Organize a privacy or security incident into an attorney-ready working file. The skill records the incident facts as user-supplied facts, structures the is-this-a-reportable-breach analysis as questions for counsel (never answering them), builds a notification-obligation inventory in which every candidate obligation is flagged [ATTORNEY TO CONFIRM], maps contractual notice obligations from provided DPAs and contracts, assembles a working chronology with a trigger-date register, and produces an evidence-preservation checklist. It produces draft legal work product for attorney review — not legal advice.
This skill never determines whether the incident "is a breach" under any law, never determines whether notification is required, and never computes or asserts any notification deadline. Notification windows are outcome-determinative and jurisdiction-specific; every clock in the output is [deadline verification required], anchored to a user-supplied trigger date recorded as a fact. Incident analysis is frequently conducted under attorney-client privilege and work-product protection: whether and how to structure the investigation under privilege is a counsel decision this skill routes to counsel and never resolves.
If the incident description or the discovery date is missing, stop and request them. A suspected incident is time-critical: state prominently that the matter should be routed for immediate attorney attention (see core/jurisdiction-and-deadline-gates.md), and do not let intake work delay that routing.
-
Confirm inputs and post the time-sensitivity banner. Verify the incident description, discovery date, and privilege posture are provided; request anything missing. Open the working file with the banner: incident matters are time-critical, candidate notification clocks may be running, and the file requires immediate attorney attention — [CRITICAL — ATTORNEY TO VERIFY DEADLINE].
-
Record the privilege posture. Note who is directing the investigation, whether counsel has been engaged, and whether forensic or third-party investigators were retained through counsel — all as user-supplied facts. Flag every open privilege-structure question as [ATTORNEY TO CONFIRM: privilege structure]. Do not advance distribution of the file beyond the stated recipients until counsel confirms the protocol.
-
Complete the incident-facts intake. Record, each labeled by source and dated: (a) what is believed to have happened; (b) how and when the incident was discovered; (c) the suspected vector or cause; (d) containment status and remediation steps taken so far; (e) whether the threat actor is believed to retain access or data; (f) who inside and outside the organization already knows. Mark unknowns as [CONFIRM: ...] rather than leaving them blank.
-
Inventory the data elements. For each affected system, list the categories of personal data believed involved (identifiers, credentials, financial, health, biometric, children's data, other sensitive categories), each labeled confirmed, suspected, or unknown. Note that whether a category is legally "sensitive" varies by framework — [verify jurisdiction].
-
Inventory the affected populations. Record the data subject groups (customers, employees, patients, minors, end users of business customers), their geographies and residencies as stated, and headcounts labeled as estimates or confirmed figures. Geography drives which regimes counsel must assess; do not infer applicable law from it.
-
Map systems and vendor involvement. List affected systems and their owners. If the incident occurred at or through a vendor or sub-processor, record the vendor's notice (date received, channel, and what it states — quoted or faithfully summarized and attributed), and note that the organization may itself hold inbound and outbound notice obligations [ATTORNEY TO CONFIRM].
-
Build the working chronology. Assemble a dated, time-stamped chronology of user-supplied events: occurrence (if known), detection, discovery, escalations, containment steps, vendor notices, internal decisions. Every entry cites its source. Do not interpolate events or infer dates between known points. For extensive litigation-grade chronologies, note skills/litigation/litigation-chronology/SKILL.md as the follow-on.
-
Compile the trigger-date and clock register. For each candidate clock (regulator notification, data subject notification, contractual notice, insurance notice), record: the user-supplied trigger date and what the user says triggered it; the framework or contract that may impose the clock, stated generically; and the deadline field completed only as [deadline verification required]. Never compute a due date, count days, or characterize time remaining.
-
Structure the reportability analysis as questions. Draft the question set counsel must answer, without answering any of them. Cover at minimum: Which breach-notification frameworks could apply to these populations and data, and in which jurisdictions? [verify jurisdiction] Does the incident meet each framework's definition of a notifiable breach or security incident? Do risk-of-harm or likelihood thresholds change the answer? Does the organization's role (controller, processor, other) change who must notify whom? Do any exceptions (for example, encryption or good-faith-access-style exceptions, described generically) merit assessment [Verify current law]? What has the forensic investigation established, and what remains unknown?
-
Build the notification-obligation inventory. List every candidate notified party in four groups — regulators and authorities, data subjects, contractual counterparties (customers, controllers, partners), and insurers — plus any other candidate (law enforcement, credit bureaus, works councils) surfaced by the facts. For each: who they are, why they surface from the facts, the user-supplied trigger date, [deadline verification required] for the window, and [ATTORNEY TO CONFIRM: whether this notification obligation exists and applies]. The inventory is a checklist of questions, not a list of duties.
-
Map contractual notice obligations. From the provided DPAs, vendor contracts, and customer contracts only: quote or precisely cite each incident- or breach-notice clause, the counterparty, the stated trigger, the stated notice period as written (marked [deadline verification required]), and the required content and channel of notice. If contracts are referenced but not provided, list them as gaps — never reconstruct terms from memory. Route substantive review of any DPA to skills/privacy/dpa-review/SKILL.md.
-
Record insurance notice provisions. If the policy or a summary is provided, record its notice clause (who must be notified, stated trigger, stated period [deadline verification required]), any panel or consent requirements for retaining vendors, and flag engagement of the broker and coverage counsel as [ATTORNEY TO CONFIRM]. If not provided, list the policy as a gap.
-
Draft the evidence-preservation checklist. List the categories of evidence to preserve, as items for counsel to direct: system and access logs, forensic images, affected datasets, the compromised accounts' artifacts, relevant communications and tickets, vendor notices, and backup snapshots — with owners and at-risk items (for example, logs subject to short rotation windows) flagged prominently. Note that preservation duties and any litigation hold are attorney determinations; route formal hold issuance to skills/litigation/legal-hold/SKILL.md.
-
Compile escalation items and assemble the output. Flag anything needing immediate counsel attention: sensitive or children's data, regulator or media awareness, extortion demands, cross-border populations, vendor-chain complications, or any indication a clock trigger occurred materially earlier than discovery. Assemble the output in the format below, label it as privileged draft work product, and attach the unchecked Attorney Verification Checklist.
When the output will brief a non-lawyer stakeholder (an executive, board member, or incident commander), add a Business Stakeholder Summary as a clearly separated section following core/business-stakeholder-communication.md — Business Summary, Decision Needed, Recommended Ask, Fallback Position, and Escalation Needed? — produced only on request or for a plainly business audience, always in addition to the deliverable above and never a substitute for attorney review.