Legal Adjacent Writing
Parent: Writing and Documentation · researched 2026-05-29T19:22:24.356Z· 9 sources · 10 concepts · skill legal-adjacent-writing
Reference for drafting legal-adjacent prose that will go to counsel: contracts, disclaimers, privacy notices, breach disclosures, and regulator-facing statements. This skill is craft for drafts, not l
Legal-Adjacent Writing
- Reference for drafting legal-adjacent prose that will go to counsel: contracts, disclaimers, privacy notices, breach disclosures, and regulator-facing statements. This skill is craft for drafts, not legal advice. Every output should carry a "counsel must review before execution" footer. [source]
The five-point legal-adjacent writing test
- Is the risk-allocating verb correct? "Shall," "will," "must," and "may" are not synonyms. Modern drafting prefers "must" over "shall" because "shall" has been litigated into ambiguity. [source]
- Are the defined terms actually defined? Every Capitalized Term should appear once in a Definitions section. [source]
- Does the carve-out language survive a hostile read? "Except for" should be paired with a non-exhaustive list ("including but not limited to") only when you want breadth. [source]
- Is the temporal scope explicit? "In the 12 months preceding the event giving rise to the claim" is unambiguous. "In the prior year" is ambiguous. [source]
- Is the notice-and-cure mechanism workable? If a clause requires "written notice," specify the delivery channel, the recipient, and the cure window. [source]
2. The limitation-of-liability triangle
- Cap amount. Most common SaaS form: "fees paid by Customer in the 12 months preceding the event." [source]
- Damages exclusion. "No indirect, incidental, special, consequential, or punitive damages, including lost profits." [source]
- Carve-outs. Standard market carve-outs: breach of confidentiality, breach of IP indemnification, payment obligations, gross negligence, willful misconduct, death or personal injury. [source]
3. The "AS IS" warranty disclaimer
4. The 8-K Item 1.05 cyber disclosure
- The SEC's 2023 cybersecurity rules require public companies to file a Form 8-K within four business days of determining that a cybersecurity incident is material. [source]
- What must be disclosed: [source]
- The material aspects of the nature, scope, and timing of the incident [source]
- The material impact or reasonably likely material impact on the registrant [source]
- What is NOT required: specific technical detail about the attack vector, specific detail about cybersecurity systems, or any detail that would impede ongoing remediation. [source]
5. GDPR Article 33 — the 72-hour clock
- GDPR Article 33 requires controllers to notify the supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." [source]
- Phased notification is explicitly permitted. Article 33(4) allows you to provide information "in phases without undue further delay." [source]
- The notification must include: [source]
- Nature of the breach [source]
- Name and contact details of the DPO [source]
- Likely consequences of the breach [source]
- Measures taken or proposed [source]
6. Privacy notice architecture (GDPR / CCPA / CPRA)
- Required components under GDPR Article 13/14: [source]
- Identity and contact details of the controller [source]
- Purposes of processing and legal basis for each [source]
- Recipients or categories of recipients [source]
- Storage period or criteria [source]
- Data subject rights [source]
- Right to lodge a complaint with a supervisory authority [source]
Anti-Patterns
- Mixing "shall" and "must" within the same document. Pick one register. [source]
- The "reasonable" undefined. "Commercially reasonable" should be defined or paired with a benchmark. [source]
- Non-conspicuous warranty disclaimers. A disclaimer that is not in all caps may be ignored under UCC § 2-316. [source]
- Promising what you can't deliver in a privacy notice. "We will never share your data with anyone" creates a contractual representation. [source]
- Stuffing technical detail into an 8-K cyber disclosure. Describe impact, not mechanism. [source]
Final reminder
- > This is draft language only. It is not legal advice. Qualified counsel must review before execution, filing, or public release. [source]
References
Children
- Disclaimers and AS-IS Language (frontier)
- MSA and NDA Structure (frontier)
- Terms of Service Architecture (frontier)
- Privacy Notices (GDPR/CCPA/CPRA) (frontier)
- Security Incident Disclosures (8-K Item 1.05) (frontier)
- Warranty and Limitation-of-Liability Clauses (frontier)
- Indemnification with Carve-Outs (frontier)
- Force-Majeure Clauses (frontier)
- SOC2/HIPAA Notice Patterns (frontier)
- Risk-Allocating Contract Architecture (frontier)
Frontier under this node: Disclaimers and AS-IS Language, Force-Majeure Clauses, Indemnification with Carve-Outs, MSA and NDA Structure, Privacy Notices (GDPR/CCPA/CPRA), Risk-Allocating Contract Architecture, SOC2/HIPAA Notice Patterns, Security Incident Disclosures (8-K Item 1.05), Terms of Service Architecture, Warranty and Limitation-of-Liability Clauses