Incident Response and Breach Notification Toolkit
By Casey Scott McKay ·
A data breach is a legal problem disguised as a technical one, and the decisions that determine how it ends are made in the first four hours by people who do not know they are making them. This toolkit runs a response from the first phone call to the post-incident review, and routes each stage to the Marksy documents that do the work. It covers containment that preserves evidence, the privilege structure that cannot be retrofitted, log preservation against retention windows measured in weeks, and the data-element inventory that every legal question depends on. It then covers residence mapping and the shortest applicable deadline, the encryption safe harbor, the risk-of-harm determination and its documentation, notice drafting across inconsistent state requirements, regulator filings, the call center, insurance and vendors, ransomware and sanctions, and the six controls that determine the outcome before anything happens.
IP and Technology > Privacy Data Security | Toolkit | Published 23 June 2026 - Updated 14 July 2026 | Casey Scott McKay - marksy.us
Summary. A data breach is a legal problem disguised as a technical one, and the decisions that determine how it ends are made in the first four hours by people who do not know they are making them. This toolkit runs a response from the first phone call to the post-incident review, and routes each stage to the Marksy documents that do the work. It covers containment that preserves evidence, the privilege structure that cannot be retrofitted, log preservation against retention windows measured in weeks, and the data-element inventory that every legal question depends on. It then covers residence mapping and the shortest applicable deadline, the encryption safe harbor, the risk-of-harm determination and its documentation, notice drafting across inconsistent state requirements, regulator filings, the call center, insurance and vendors, ransomware and sanctions, and the six controls that determine the outcome before anything happens.
Keywords: containment without destruction · privilege structure · forensic engagement through counsel · litigation hold · log retention · data element inventory · encryption safe harbor · residence mapping · deadline calendar · risk of harm determination · notification drafting · attorney general filing · credit agency notice · call center scripting · insurance notice · vendor contract review · ransomware sanctions screening · securities disclosure · decision log · post-incident review
Start Here
Winterbourne Health Services detects anomalous authentication against an administrative console at 7:40 on a Friday evening. Within an hour, four decisions are being made by people who do not know they are decisions.
The on-call engineer begins reimaging the affected host to restore service.
The technology director calls the firm the company uses for penetration testing, under an existing master services agreement.
Someone sends an all-hands email asking whether anyone noticed anything unusual this week.
And nobody has checked how long the authentication logs are retained.
Four decisions, all reversible for about another hour, and all of them determining what the next eight months look like.
This toolkit answers three questions.
- What must happen in the first four hours? Contain without destroying, and decide who directs the investigation. Nothing else in the response can be fixed afterward if these are wrong.
- What triggers notification, and to whom, by when? A data-element inventory, a residence map, and the shortest applicable deadline.
- What determines whether this is manageable? Six controls that existed or did not before Friday evening.
If you read only one thing, read The First Seventy-Two Hours. It explains what actually triggers an obligation, which is narrower and more variable than most companies assume.
The First Four Hours
Contain, and preserve while containing. Isolate systems, revoke credentials, and block the access path. Do not reimage. Reimaging a compromised host destroys the evidence that answers whether data left, which is the question everything else turns on — and Winterbourne's on-call engineer is destroying it right now.
Decide who directs the investigation. Outside counsel engages first, and the forensic firm is engaged by counsel. Where the technology team has already called its usual vendor, stand up a parallel counsel-directed workstream immediately rather than trying to retrofit privilege onto work underway.
Open a decision log. Who decided what, when, and on what information. It is the record that answers a regulator two years later, it is nobody's job by default, and it cannot be reconstructed.
Do not send company-wide email. Every message is discoverable and most of them speculate.
Preserve logs immediately. Firewall, VPN, authentication, database access, endpoint telemetry, email, and cloud audit logs. Retention windows are short and rolling — seven days is common — and this is where cases are decided before anyone knows there is a case.
The Privilege Structure
Engagement. Outside counsel retains the forensic firm. The statement of work states the engagement is to assist counsel in rendering legal advice and in anticipation of litigation, and it describes a scope different from the firm's ordinary incident response work.
Separate the workstreams. Remediation — restore, patch, harden — runs under the technology team with its own vendor and its own reporting. The legal investigation runs under counsel. Two workstreams, two reports.
Limit distribution of the legal report. Counsel, a defined internal legal group, and named executives. Not the board deck, not the insurer's file, not the technology organization's ticketing system.
Pay through the legal budget.
What defeats privilege. A pre-existing master services agreement with the forensic firm — Winterbourne's second decision. A statement of work identical to the firm's standard engagement. A single report circulated to everyone. And a factual record showing the company would have commissioned the same investigation regardless of litigation. Fed. R. Civ. P. 26.
Why it matters. The forensic report is the most consequential document in the response and the most frequently discoverable, and the structure is decided in the first hours or not at all.
Preservation
Issue the litigation hold within hours, reaching the security team, the owners of affected systems, executives, and anyone who communicated about the incident.
Preserve logs first, by imaging rather than by exporting a report, because the report is a summary and the underlying data is the evidence.
Image affected systems before remediation.
Preserve attacker artifacts — malware samples, scripts, staged archives, and command-and-control indicators — and any communications with the attacker.
Document chain of custody from the first image forward.
Do not let internal IT investigate. Well-meaning examination alters metadata and creates a chain-of-custody problem that is entirely avoidable.
The Data-Element Inventory
The single most important work product in the response.
Not the record count. The specific fields, per record, per affected individual. Names, Social Security numbers, driver's licence numbers, financial account numbers with access codes, medical information, biometric data, and credentials.
Per system, per table. Legacy systems are where the surprises live, and the surprises are usually data collected years earlier for a purpose nobody remembers.
What was actually accessible, not merely what the system holds. A query returning aggregates from a table containing sensitive fields did not expose those fields.
Encryption state, field by field. To what standard, and whether the key was also acquired.
Deliverable. A matrix of population by data element by system by encryption state. Every state analysis runs off it, and a company with no maintained data inventory spends five weeks building it under deadline.
What Triggers Notification
There is no federal breach statute of general application. What exists is fifty-plus state statutes, several sector-specific federal regimes, and a securities disclosure rule, layered.
The definitional trigger. Unauthorized acquisition of, or access to, personal information — and which of those two verbs a statute uses matters, particularly for ransomware.
Personal information varies. The common core is a name plus a Social Security number, a driver's licence number, or a financial account number with an access code. Common extensions reach medical information, health insurance information, biometric data, credentials with a password, taxpayer identification numbers, and passport numbers. A few states reach date of birth or mother's maiden name.
The state statutes. Cal. Civ. Code § 1798.82 is the model most followed, requiring disclosure in the most expedient time possible and prescribing content, with Cal. Civ. Code § 1798.29 covering agencies. N.Y. Gen. Bus. Law § 899-aa reaches an expanded element set and N.Y. Gen. Bus. Law § 899-bb adds an affirmative security obligation. Tex. Bus. & Com. Code § 521.053 imposes a sixty-day outer limit. 740 ILCS 530/10 carries the Illinois obligation. And Mass. Gen. Laws ch. 93H § 3 prohibits describing the nature of the breach in the individual notice — the opposite of what several other states require, and a genuine drafting problem.
The encryption safe harbor. Nearly universal, and the single most valuable control a company can have, because it converts a notifiable event into a non-event. The safe harbors differ: some require a specified standard, some only that data be rendered unreadable, and some also cover redaction or tokenization. All require that the key not also have been acquired.
The good-faith employee exception, excluding acquisition by an employee or agent for a legitimate purpose where the information is not further used or disclosed.
The Deadline Calendar
Map affected individuals to states of residence. The obligation follows the individual, not the company.
Identify the shortest applicable deadline. Fixed-day statutes, expedient-time standards, and any sector rule. The shortest governs everyone, because notifying different states on different days is operationally impossible and reads worse than a single date.
Determine the trigger date per state. Some run from discovery of the incident, some from determination that a breach occurred. Run from the earlier where the distinction is contested.
Law enforcement delay requires a request that notification would impede an investigation, documented, and it ends when law enforcement says it may.
The sector deadlines. Health breach notice to individuals without unreasonable delay and not later than sixty days under 45 C.F.R. § 164.404, to the regulator under 45 C.F.R. § 164.408, and to media above five hundred residents under 45 C.F.R. § 164.406. Financial safeguards under 15 U.S.C. § 6801, enforced by functional regulators under 15 U.S.C. § 6805. And for a public company, disclosure of a material cybersecurity incident within four business days of determining materiality, with the determination itself required without unreasonable delay.
