incident reporting (applies from 2 Aug 2026)

License & Disclaimer

This skill provides guidance based on publicly available GDPR regulatory materials. It does not constitute legal advice. All notification decisions should involve qualified legal counsel and your organization's DPO.


*Created by Oliver Schmidt-Prietz — OneZero Legal