Managing Multi-Jurisdiction Breach Notification

SkillCommunication

Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notification laws (varying timelines from 30 to 90 days), and other international regimes. Covers conflict resolution when notification timelines differ, lead supervisory authority determination, and parallel notification execution. Keywords: multi-jurisdiction, cross-border breach, notification coordination, GDPR, US state laws, international breach notification.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Managing Multi-Jurisdiction Breach Notification skill

What this skill tells your AI

The instructions your AI receives, as published by thomasmoreai/legal-skills-open in cross-jurisdiction/data-protection/skills/breach-multi-jurisdiction/SKILL.md and read by ahel’s review.

Overview

When a data breach affects individuals across multiple legal jurisdictions, the controller must navigate overlapping and sometimes conflicting notification requirements. The EU GDPR imposes a 72-hour supervisory authority notification deadline; US state laws impose varying timelines and content requirements; and other jurisdictions (Canada, Australia, Brazil, Japan, South Korea) have their own regimes. This skill provides the framework for coordinated notification across jurisdictions.

Jurisdiction Mapping — Notification Requirements

European Union — GDPR (All Member States)

ElementRequirement
SA notification timeline72 hours from awareness (Art. 33(1))
SA notification thresholdUnless breach is "unlikely to result in a risk"
DS notification timelineWithout undue delay when "high risk" (Art. 34(1))
Lead SA determinationOne-stop-shop: Art. 56 lead SA based on main establishment
Cross-border mechanismLead SA notified; other concerned SAs informed via Art. 60
Content requirementsArt. 33(3)(a)-(d) for SA; Art. 34(2) for data subjects

United States — State Breach Notification Laws

StateTimelineAG NotificationThresholdKey Differences
CaliforniaMost expedient time possible, no unreasonable delayYes, if 500+ CA residentsName + specified data elementSubstitute notice for 500,000+ affected; specific template for health data
New YorkMost expedient time possible, no unreasonable delayAG, DFS, DOCS simultaneouslyPrivate information (name + data element)SHIELD Act: 30-day AG notification for NY residents
Texas60 days from determinationAG if 250+ TX residentsName + sensitive personal informationExpanded definition of sensitive data includes biometric identifiers
Florida30 days from determinationFDLE within 30 days if 500+Name + specified data elementOne of the shortest statutory deadlines
MassachusettsAs soon as practicableAG + OCABR simultaneouslyName + specified data elementRequires description of remedial services offered
IllinoisMost expedient time possible, no unreasonable delayAG if 500+ IL residentsName + specified data elementBIPA adds biometric data breach notification requirements
Virginia60 days from discoveryAG + affected individualsName + specified data elementVCDPA adds consumer data rights context
Colorado30 days from determinationAG within 30 days if 500+Name + specified data elementAmong the shortest deadlines alongside Florida
PennsylvaniaWithout unreasonable delayAG if notifyingName + specified data elementBroad definition of personal information
Washington30 days from discoveryAG within 30 days if 500+Name + specified data elementBiometric and health data included

Other International Jurisdictions

JurisdictionLawSA TimelineDS TimelineNotable
United KingdomUK GDPR + DPA 201872 hours (ICO)Without undue delayMirrors EU GDPR; ICO is sole SA
CanadaPIPEDA + provincial laws"As soon as feasible" to OPC"As soon as feasible"Real risk of significant harm (RROSH) threshold
AustraliaPrivacy Act 1988 (NDB scheme)30 days to OAICAs soon as practicable"Eligible data breach" = serious harm likely
BrazilLGPD"Reasonable time" to ANPD"Reasonable time"ANPD defines timeframes by regulation
JapanAPPIPromptly to PPC (3-5 days recommended)PromptlyMandatory for 1,000+ subjects or sensitive data
South KoreaPIPAWithin 72 hours to PIPCWithout delayMirrors GDPR timeline
SingaporePDPA3 calendar days to PDPCAs soon as practicableSignificant harm or significant scale threshold

Conflict Resolution Framework

Principle 1: Meet the Shortest Deadline First

When notification timelines conflict, always prepare to meet the shortest applicable deadline. This typically means:

  • EU/UK GDPR 72-hour deadline drives the primary notification timeline.
  • US state notifications are prepared in parallel and dispatched as soon as the statutory requirement is met.
  • The 72-hour GDPR notification often satisfies the "without unreasonable delay" standard in most US states.