Build the calendar backward from go-live through approval, drafting, forms, print lead time, and call center standup.
The Risk-of-Harm Determination
Know which states permit it. Several require notification whenever the definitional trigger is met, and those states set the national floor.
Document it in writing — the facts relied on, the analysis, the conclusion, and the date — retained, and filed with the attorney general where required.
What supports it. Data recovered before use. A device located intact with forensic confirmation it was never accessed. Encryption falling just short of the safe harbor. An internal misdirection with confirmed deletion. Access logs showing no retrieval within a short exposure window.
What does not. The absence of evidence of misuse, standing alone. Regulators read that as the absence of investigation.
For health information, apply the four-factor assessment: the nature and extent of the information, the unauthorized person who used or received it, whether it was actually acquired or viewed, and the extent of mitigation. A presumption of breach applies unless the assessment demonstrates a low probability of compromise. 45 C.F.R. § 164.402.
Document a decision not to notify. A decision is a decision, and it should have a written basis with a date. The absence of a file is how a defensible call becomes indefensible two years later.
Drafting the Notices
Assume multiple versions, because a single national notice cannot satisfy a state requiring a description of the incident and a state prohibiting one.
Differentiate by exposure where the population differs. Sending everyone the worst-case notice is over-inclusive and, in some states, non-compliant.
Be precise about dates and explicit about what remains under investigation.
Avoid characterizations of severity. "A sophisticated attack" reads as excuse-making and "a minor incident" reads as minimization, and both appear in complaints.
Describe fraud alerts and security freezes with the mechanism and the credit reporting agencies' contact details. 15 U.S.C. § 1681c-1.
State the monitoring offer, its period, and its deadline, and do not condition it on a release, which several states prohibit.
Follow the format rules — conspicuous, not commingled with marketing, and using any prescribed heading.
Prepare substitute notice where cost or population thresholds are met: email where available, conspicuous website posting, and statewide media.
Assume the regulator version becomes public, because several attorneys general publish them and the description written for regulators is the one reporters quote.
Regulators, Agencies, and the Call Center
Attorney general filings, on different forms and portals with different thresholds.
Credit reporting agencies where the affected resident count exceeds the state threshold.
Sector regulators on their own clocks, several shorter than any state deadline.
Securities disclosure for a public company, coordinated with the materiality determination.
The call center, scripted and reviewed by counsel, staffed before the notices land, with an escalation path for people reporting actual fraud and a log of every call. This is where careful drafting is most often undone, by an agent improvising an answer about scope.
One spokesperson, one approved statement for media and partners, updated only when the facts change.
Employee communications are external. They are forwarded, screenshotted, and produced. Write them as though a regulator will read them.
Enterprise customer contracts frequently impose notice deadlines shorter than any statute and some require notice of an incident rather than a confirmed breach. Read them early.
Insurance, Vendors, and Ransomware
Notify insurers immediately. Most policies require prompt notice and several require consent before costs are incurred. Four weeks of forensics followed by a tender produces a consent-to-incur argument the insured loses.
Check panel provisions before the incident. Many policies require panel counsel and forensic firms, and using your own must be endorsed at renewal rather than argued at claim time.
Track costs by policy category from day one, because reconstructing them against sublimits later is painful and lossy.
Understand that betterment is not covered — the security improvements the incident revealed to be necessary — and it is frequently the largest post-incident line item.
Read the vendor contract on day one where a provider is involved: its notice deadline to you, its cooperation obligation, its indemnity, and whether it may notify anyone without your approval. Under the health rules, 45 C.F.R. § 164.410 governs a business associate's notice to the covered entity, and a provider taking the full permitted period consumes most of the covered entity's clock.
Demand the vendor's data-element inventory for your records, not a two-paragraph assurance.
Ransomware. Determine whether encryption alone meets the definitional trigger in each state. Assume exfiltration unless the logs exclude it, because modern ransomware exfiltrates before encrypting and a threat to publish is evidence of acquisition. Screen any payment for sanctions exposure before it is made, because payment to a designated person carries strict liability risk. Understand that payment does not resolve notification — a deletion assurance from a criminal is not a forensic finding — and that restoration from backup does not answer whether data left.
