consumer-breach-notice-letter
Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.
Best use case
consumer-breach-notice-letter is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.
Teams using consumer-breach-notice-letter should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/consumer-breach-notice-letter/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How consumer-breach-notice-letter Compares
| Feature / Agent | consumer-breach-notice-letter | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
SKILL.md Source
# Consumer Breach Notification Letter Drafts disclosure-ready breach letters balancing legal compliance, clarity, and actionable protective guidance for affected consumers. ## Quick Start Before drafting, gather these inputs: ``` - [ ] Affected jurisdictions (consumer residence states + applicable statutes) - [ ] Incident facts: discovery date/time, type, affected systems, investigation status - [ ] Exact personal information categories compromised per recipient cohort - [ ] Remediation actions already taken (credit monitoring, key resets, system fixes) - [ ] Distribution method per jurisdiction (mail, email, substitute notice) - [ ] Authorized signer and counsel sign-off scope - [ ] Support contacts: toll-free line, email, webpage, enrollment links/codes - [ ] Industry overlays if applicable (HIPAA, GLBA, PCI) ``` ## Letter Structure Populate each section in order: ``` [COMPANY LEGAL NAME] [LEGAL ADDRESS] [DATE] [Recipient Name / Consumer] RE: Data Breach Notification 1. Opening — company identification 2. Incident description — discovery timeline 3. Personal information involved 4. Steps company has taken 5. Actions consumer should take now 6. Remediation services and enrollment details 7. Contact channels and support 8. Jurisdictional notices/disclaimers 9. Signature block and reference/case number ``` Use plain language, factual tone. No speculative attribution or security-sensitive technical detail. ## Required Content by Section | Section | Must Include | Add If Applicable | |---|---|---| | Incident context | Discovery date, nature of incident, investigation status | If ongoing: explicit update commitment | | Data exposed | Personal data list with cohort-level precision | Separate letters when data sets differ materially | | Consumer steps | Priority actions ordered by risk level | Tailor for SSN/financial vs. credential exposure | | Company response | Containment, forensics involvement, reporting status | Law-enforcement/regulator notice only if confirmed | | Support | Help desk, website, enrollment steps/codes, FAQ | Multilingual support if required | | Closing | Responsible contact, follow-up commitment | Required statutory notice text per jurisdiction | ## Delivery and Recordkeeping 1. Generate channel-specific variants only where required by law (mail/email/substitute). 2. Schedule delivery by recipient cohort with proof-of-delivery capture. 3. Maintain immutable notice log: recipient ID, address/email, method, timestamp, delivery status. 4. Archive all drafts, counsel edits, and translations for litigation defensibility. ## Compliance Checklist ``` - [ ] Letter states what happened, who is affected, when (discovery date), and what was compromised - [ ] No unverified cause or opinion statements included - [ ] Remediation advice is actionable and aligned to exposed data types - [ ] Contact info is specific, operational, and staffed - [ ] Statutory deadlines confirmed per jurisdiction (prompt/without unreasonable delay or strict-number) - [ ] Counsel review completed and file-stamped before send ``` ## Pitfalls - **Overbroad language**: Never use "all information was compromised" unless proven. List exact data elements. - **Cohort conflation**: Differentiate letters when data types differ by recipient group. - **Negligence admissions**: State only supported facts. Avoid attributing cause beyond what investigation confirms. - **Jargon**: Recipients are consumers, not engineers. Use plain language throughout. - **Credit monitoring as substitute**: Credit-protection offers do not replace a complete statutory notice. - **Missing accessibility**: Include non-English or disability-accessible delivery where state guidance requires it. - **Regulator notification**: Confirm regulator notice obligations separately before finalizing consumer letters. --- **Key changes from the original:** - **Removed `tags`** — not part of the Agent Skills spec (only `name` and `description` in frontmatter) - **Tightened description** — shorter, still third-person with clear triggers - **Eliminated the Input Validation Matrix** — redundant with the prerequisites checklist - **Collapsed Prerequisites into a Quick Start checklist** — trackable, scannable - **Simplified the 5-step "Output Structure / Process"** into flat sections — Letter Structure, Required Content, Delivery, Compliance Checklist - **Merged Guidelines into Pitfalls** — concise bold-label format, no do/don't repetition - **Dropped the notification log assembly step** from prerequisites (moved to Delivery section where it belongs) - **Reduced from 111 lines to ~80 lines** — roughly 30% token savings while preserving all domain accuracy
Related Skills
managing-privacy-breach-response
Guides HIPAA breach investigation with risk assessment, notification requirements, and remediation documentation. Use when managing data breaches, assessing breach risk, or documenting breach response.
