Help us improve
Share bugs, ideas, or general feedback.
From data-breach-response-skills
Guides GDPR Article 34 notifications to data subjects for high-risk personal data breaches, covering risk thresholds, required content, exemptions, and letter templates.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin data-breach-response-skillsHow this skill is triggered — by the user, by Claude, or both
Slash command
/data-breach-response-skills:breach-subject-commsThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Article 34 of the GDPR requires controllers to communicate a personal data breach to affected data subjects "without undue delay" when the breach is "likely to result in a high risk to the rights and freedoms of natural persons." This obligation is separate from and additional to the Art. 33 supervisory authority notification. The communication must be in clear and plain language, directly acce...
Guides GDPR Article 34 notifications to data subjects for high-risk personal data breaches, covering risk thresholds, required content, exemptions, and letter templates.
Executes GDPR Article 33 personal data breach notifications to supervisory authorities within 72 hours, covering risk assessment, deadline calculation with holidays/weekends, required content, and DPO involvement.
Executes LGPD security incident response runbook (Art. 48 LGPD + Resolução CD/ANPD nº 15/2024): guides 3-day notification deadlines, ANPD/subject notification items, and 5-year record retention.
Share bugs, ideas, or general feedback.
Article 34 of the GDPR requires controllers to communicate a personal data breach to affected data subjects "without undue delay" when the breach is "likely to result in a high risk to the rights and freedoms of natural persons." This obligation is separate from and additional to the Art. 33 supervisory authority notification. The communication must be in clear and plain language, directly accessible to the affected individuals, and must contain specific information prescribed by Art. 34(2).
Art. 34 notification is triggered when the breach risk assessment yields a "high risk" determination. Per EDPB Guidelines 9/2022, Section 3.2, high risk is present when:
The data subject communication must contain, at minimum, the information specified in Art. 33(3)(b), (c), and (d):
A controller may be exempt from direct data subject notification in three circumstances:
The controller has applied appropriate technical and organisational protection measures that render the personal data unintelligible to any person who is not authorized to access it, such as encryption.
Requirements for this exemption:
The controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise.
Requirements for this exemption:
Individual notification would involve disproportionate effort, in which case a public communication or similar measure shall be made instead.
Requirements for this exemption:
Subject: Important Security Notice — Your Payment Information May Have Been Affected
Dear [Data Subject Name],
We are writing to inform you of a security incident that may have affected your personal and payment information held by Stellar Payments Group.
What happened: On 13 March 2026, we detected unauthorized access to our payment processing database. Our investigation determined that an external attacker gained access to a subset of customer payment records between 10 March and 13 March 2026.
What information was involved: Your name, email address, billing address, and payment card details (card number, expiry date, and CVV) associated with your Stellar Payments account were among the records accessed.
What we are doing:
What you can do:
Free credit monitoring: We are offering all affected customers 12 months of complimentary credit monitoring through Experian IdentityWorks. To enroll, visit stellarpayments.eu/breach-support and use activation code SPG-2026-PROTECT. Enrollment is available until 30 June 2026.
Contact us: If you have questions, our dedicated breach response team is available at:
Our Data Protection Officer, Dr. Elena Vasquez, can be reached at dpo@stellarpayments.eu or +49 30 7742 8001.
We sincerely regret this incident and are committed to preventing any recurrence.
Regards, Marcus Lindqvist Chief Executive Officer Stellar Payments Group
Subject: Important Notice Regarding Your Health Information
Dear [Data Subject Name],
We are contacting you to inform you of a security incident involving your health information held by Stellar Payments Group's employee wellness programme.
What happened: On 5 March 2026, we discovered that an employee in our IT department accessed the occupational health database without authorization between 1 February and 4 March 2026. This database contains health screening results and sick leave records for employees enrolled in our wellness programme.
What information was involved: Your name, employee number, date of birth, health screening results (including blood pressure, cholesterol, and BMI readings), and sick leave history for 2025-2026.
What we are doing:
What you can do:
Counselling support: We have arranged confidential counselling support through our Employee Assistance Programme (EAP) provider, Workplace Options, available 24/7 at +49 800 100 0287 (reference: SPG-Health-2026).
Contact us:
Regards, Dr. Elena Vasquez Data Protection Officer Stellar Payments Group
Subject: Action Required — Your Stellar Payments Account Credentials May Be Compromised
Dear [Data Subject Name],
We are writing to inform you that your Stellar Payments account login credentials may have been exposed in a security incident.
What happened: On 20 March 2026, our security monitoring systems detected that a database backup file containing customer account credentials was inadvertently stored on an unsecured cloud storage instance between 15 March and 20 March 2026.
What information was involved: Your email address, username, and hashed password for your Stellar Payments account. While passwords were stored in a hashed format (bcrypt with a cost factor of 12), we are treating this as a high-risk breach because sophisticated attackers may attempt to reverse the hashes.
What we are doing:
What you must do immediately:
Contact us:
Regards, Thomas Brenner Chief Information Security Officer Stellar Payments Group
Subject: Service Disruption Notice — Your Data Was Temporarily Unavailable
Dear [Data Subject Name],
We are writing to inform you of a security incident that temporarily affected access to your account data.
What happened: On 13 March 2026, Stellar Payments Group experienced a ransomware attack that encrypted portions of our customer database. This made your account data temporarily unavailable for approximately 36 hours while we restored systems from secure backups.
What information was affected: Your account data (name, contact details, transaction history, and account balance) was rendered inaccessible during the incident. Our forensic investigation has confirmed that no data was exfiltrated (copied or stolen) during the attack. The data was encrypted in place and has been fully restored.
What we are doing:
What you should do:
Contact us:
Regards, Marcus Lindqvist Chief Executive Officer Stellar Payments Group
Subject: Important Notice Regarding Your Employment Records
Dear [Data Subject Name],
We are writing to inform you of a security incident involving your employment records held by Stellar Payments Group.
What happened: On 1 March 2026, our data loss prevention system detected that a departing employee in the People Operations department transferred a file containing employee records to a personal cloud storage account on 27 February 2026. We immediately launched an investigation and recovered the data.
What information was involved: Your name, employee number, home address, personal email address, date of birth, salary information, bank account details for payroll, and national insurance/social security number.
What we are doing:
What you can do:
Free identity protection: We are providing all affected employees with 24 months of complimentary identity theft protection through Experian IdentityWorks, including dark web monitoring, credit monitoring, and EUR 25,000 identity theft insurance. Enrollment details are available on the HR portal under Benefits > Breach Support, or contact hr-confidential@stellarpayments.eu.
Contact us:
Regards, Dr. Elena Vasquez Data Protection Officer Stellar Payments Group