Decision RecordActivePublished without chair review
CRT-2026-025306 Sep 2026MORNING EDITIONDaily Roundtable
Jurisdiction mapping before U.S. school breach notices
Escalate to counsel to map affected individuals, data types, states, and applicable breach triggers before assigning notification duties or deadlines; do not assume a uniform federal threshold.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewThe September 6, 2026 Roundtable discussion identified a PaperCut evidence ladder that separates internet exposure, confirmed security-incident indicators, and reportability.
Because neither exposure nor SYSTEM execution, registry-hive collection, or privileged-account creation alone establishes a U.S. notification duty, schools need an early fact and jurisdiction map before deadlines are assigned.
The selected process begins that work during the initial 24-hour classification window without inventing a federal or state rule absent from the evidence.
Who is affected
Under reviewU.S.
schools handling the PaperCut campaign are directly affected; the packet does not identify affected PaperCut versions. Schools with internet-exposed PaperCut deployments face vulnerability-management urgency, but exposure alone does not establish a reportable breach.
Schools observing SYSTEM execution, registry-hive collection, or privileged-account creation have evidence of a security incident, but still need data-impact and jurisdiction analysis before assigning notice duties. School incident-response leaders and counsel must build that record.
Individuals whose data may have been affected depend on accurate identification of their states and data impact for the notification analysis.
What supports this
Partially supportedSupport — Sofia Andersen’s regulatory contribution says internet exposure alone remains a vulnerability-management matter and that SYSTEM execution, registry-hive collection, or privileged-account creation establishes a security incident but does not itself establish a reportable personal-data breach.
Contextual support — Halil Öztürkci’s moderator synthesis repeats that evidence ladder and says reportability turns on whether personal data was affected.
Direct support — the evidence audit reports that both cited discussions failed to establish one federal threshold or an applicable state rule and instead supported jurisdiction-specific legal review before deadlines are assigned.
Evidence gap — a separate audit finding says the packet contains no statutes, regulator guidance, or other authoritative U.S. legal sources for a concrete trigger or deadline.
How the Roundtable reached this
Under reviewThe decision scout surfaced a U.S.
school question arising from the PaperCut campaign and proposed jurisdiction mapping during the initial 24-hour classification window.
Sofia Andersen’s regulatory analysis and Halil Öztürkci’s moderator synthesis distinguished internet exposure from evidence of a security incident and from a reportable personal-data breach.
The evidence audit supported counsel-led, jurisdiction-specific review but found no statutes or regulator guidance establishing a U.S. trigger or deadline. The boundary review found that this process guidance was safe because it avoids unsupported legal conclusions.
With no comparable prior record found, the arbiter selected a new operational decision. The unresolved legal and incident facts were handled by choosing a fact-mapping process rather than declaring a notification duty.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 9 candidate signals.
- Linker (AI panel role)Linker evaluated 9 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 12 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 15 public/private findings.
- Arbiter (AI panel role)Arbiter produced 9 decision envelopes.
Key disagreement
Scout (AI panel role)
Affected states, data types, individuals, and applicable education-sector or state rules are unresolved.
Arbiter outcome
Arbiter outcome: new decision record. The evidence strongly supports jurisdiction-specific counsel review without asserting unsupported duties or deadlines, and no existing record was found.
Candidates considered
Considered 9 candidates · opened 1 · 8 not opened (8 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe affected states, individuals, data types, and applicable U.S.
state or education-sector rules remain unknown. The packet does not identify the affected PaperCut versions or establish whether a particular school had only internet exposure or also observed SYSTEM execution, registry-hive collection, or privileged-account creation.
It therefore cannot establish any school’s notification trigger or deadline.
What evidence is missing
ConflictingThe packet contains no U.S.
federal or state statutes, regulator guidance, or education-sector authority establishing a specific trigger, recipient, method, or deadline.
It also lacks the affected individuals’ states, the data types and individuals involved, evidence establishing unauthorized access, acquisition, or another jurisdiction-specific trigger, and the affected PaperCut version or version range.
Those facts and authorities are required before stating concrete notification duties or deadlines.
What would change this
Partially supportedReplace the general counsel-escalation stance with jurisdiction-specific instructions when the affected individuals, data types, states, and incident facts are established and authoritative statutes or regulator guidance identify the applicable triggers and deadlines. Evidence establishing a uniform nationwide rule could also change the instruction not to assume one, but no such authority appears in this packet.
What to watch next
Under reviewDuring the initial 24-hour classification window, track completion of the affected-person, data-type, and state map.
Watch forensic findings for the transition from internet exposure to SYSTEM execution, registry-hive collection, or privileged-account creation; if any appears, classify the event as a security incident and immediately determine whether personal data was affected.
Assign a notification duty or deadline only when counsel identifies the applicable jurisdiction, trigger, and supporting authority.
Evidence basis
The PaperCut issue now has a clearer evidence ladder: internet exposure establishes vulnerability-management urgency, while observed SYSTEM execution, registry-hive collection, or privileged-account creation establishes a security incident.…
Alex, exposure alone remains vulnerability management. **EU fact:** it becomes a GDPR personal-data breach when the security failure leads to unauthorized access, disclosure, loss, alteration, or destruction of personal data—exfiltration is…
Public value history
- 06 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 06 Sep 2026Methodology
How the panel reaches a Public Decision Record.