The Six Controls
Every post-incident finding reduces to one of these, and the response's quality is largely determined by which existed beforehand.
Encryption at rest with separated key management. The highest leverage on the list, because the safe harbors convert a notifiable event into a non-event.
Log retention long enough to exclude exfiltration. Ninety days is a workable floor for authentication, database access, network egress, and cloud audit trails. The cheapest control and the most commonly deficient.
Data minimization on a schedule that runs. Records deleted before the incident are not in the breach, and the recurring finding is years of data retained for no reason.
A maintained field-level data inventory, which converts a five-week scoping exercise into a two-day one.
Vendor contract terms — notification within days, cooperation with access to findings, meaningful indemnity, and a prohibition on the vendor notifying anyone without approval.
A tested plan with named people, pre-engaged counsel, a pre-selected forensic firm engageable through counsel within hours, and an insurance endorsement permitting your counsel if you want it.
None is exotic or expensive relative to a single response. They are absent because each is invisible until the night it matters.
The Litigation That Follows
Consumer class actions within days of a notice reaching a meaningful population, on negligence, implied contract, unjust enrichment, and state consumer protection theories. The perennial difficulty is injury, and courts divide on whether increased risk, monitoring time, and diminished value suffice.
The statutory claim. Cal. Civ. Code § 1798.150 supplies a private right of action with statutory damages for a breach of enumerated elements resulting from a failure to maintain reasonable security, which removes the injury problem for the categories it covers.
Financial institution claims for reissuance costs and fraud losses, constrained by the economic loss rule and by card network allocation rules.
Securities and derivative claims for a public company following disclosure.
Regulatory proceedings, frequently multistate, resolving with a security program, assessments, and payments.
Class certification. Fed. R. Civ. P. 23. Predominance is contested where data elements differ across the population and injury varies.
And the notice itself is quoted in the first paragraph of the complaint. A notice overstating certainty and later corrected supplies the deception allegation; one understating and later expanded supplies the concealment allegation. Precision about what is known, with explicit acknowledgment of what remains open, survives both.
Winterbourne's Four Decisions, Reversed
The reimaging. Stop it. The compromised host is the evidence that answers whether data left, and once it is reimaged the analysis proceeds on the assumption that everything did — which changes the notification population from a determinable set to the entire database. Isolate rather than restore, image before touching, and accept the service outage. The forty minutes of additional downtime is the cheapest thing in this response.
The penetration testing firm. The problem is not the firm's competence; it is the master services agreement it works under. A forensic investigation conducted under a pre-existing general engagement, by a firm the company uses for ordinary security work, is the fact pattern in which privilege most often fails. Engage outside counsel tonight, have counsel retain a forensic firm under a statement of work referencing anticipated litigation, and let the existing vendor handle remediation on a separate track with separate reporting.
The all-hands email. Already sent, already discoverable, and it will produce replies from people speculating about what happened. Follow it with a short, counsel-reviewed message telling employees that an issue is being investigated, that they should not discuss it, and that questions go to a named person. Then stop.
The log retention question. The most urgent item and the only one nobody has touched. Find out tonight how far back authentication, VPN, database access, and cloud audit logs go, and preserve them by imaging. If the answer is seven days, the intrusion window may already be partly gone, and knowing that changes both the investigation plan and the notification analysis.
What the first hour should have been. Contain, preserve, call the general counsel, and ask one question: how long do the logs go back. Everything else follows.
The Documentation File
Three years after an incident, what protects the company is the file. Confirm each of these exists.
The decision log. Every material decision, who made it, when, and on what information. Regulators ask why notification took eleven days, and the answer is either a documented sequence of investigative findings or an absence.
The forensic conclusions, in the privileged workstream, with remediation kept separate.
The data-element matrix, with version history showing how the population estimate changed and why.
The encryption findings, field by field, with the technical basis.
The risk-of-harm determination where relied on.
The residence map and the deadline calculation, showing which statute governed and why.
Every notice version and the population that received it.
Every regulator filing and its confirmation.
The call center log, including complaints and escalations.
The cost record by policy category.
The post-incident review and the remediation plan, with completion dates — a document that is uncomfortable to write and that is the strongest evidence of good faith available, provided the items were actually completed. An identified deficiency with no completion date is worse than no review at all.
The board reporting record, because the oversight claim turns on whether the board was informed and what it did.
Who Runs It
Response fails on organization more often than on analysis, and the roles should be assigned by name before anything happens.
The decision-maker. One executive with authority to spend, to notify, and to make the materiality call, available at any hour. Not a committee, because a committee that must convene is a committee that meets on Monday — and Winterbourne's incident began on a Friday evening, which is when they always begin.
Outside counsel, engaged in advance with conflicts cleared and an engagement letter ready to sign.
The forensic firm, pre-selected, engageable through counsel within hours, and not already retained under a general master services agreement.
The internal lead, usually the chief information security officer, running containment and remediation, reporting to the decision-maker and coordinating with counsel rather than directing the legal investigation.
The communications owner, working from counsel-approved statements.
The notification project manager. An underrated role. Notification is logistics — versions, populations, print vendors, portals, staffing, deadlines — and it needs someone who runs projects rather than someone who practices law.
The insurer liaison, tracking costs by policy category from day one and managing consent-to-incur.
The scribe, maintaining the decision log.
Test the assignments annually in an exercise using a realistic scenario, starting at the wrong hour, forcing the privilege decision in the first ten minutes and a communications decision under pressure. A plan naming titles rather than people, or naming people who have since left, is a plan that fails at the moment it is opened.
Incidents That Are Not Breaches
Not every incident triggers an obligation, and treating every alert as a breach exhausts a response function that needs to be sharp when it matters.
Confirm personal information was involved at all. An intrusion into a build server holding no personal data is a security incident and not a notifiable breach, though it may trigger contractual notice to customers.
Confirm acquisition or access, as the state defines it. A misconfiguration that made data reachable in principle, with logs showing nobody reached it, is a different case from one where the logs are absent.
Confirm the data elements meet a definition somewhere. Names alone, business contact information, and publicly available government record information are outside most definitions.
Apply the encryption and redaction safe harbors.
Check the good-faith employee acquisition exception, which most statutes supply where an employee or agent acquired the information for a legitimate purpose and it was not further used or disclosed.
Check the internal misdirection scenario. An email sent to the wrong internal recipient, confirmed deleted and not forwarded, frequently supports a no-notification determination — documented.
Check contractual obligations separately from statutory ones. Enterprise customer agreements requiring notice of any security incident regardless of the statutory threshold are where most notices actually originate for business-to-business companies.
Track the near misses. A pattern of incidents that fell just short is the strongest internal argument for funding the six controls, and it is the record a regulator will find if it looks.
Twenty Failure Modes
Internal IT investigates first. Metadata altered, chain of custody broken, and the strongest evidence now contestable.
The pivot host is reimaged. The evidence answering the exfiltration question is gone.
Logs roll over. Seven-day retention discovered on day nine.
The technology team calls its usual vendor. Privilege lost before counsel was involved.
A single forensic report circulated to the board, the insurer, the merchant bank, and the technology organization.
No data inventory, so five weeks are spent answering what fields were in a legacy table.
The residence map done in week four, with a thirty-day state discovered with nine days left.
The trigger date measured from the wrong event — determination rather than discovery.
A press statement on day four with a number in it, two orders of magnitude off, opening the complaint.
The risk-of-harm determination never written down.
One national notice, which cannot satisfy a state requiring a description and one prohibiting it.
The call center improvising an answer about scope.
The insurer tendered in week five, after four weeks of costs incurred without consent.
The vendor notifies your customers directly, in language the data owner never saw.
The vendor's two-paragraph assurance accepted in place of a data-element inventory.
Ransom paid before sanctions screening.
Betterment assumed to be covered.
Enterprise customer notice provisions read at month two, after their deadlines passed.
The post-incident review written outside privilege, listing every failure, produced in discovery.
Findings left open. An identified deficiency with no completion date, two years old, is worse than the original failure.
The Post-Incident Review
Run it under privilege. The review will identify failures, by design, and a document cataloguing them is a plaintiff's exhibit unless it is structured as counsel-directed work in anticipation of the litigation that a notified breach reliably produces.
Expect the recurring findings. Log retention too short to exclude exfiltration. No maintained data inventory. Unencrypted legacy stores holding data collected years earlier for a forgotten purpose. Detection that depended on an external party rather than on internal monitoring. An incident response plan never exercised. And vendor contracts with three-week notification deadlines.
Fix the six controls in order of leverage.
Fix the contracts at the next renewal cycle rather than waiting for the next incident.
Fix the plan and exercise it, with named decision-makers and a pre-selected forensic firm.
Report to the board with the findings and the completion plan, because the oversight claim turns on whether the board was informed and what it did.
Close the items. An open finding discovered in discovery two years later is worse than the original failure, because it establishes that the company knew about the deficiency and did nothing. This is the single most common way a well-run response becomes a bad exhibit, and it happens because the review is treated as the end of the matter rather than as the beginning of a remediation plan with owners and dates.
A Suggested Reading Path
Tonight:
Before an incident:
- The Data Behind the Marketing
- Building a Privacy Compliance Program for a Consumer Brand
- Marketing Privacy Compliance Checklist
For the vendor terms that decide who pays:
Primary Authorities
| Authority | Proposition | |---|---| | Cal. Civ. Code § 1798.82 | Notification; content and timing | | Cal. Civ. Code § 1798.29 | Parallel agency obligation | | Cal. Civ. Code § 1798.150 | Private right of action | | N.Y. Gen. Bus. Law § 899-aa | Expanded data elements | | N.Y. Gen. Bus. Law § 899-bb | Reasonable security obligation | | Tex. Bus. & Com. Code § 521.053 | Sixty-day outer limit | | 740 ILCS 530/10 | Illinois notification | | Mass. Gen. Laws ch. 93H § 3 | Prohibits describing the breach | | 45 C.F.R. § 164.402 | Health breach; four-factor test | | 45 C.F.R. § 164.404 | Individual notice; sixty days | | 45 C.F.R. § 164.406 | Media notice | | 45 C.F.R. § 164.408 | Notice to the regulator | | 45 C.F.R. § 164.410 | Business associate notice | | 15 U.S.C. § 6801 | Financial safeguards | | 15 U.S.C. § 6805 | Functional regulator enforcement | | 15 U.S.C. § 1681c-1 | Fraud alerts and freezes | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 18 U.S.C. § 1030 | Computer fraud; the attacker | | 18 U.S.C. § 2511 | Interception | | Fed. R. Civ. P. 26 | Work product; forensic privilege | | Fed. R. Civ. P. 23 | Class certification |
Forms and Templates
The License Agreement Template is where the vendor terms that decide a response live: the incident notification deadline measured in hours rather than days, the cooperation obligation with access to findings, the prohibition on the vendor notifying your customers, and an indemnity that bears some relationship to notification costs. A company that negotiated those four terms before an incident has a materially different response from one that reads its supply agreement on day one and discovers a three-week vendor notification window. The Portfolio Inventory Template doubles as the systems and data register — which systems hold which elements, in what encryption state, with what log retention — and it is the artifact that turns a five-week forensic scoping exercise into a two-day one. The Cease and Desist Template matters for the rarer case where the incident involved a departing employee or a competitor rather than an outside intruder, because the trade secret preservation and demand sequence runs in parallel with the notification analysis.
Related Toolkits and Checklists
Where the exposed data includes biometric identifiers, the Biometric and Sensitive Data Toolkit supplies the additional consent and retention obligations and the private right of action that attaches to insecure handling. For the ongoing privacy program these obligations sit inside, the Privacy and Marketing Data Toolkit. For the vendor agreements that determine notification timing and who bears the cost, the Technology Contracts Toolkit. And where the incident involved an insider rather than an intruder, the Trade Secret Litigation Toolkit runs the parallel preservation and claim analysis.
Related Documents
Articles
- The First Seventy-Two Hours
- Your Face as Data
- The Data Behind the Marketing
- What You Are Actually Buying
- Who Owns the Data
Guides
- Running a Data Breach Response
- Building a Biometric Compliance Program
- Building a Privacy Compliance Program for a Consumer Brand
- Negotiating a Technology Agreement
Checklists
- Incident Response Checklist
- Biometric Data Checklist
- Technology Agreement Checklist
- Marketing Privacy Compliance Checklist
Toolkits
- Biometric and Sensitive Data Toolkit
- Privacy and Marketing Data Toolkit
- Technology Contracts Toolkit
- Trade Secret Litigation Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Breach obligations turn on specific data elements, states of residence, and sector rules. Marksy is not a law firm.