Agent skill · Security

gdpr-breach-sentinel-oliver-schmidt-prietz

Elite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a data breach or security incident — including "is this even a personal data breach?" triage, (2) User asks about breach notification obligations or deadlines, (3) User mentions "72 hours", Art. 33, Art. 34, or notification requirements, (4) Discussion involves security incidents affecting personal data, (5) User needs breach risk assessment using ENISA methodology, (6) User mentions "Data Breach" or "Incident" or "Data Leakage" or "Ransomware" or "Exfiltration", (7)

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill gdpr-breach-sentinel-oliver-schmidt-prietz --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 14
SKILL.md size: 39 KB
Bundled scripts: none
Version: 2026.06.11
Declared author: Oliver Schmidt-Prietz
Path: skills/gdpr-breach-sentinel-oliver-schmidt-prietz/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

Guides users through post-breach compliance with GDPR Articles 33 & 34, EDPB Guidelines, and ENISA methodology. Builds an EDPB-template-aligned breach evidence file, generates audit-ready documentation, and provides actionable mitigation guidance.

How it works

  • Session starts with a disclaimer about non-legal guidance and confidentiality reminders.
  • It prompts to check emergency status and offers STANDARD MODE or FAST PATH.
  • It performs a Breach Qualification Gate to classify the incident as SECURITY INCIDENT ONLY, BREACH CONFIRMED, BREACH LIKELY — UNDER INVESTIGATION, or INSUFFICIENT FACTS, before intake.
  • Intake mode is selectable: Guided Mode (one-question-at-a-time) or Fast Path (extracts 11 data points: Role, Timeline/T0, Breach Type, Data Categories, Subject Count, Identifiers, Encryption, Malicious Intent, Cross-Border, DPA Deadlines, AI System).
  • In Guided Mode, it uses a defined question sequence to determine role determination (Controller, Processor, Hybrid) and proceeds with appropriate risk assessment tracks. It includes detailed guidance for Breach Type: 'Still Under Investigation' with instructions on preserving evidence, phased notification, and documenting investigation.
  • It emphasizes ENISA methodology for risk scoring (DPC, EI, CB) and provides a legal bridge aligning ENISA outcomes with Art. 33/34 obligations.

When to use it

Use when a user reports a data breach or security incident, asks about breach notification obligations or deadlines, mentions 72 hours or Article numbers, discusses security incidents affecting personal data, requires ENISA-based risk assessment, or needs breach documentation and AI Act screening.

What it can touch

The skill uses the CLAUDE-CODE tool for analysis and generation. It constructs an EDPB-template-aligned breach evidence file and audit-ready documents; it may guide output formatting for documentation files (.docx) as part of its recommendations.

Caveats

  • Not legal advice; final notification decisions should involve the organisation's DPO and qualified legal counsel.
  • Data should be anonymised where possible; do not upload raw forensic artefacts or personal data to public tools unless cleared.
  • The tool requires careful handling of live incident data and legal privilege separation in outputs.
From the SKILL.md

# GDPR Breach Response Sentinel Guide users through post-breach compliance with **GDPR Articles 33 & 34**, **EDPB Guidelines 9/2022 & 01/2021**, and **ENISA Severity Methodology**. Build an EDPB-template-aligned breach evidence file, generate audit-ready documentation, and provide actionable mitigation guidance. --- ## Session Initialization ### 1. Display Disclaimer (show at session start, do not block) > **Important:** This skill provides structured GDPR breach-notification guidance based on Art. 33–34 GDPR, EDPB Guidelines, and ENISA methodology. It is not legal advice. Final notification decisions should involve your organisation's DPO and qualified legal counsel. ### 2. Confidentiality & Input Hygiene (show with disclaimer, do not block) > **Handle with care:** This may be a live incident. > - Do not paste real personal data unless necessary — anonymised or pseudonymised samples ("Employee A", "Patient 1") are sufficient for the assessment. > - Do not upload forensic artefacts, logs, or personal data to public tools unless cleared by your security and legal teams; for an actual breach, work in an environment your organisation has approved for confidential incident data. > - Pr

What's inside
Steps it walks through
  1. Session Initialization
  2. 1. Display Disclaimer (show at session start, do not block)
  3. 2. Confidentiality & Input Hygiene (show with disclaimer, do not block)
  4. 3. Check Emergency Status
  5. 4. Breach Qualification Gate (run BEFORE intake)
  6. 5. Intake Mode Selection
  7. Quick Decision Trees
  8. Standard Mode: Question Sequence (Guided Mode)
  9. Role Determination (Track Selection)
  10. Breach Type: "Still Under Investigation"
  11. T0 Validation Rules
  12. Processor Deadlines (Track B)
  13. Supply Chain / Sub-Processor Chain Breaches
  14. Risk Assessment (ENISA Methodology)
Ships with 13 files
  • LICENSE.txt
  • README.md
  • evals.json
  • references/art34-communication.md
  • references/edpb-cases.md
  • references/edpb-template-evidence-file.md
  • references/enisa-methodology.md
  • references/mitigation-playbook.md
  • references/parallel-regimes.md
  • references/post-notification-tracking.md
  • references/strategic-advisory.md
  • references/templates.md
  • references/web-research.md
More from awesome-legal-skills
All skills →
About this skill
What does the gdpr-breach-sentinel-oliver-schmidt-prietz skill do?

Elite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a data breach or security incident — including "is this even a personal data breach?" triage, (2) User asks about breach notification obligations or deadlines, (3) User mentions "72 hours", Art. 33, Art. 34, or notification requirements, (4) Discussion involves security incidents affecting personal data, (5) User needs breach risk assessment using ENISA methodology, (6) User mentions "Data Breach" or "Incident" or "Data Leakage" or "Ransomware" or "Exfiltration", (7)

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill gdpr-breach-sentinel-oliver-schmidt-prietz --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going