Skip to main content
Glama

Data Breach Notification Deadlines

Server Details

Who to notify after a data breach and by what date: all US states, SEC, HIPAA, GDPR, UK. Sourced.

If you are the author of this connector, you can claim ownership by verifying the domain or GitHub account it belongs to. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP · MCP 2025-06-18
URL

TDQS

Score is being calculated.

Available Tools

3 tools
list_breach_lawsInspect

Lists breach notification laws with who is covered, which data types trigger them, encryption exemptions, every notice with its deadline rule and threshold, penalties and the official source. Filter by US state, country (ISO code or name) or scope (us_state, us_federal_sector, country, region). Free.

ParametersJSON Schema
NameRequiredDescriptionDefault
scopeNoOptional: us_state, us_federal_sector, country or region.
stateNoOptional US state code or name.
countryNoOptional country code or name, for example "GB", "Germany", "Canada".
list_capabilitiesInspect

Lists coverage (US states, US federal sector rules, countries), the date the data was last checked, and related Nero Labs Rules servers. Free.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

who_to_notifyInspect

Works out every data breach notice a company owes and the deadline for each. Give affected (how many people in each US state or country), the data types exposed (for example ssn, drivers_license, payment_card, financial_account, medical, health_insurance, username_password, biometric, passport, dob, email_address), whether the data was encrypted with the key kept safe, the date the breach was discovered, and flags: sec_registrant (US public company), sector (hipaa_covered_entity, hipaa_business_associate, glba_financial, health_app, nydfs_licensee) and role (owner, or service_provider holding data for another company). Returns each notice owed (people affected, state attorneys general, credit bureaus, HHS, SEC Form 8-K, FTC, EU and UK data protection authorities, Canada, Australia) with the deadline as a date where the law sets a fixed period, the deadline rule in words, what the notice must contain, how to send it and the official source, earliest first. Unclear cases give the SAFE answer (notice treated as required) plus what it depends on. Free.

ParametersJSON Schema
NameRequiredDescriptionDefault
roleNoowner (default): the company that owns or licenses the data. service_provider: holds it for another company, which mostly means notifying that company quickly.
sectorNoSector rules that apply: hipaa_covered_entity, hipaa_business_associate, glba_financial (non-bank financial firms under the FTC Safeguards Rule), health_app (FTC Health Breach Notification Rule), nydfs_licensee (New York DFS regulated).
affectedYesWhere the affected people live: [{"state":"CA","count":1200},{"state":"TX","count":300},{"country":"Germany","count":40},{"country":"United Kingdom","count":15},{"country":"Canada","province":"Quebec","count":5}]. A bare two-letter code is read as a US state (CA = California); use {"country":"CA"} or "Canada" for Canada.
encryptedNoTrue only if all the exposed data was encrypted and the key was not exposed. Many US state laws then need no notice. Default false.
data_typesNoPersonal data exposed, for example ["ssn","drivers_license","payment_card"]. If left out every law is treated as triggered (SAFE).
sec_registrantNoTrue for a company that files reports with the US SEC (listed in the US). Adds Form 8-K Item 1.05.
date_discoveredNoDate the breach was discovered (or you became aware of it), YYYY-MM-DD. Defaults to today. Deadlines are counted from it.
materiality_dateNoSEC registrants: date the company decided the incident is material, YYYY-MM-DD. The 8-K is due 4 business days after it.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updates
    • First observedlist_breach_laws
    • First observedlist_capabilities
    • First observedwho_to_notify

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Enables AI assistants to answer questions offline, with no dependencies, about Gulf cyber incident notification duties, including which authorities to alert, their deadlines, and the official source behind each one.
    8
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Broadcasts Article 73 incident reports simultaneously to EU AI Act, DORA, NIS2, GDPR, and ISO 42001 regulators, with escalation workflows and audit trails.
    52 PyPI
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Source-verified regulatory and compliance intelligence: 10,000+ obligations across 39 pillars, each grounded in a primary legal source with a content hash. Covers the EU AI Act, GDPR, DORA, NIS2, HIPAA, Basel III and the MITRE ATT&CK/ATLAS families.
    25
    1
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources