| name | data-breach-consumer-notice |
| title | Consumer Data Breach Notification Letter |
| description | Drafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produces compliance scoping tables, data-element disclosures, remediation summaries, and consumer protection guidance tailored to incident facts and recipient cohorts. Use for multi-state breach letters, consumer breach notification, security incident notice, PII exposure notice, or sector-specific breach compliance. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/data-breach-consumer-notice |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | data-protection |
| language | en |
| tags | ["drafting","letter","regulatory"] |
Consumer Data Breach Notification Letter
Produces a legally compliant consumer breach notice letter tailored to incident facts, affected data types, and multi-state statutory requirements.
Prerequisites
- Incident summary — what happened, discovery date, current status, affected timeframe
- Affected population — states of residence, cohort segmentation if data elements differ
- Data elements exposed — specific categories per individual or cohort
- Legal regimes — applicable state breach statutes plus sector overlays (HIPAA, GLBA, PCI, FERPA)
- Remediation actions — containment, forensic investigation, security enhancements (completed or underway)
- Consumer protection services — vendor, duration, enrollment steps, cost allocation
- Contact channels — toll-free number, hours, email, FAQ URL, language support
- Delivery method — mail, email, or substitute notice; regulator notice obligations per state
Quick Start
- Build the compliance scoping table (jurisdictions, deadlines, delivery methods)
- Complete the data elements disclosure and remediation tables
- Draft the letter using the required section order below
- Verify against the compliance checklist
- Flag for counsel review before issuance
Workflow
Step 1 — Compliance Scoping
Map each affected jurisdiction to its requirements:
| State | Statute/Regime | Notice Deadline | Required Content Add-ons | Delivery Method | Regulator Notice |
|---|
| {State} | {Cite} | {Days} | {State-specific items} | {Mail/Email/Substitute} | {AG/Agency, date} |
Draft to the most stringent standard across all jurisdictions. Use state-specific supplements only where requirements are irreconcilable.
Step 2 — Data Elements Disclosure
| Data Category | Affected? | Scope |
|---|
| Name and contact info | Yes/No | {Detail} |
| SSN or government ID | Yes/No | {Detail} |
| Financial account or card data |