Data Breach Notification Deadlines

Who to notify after a data breach and by what date: all US states, SEC, HIPAA, GDPR, UK. Sourced.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
73%
命名の品質
93%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~948トークン数(ツール定義)
~2.4 KB一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.74%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "breach-notification-deadlines": {
      "url": "https://breach-notification-deadlines.nerolabs.workers.dev/mcp"
    }
  }
}

リモートエンドポイント

https://breach-notification-deadlines.nerolabs.workers.dev/mcpstreamable-http

できること

ツール一覧

ツール(3)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢list_capabilities

Lists coverage (US states, US federal sector rules, countries), the date the data was last checked, and related Nero Labs Rules servers. Free.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟡who_to_notify(affected, data_types, encrypted, date_discovered, sec_registrant, ...)

Works out every data breach notice a company owes and the deadline for each. Give affected (how many people in each US state or country), the data types exposed (for example ssn, drivers_license, payment_card, financial_account, medical, health_insurance, username_password, biometric, passport, dob, email_address), whether the data was encrypted with the key kept safe, the date the breach was discovered, and flags: sec_registrant (US public company), sector (hipaa_covered_entity, hipaa_business_associate, glba_financial, health_app, nydfs_licensee) and role (owner, or service_provider holding data for another company). Returns each notice owed (people affected, state attorneys general, credit bureaus, HHS, SEC Form 8-K, FTC, EU and UK data protection authorities, Canada, Australia) with the deadline as a date where the law sets a fixed period, the deadline rule in words, what the notice must contain, how to send it and the official source, earliest first. Unclear cases give the SAFE answer (notice treated as required) plus what it depends on. Free.

入力スキーマ

{
  "type": "object",
  "properties": {
    "affected": {
      "type": "array",
      "description": "Where the affected people live: [{\"state\":\"CA\",\"count\":1200},{\"state\":\"TX\",\"count\":300},{\"country\":\"Germany\",\"count\":40},{\"country\":\"United Kingdom\",\"count\":15},{\"country\":\"Canada\",\"province\":\"Quebec\",\"count\":5}]. A bare two-letter code is read as a US state (CA = California); use {\"country\":\"CA\"} or \"Canada\" for Canada.",
      "items": {
        "type": "object"
      }
    },
    "data_types": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Personal data exposed, for example [\"ssn\",\"drivers_license\",\"payment_card\"]. If left out every law is treated as triggered (SAFE)."
    },
    "encrypted": {
      "type": "boolean",
      "description": "True only if all the exposed data was encrypted and the key was not exposed. Many US state laws then need no notice. Default false."
    },
    "date_discovered": {
      "type": "string",
      "description": "Date the breach was discovered (or you became aware of it), YYYY-MM-DD. Defaults to today. Deadlines are counted from it."
    },
    "sec_registrant": {
      "type": "boolean",
      "description": "True for a company that files reports with the US SEC (listed in the US). Adds Form 8-K Item 1.05."
    },
    "materiality_date": {
      "type": "string",
      "description": "SEC registrants: date the company decided the incident is material, YYYY-MM-DD. The 8-K is due 4 business days after it."
    },
    "sector": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "hipaa_covered_entity",
          "hipaa_business_associate",
          "glba_financial",
          "health_app",
          "nydfs_licensee",
          "telecom",
          "critical_infrastructure"
        ]
      },
      "description": "Sector rules that apply: hipaa_covered_entity, hipaa_business_associate, glba_financial (non-bank financial firms under the FTC Safeguards Rule), health_app (FTC Health Breach Notification Rule), nydfs_licensee (New York DFS regulated)."
    },
    "role": {
      "type": "string",
      "enum": [
        "owner",
        "service_provider"
      ],
      "description": "owner (default): the company that owns or licenses the data. service_provider: holds it for another company, which mostly means notifying that company quickly."
    }
  },
  "required": [
    "affected"
  ],
  "additionalProperties": false
}
🟢list_breach_laws(state, country, scope)

Lists breach notification laws with who is covered, which data types trigger them, encryption exemptions, every notice with its deadline rule and threshold, penalties and the official source. Filter by US state, country (ISO code or name) or scope (us_state, us_federal_sector, country, region). Free.

入力スキーマ

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "Optional US state code or name."
    },
    "country": {
      "type": "string",
      "description": "Optional country code or name, for example \"GB\", \"Germany\", \"Canada\"."
    },
    "scope": {
      "type": "string",
      "description": "Optional: us_state, us_federal_sector, country or region."
    }
  },
  "additionalProperties": false
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 3 件