Principle 2: Superset Content Approach

Prepare a single core notification document containing the superset of all content requirements across jurisdictions, then adapt for jurisdiction-specific formatting:

Content ElementGDPR Art. 33(3)California CC §1798.82New York GBL §899-aaTexas BCC §521.053
Nature of breachRequiredRequiredRequiredRequired
Data categories affectedRequiredRequired (specific elements)RequiredRequired
Data subject countRequired (approximate)Not required but recommendedRequiredRequired
DPO/contact detailsRequiredContact details requiredContact details requiredContact details required
Likely consequencesRequiredNot explicitly requiredNot explicitly requiredNot explicitly required
Measures takenRequiredRemedial actions requiredRemedial actions requiredRequired
Credit monitoring offerNot required (but common)Required for SSN/financialRecommendedRequired for SSN
SA notification referenceRequiredAG notification requiredAG notification requiredAG notification required

Principle 3: Parallel Execution Tracks

Manage notifications through parallel workstreams:

Track 1: EU/UK GDPR (72-hour priority)

  • Lead SA notification within 72 hours
  • Phased notification under Art. 33(4) if investigation is ongoing
  • Art. 34 data subject notification within 7 days of high-risk determination

Track 2: US State Notifications (varies by state)

  • AG notifications for each state where affected residents reside
  • Individual notifications per state-specific requirements
  • Substitute notice where individual notification is not feasible

Track 3: Other International Jurisdictions

  • OAIC notification (Australia) within 30 days
  • OPC notification (Canada) as soon as feasible
  • Other jurisdictions as applicable

Lead Supervisory Authority Determination

For Stellar Payments Group with main establishment in Berlin, Germany:

  • Lead SA: Berliner Beauftragte für Datenschutz und Informationsfreiheit
  • Concerned SAs: Any SA in an EU member state where affected data subjects reside
  • One-stop-shop mechanism: The lead SA coordinates with concerned SAs under Art. 60
  • Exception: If the breach relates solely to an establishment in another member state, or substantially affects data subjects only in that state, the local SA may be the competent authority under Art. 56(2)

Notification Coordination Checklist

Pre-Notification (Within 24 Hours of Awareness)

  • Determine which jurisdictions are affected based on data subject residency analysis
  • Map applicable notification laws for each jurisdiction
  • Identify the shortest notification deadline and set as primary driver
  • Assign jurisdiction-specific notification leads (EU: DPO; US: General Counsel; APAC: Regional Privacy Manager)
  • Engage external counsel in each jurisdiction as needed

EU/UK Track (72-Hour Deadline)

  • Identify lead SA and prepare notification form
  • Complete Art. 33(3) content requirements
  • Submit notification to lead SA within 72 hours
  • If cross-border, inform lead SA that multiple member states are affected
  • Prepare Art. 34 data subject notification in languages of affected member states

US Track (Varies by State)

  • Determine affected residents per state using postal/billing addresses
  • For each state with 500+ affected residents, prepare AG notification
  • Draft individual notification letters per state content requirements
  • Include credit monitoring offer where required (SSN/financial data states)
  • Engage outside US counsel for state-specific compliance review
  • Submit AG notifications per each state's required timeline
  • Dispatch individual notifications per each state's required timeline

International Track

  • Prepare OAIC notification (Australia) within 30 days
  • Prepare OPC notification (Canada) "as soon as feasible"
  • Assess other jurisdictions (Brazil, Japan, South Korea, Singapore) based on affected populations
  • Engage local counsel for jurisdiction-specific requirements

Coordination with Law Enforcement

In some jurisdictions, law enforcement authorities may request a delay in data subject notification to avoid prejudicing a criminal investigation:

  • EU: EDPB Guidelines 9/2022 acknowledge that law enforcement may request delay; the controller should document the request and comply while still notifying the SA within 72 hours.
  • US: Many state laws explicitly permit delay at law enforcement request. The delay must be documented and notification must proceed promptly upon law enforcement clearance.
  • Best practice: Always notify the supervisory authority/AG on time even if data subject notification is delayed at law enforcement request.

Signals

GitHub stars
72
Forks
7
Last commit
Jul 2026
Advanced
Catalog kind
skill
Gateway key
breach-multi-jurisdiction
Source
github.com/thomasmoreai/legal-skills-open