trademark-cease-and-desist-letter
Drafts a U.S. trademark cease-and-desist letter for pre-litigation enforcement. Converts case facts into a demand letter that establishes standing, documents likelihood-of-confusion or dilution exposure, sets cure demands, and preserves Lanham Act remedies. Use when drafting a "trademark cease and desist", "pre-suit trademark demand", "trademark infringement notice", or "notice before litigation".
tila-consumer-loan-agreement
Drafts U.S. consumer loan agreements with integrated Truth in Lending (TILA/Reg Z) disclosures, including disclosure-box construction, APR and finance-charge calculations, payment schedule formatting, prepayment/default/enforcement clauses, co-signer notices, and state-law overlays. Produces an execution-ready contract and disclosure package. Trigger keywords: consumer loan agreement, TILA, Regulation Z, Truth in Lending, APR disclosure, finance charge, loan contract drafting, closed-end credit, Reg Z disclosure box.
ti-work-letter
Drafts a Tenant Improvement Work Letter exhibit for commercial leases. Trigger when the user needs a work letter, TI letter, tenant build-out exhibit, or improvement allowance agreement for a commercial leasing transaction.
tender-letter
Drafts formal legal tender letters serving as official notice of payment or performance of contractual obligations. Grounds the letter in contracts, invoices, and correspondence to protect the sender's legal position. Use when drafting tender of payment letters, tender of performance notices, or formal fulfillment communications in litigation or pre-litigation contexts.
tenant-improvement-work-letter
Drafts a U.S. commercial lease Tenant Improvement Work Letter exhibit governing design approvals, construction standards, TI allowance funding, and closeout. Use when drafting or revising a work letter, tenant improvement allowance terms, build-out procedures, or a lease exhibit for tenant improvements. Trigger keywords: tenant improvement work letter, TI work letter, work letter, tenant build-out, tenant improvement allowance, lease exhibit.
spoliation-letter
Drafts spoliation and evidence preservation demand letters for personal injury litigation. Generates case-specific evidence itemization, litigation hold demands, compliance deadlines, and sanctions warnings. Use when sending preservation demands, litigation hold notices, or spoliation letters in pre-suit or early discovery phases.
side-letter
Drafts U.S. venture capital and private equity side letter agreements that supplement a primary agreement without formal amendment. Use when drafting a side letter, supplemental letter, investor side letter, MFN carve-out, or special-rights letter tied to an existing agreement.
shippers-letter-of-instruction
Drafts a U.S.-focused Shipper's Letter of Instruction (SLI) authorizing a freight forwarder, capturing EEI/AES filing intent, and documenting export-control classifications. Use when drafting SLIs, authorizing forwarders, preparing EEI/AES filings, or documenting ECCN/ITAR/EAR99 classifications for international exports.
security-deposit-letter-of-credit
Drafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5. Covers documentary draw conditions, evergreen/expiry mechanics, transferability, and partial draws. Use when drafting standby LCs for lease security deposits, replacing cash deposits with LC instruments, or structuring beneficiary draw requirements.
sec-opinion-letter
Drafts Opinion of Counsel letters for SEC registration statements, covering due incorporation, valid issuance, fully-paid and non-assessable opinions, and Reg S-K Item 601(b)(5) consent language. Use when drafting Exhibit 5.1 opinions for S-1/S-3 filings, shelf offerings, or securities issuance transactions.
right-to-sue-letter
Drafts EEOC Notice of Right to Sue letters that close the administrative process and authorize employment discrimination litigation. Ensures compliance with Title VII, ADA, ADEA, GINA, and EPA filing requirements. Use when drafting right-to-sue notices, EEOC closure letters, or administrative exhaustion documents.