brecha

Guide personal data breach response with RGPD notification checklists and templates.

35|19|Updated May 15, 2026
One-click install
npx skills add https://github.com/betobetico/claude-para-abogados --skill brecha
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: brecha
Source: https://github.com/betobetico/claude-para-abogados/tree/main/proteccion-datos/skills/brecha
Command: npx skills add https://github.com/betobetico/claude-para-abogados --skill brecha

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you act fast and handle legal compliance when a personal data security breach occurs, ensuring timely notification to the AEPD within 72 hours and appropriate communication to affected people when the risk is high.

Core Features & Use Cases

  • Incident response workflow: Guides immediate actions from detection and containment to evidence preservation and internal documentation.
  • Risk assessment framework: Evaluates severity by data type, affected volume, and breach nature (confidentiality, integrity, availability).
  • AEPD and data-subject obligations: Produces the checklist and templates for AEPD notification (art. 33 RGPD) and for notifying data subjects when required (art. 34 RGPD).
  • Practical deliverables: Generates a structured action checklist and notification templates using the required RGPD fields.

Quick Start

Use the brecha skill for a data incident by describing what happened and the affected data and systems, so it can produce the incident checklist and AEPD/affected-person notification drafts.

Frequently Asked Questions about brecha

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I notify the AEPD of a data breach within 72 hours under RGPD?

You must notify the AEPD of a data breach within 72 hours of becoming aware of it by providing incident details, risk assessment, and required legal fields per RGPD article 33. This includes documenting the nature of the breach and the approximate number of affected data subjects.

When do I need to communicate a personal data breach to affected data subjects?

You need to communicate a personal data breach to affected individuals when the risk to their rights and freedoms is high, as mandated by RGPD article 34. The notification must describe the breach's nature and advise on protective measures they can take.

How do I assess the risk level of a data security incident?

You assess the risk level of a data security incident by evaluating the data type, the volume of affected records, and the impact on confidentiality, integrity, and availability. This framework determines whether AEPD notification and data subject communication are legally required.

What steps should I take immediately after detecting a data leak?

Immediately after detecting a data leak, you should follow an incident response workflow that includes containment, evidence preservation, and internal documentation. These initial steps secure the affected systems and establish the baseline facts needed for RGPD risk assessment.

What information is required in an RGPD breach notification to the AEPD?

An RGPD breach notification to the AEPD must include the nature of the personal data breach, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed to address it. These fields fulfill article 33 requirements.

Can I use legal templates for both AEPD notification and data subject communication?

Yes, you can generate legal templates for both AEPD notification and data subject communication from a single incident description. By inputting the breach facts and risk evaluation, the system produces structured drafts containing the exact fields required by RGPD articles 33 and 34.