Data Incident Impact Brief

Prepares a DRAFT data incident impact brief from the incident notes and data inventory the user provides: the timeline as stated, systems involved matched to the inventory, data categories held and evidenced as involved, people and record counts potentially affected with the source and method behind every figure, third parties, notification questions for legal and the data protection officer, and every UNKNOWN with the evidence that would settle it. No legal determination: it never states whether the incident is a reportable breach, whether notice is due, to whom or by when. Use when the user asks to "prepare the impact brief for this incident", "what data was involved", "how many people are affected", "map the incident to our data inventory" or "pull together what legal needs on the incident". Do not use for the blameless postmortem or root-cause timeline, use incident-postmortem-drafter instead. Drafts for human review; never approves, authorises or signs off.

kesslernity Updated

File contents

kesslernity/awesome-copilot-agent-skills/tree/main/skills/security-grc/data-incident-impact-brief commit 7400de4082

Frequently asked questions

npx skillmds@latest add kesslernity/data-incident-impact-brief