| name | breach-multi-jurisdiction |
| title | Managing Multi-Jurisdiction Breach Notification |
| description | Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-multi-jurisdiction |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | cross-jurisdiction |
| practice | data-protection |
| language | en |
Managing Multi-Jurisdiction Breach Notification
Overview
When a data breach affects individuals across multiple legal jurisdictions, the controller must navigate overlapping and sometimes conflicting notification requirements. The EU GDPR imposes a 72-hour supervisory authority notification deadline; US state laws impose varying timelines and content requirements; and other jurisdictions (Canada, Australia, Brazil, Japan, South Korea) have their own regimes. This skill provides the framework for coordinated notification across jurisdictions.
Jurisdiction Mapping — Notification Requirements
European Union — GDPR (All Member States)
| Element | Requirement |
|---|
| SA notification timeline | 72 hours from awareness (Art. 33(1)) |
| SA notification threshold | Unless breach is "unlikely to result in a risk" |
| DS notification timeline | Without undue delay when "high risk" (Art. 34(1)) |
| Lead SA determination | One-stop-shop: Art. 56 lead SA based on main establishment |
| Cross-border mechanism | Lead SA notified; other concerned SAs informed via Art. 60 |
| Content requirements | Art. 33(3)(a)-(d) for SA; Art. 34(2) for data subjects |
United States — State Breach Notification Laws
| State | Timeline | AG Notification | Threshold | Key Differences |
|---|
| California | Most expedient time possible, no unreasonable delay | Yes, if 500+ CA residents | Name + specified data element | Substitute notice for 500,000+ affected; specific template for health data |
| New York | Most expedient time possible, no unreasonable delay | AG, DFS, DOCS simultaneously | Private information (name + data element) | SHIELD Act: 30-day AG notification for NY residents |
| Texas | 60 days from determination | AG if 250+ TX residents | Name + sensitive personal information | Expanded definition of sensitive data includes biometric identifiers |
| Florida | 30 days from determination | FDLE within 30 days if 500+ | Name + specified data element | One of the shortest statutory deadlines |