Skills
GDPR Breach Sentinel
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
Domain skillsBy Oliver Schmidt-PrietzPublished on Lawvable
What this skill does
Incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Covers breach risk assessment using ENISA severity methodology, Controller vs Processor obligations, 72-hour notification clock management, EDPB case matching, cross-border Lead SA determination, AI Act Art. 62 intersection, mitigation playbooks, and audit-ready .docx document generation.
Get this skill on Lawvable
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Oliver Schmidt-Prietz
- DPIA SentinelGDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklists/whitelists. Covers threshold assessment, multi-jurisdictional blacklist checks (DE, FR, IE, BE, NL, IT, PL), 5x5 risk scoring, necessity/proportionality analysis, mitigation mapping, Art. 36 prior consultation, AI dual-phase analysis, an
- Data Processing Agreement Art. 28 GDPRReview, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or prepare a Joint Controller Arrangement under Art. 26 GDPR (basic). Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and two review depths — quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring).
- EU AI Act System ClassifierDetermine whether a technology qualifies as an AI system under Art. 3(1) and classify its risk tier (prohibited, high-risk, GPAI with systemic risk, limited risk, minimal risk). Covers scope exclusions (Art. 2), AI system definition test (7 criteria), prohibited practice screening (Art. 5), high-risk assessment (Annex I + III with Art. 6(3) exception), GPAI check, and Art. 50 transparency triggers.
- EU AI Act High-Risk ClassifierDepth assessment of whether an AI system is high-risk under Art. 6 of the EU AI Act, grounded in the Commission's draft Art. 6(5) classification guidelines (general principles + Annex I + Annex III). Covers the Annex I product-safety route, all eight Annex III areas with worked examples, the Art. 6(3) exception and its profiling re-exception, and the Art. 25 quasi-provider trap. Outputs a structured decision block, a practitioner memo, and a JSON interchange artefact.
- EU AI Act Knowledge BaseAuthoritative regulatory Q&A grounded in 70 official EU source documents, including the 2026 Commission draft guidelines on Art. 6 high-risk classification. Answers any EU AI Act question with article-level citations from the full regulation text, Commission guidelines, EDPB/EDPS opinions, codes of practice, harmonised standards, FRIA guides, and sector-specific guidance — covering penalties, timelines, GPAI obligations, high-risk and prohibited practices, and the AI Act / GDPR interplay.
- EU AI Act Obligations MapperMap the full set of legal obligations based on role and risk tier under the EU AI Act, producing an actionable compliance matrix with RACI assignments, implementation priorities, GDPR cross-references, and a phased implementation roadmap.
Skills that do related work
- DPIA SentinelGDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklis
- Supplier DPA GDPR AnalysisSystematic analysis of a Data Processing Agreement (DPA) in light of Article 28 of the GDPR, EDPB Guidelines 07/2020 and 02/2024, the 2021 Standard Contractual
- DPDPA & GDPR Compliance ReviewPerforms structured compliance review, clause redlining, and drafting suggestions for legal documents (privacy policies, data processing agreements, vendor and
- Legal Analysis ForgeEU Digital Regulation Legal Analysis Forge — generates a tailored expert prompt for structured legal analysis of an EU digital-regulation document, optionally e
- Mediation Dispute AnalysisAnalyzes legal disputes for mediation purposes — reviewing case materials (pleadings, contracts, correspondence, evidence), identifying contested issues, summar
- Privacy Policy GeneratorGuide for drafting privacy policies compliant with GDPR. Includes CNIL 2020 recommendations, a reference template, and best practices. Use when drafting or revi