Data Protection
Skills
Age Verification and Estimation Methods
Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, sel…
APEC Cross-Border Privacy Rules Certification
Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accounta…
Assessing Health Data Processing
Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial…
Children's Data Minimisation and Retention Limits
Implements strict data minimization and retention limits for children's personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and CO…
Children's Profiling Restrictions
Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural a…
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
Conducting AI System Privacy Assessment
Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training da…
Cookie Consent Banner and Policy
Drafts publication-ready cookie policies, banner copy, and consent-flow language under GDPR/ePrivacy, CCPA/CPRA, and major U.S. state privacy laws. C…
Cyber Law Compliance Summary
Produces structured cyber law compliance memoranda covering GDPR, CCPA, state privacy laws, and sector-specific regulations for US and EU operations.…
data-privacy-agreement
Draft and fill data privacy agreement templates — DPA, data processing agreement, GDPR, HIPAA BAA, business associate agreement, AI addendum. Produce…
DPA Checklist Review
Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains …
DPA Checklist Review
Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains …
DSAR Form
Drafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. …
Evaluating Consent Management Platforms
Framework for evaluating and selecting Consent Management Platforms (CMPs). Covers TCF v2.2 certification requirements, Global Privacy Control suppor…
GDPR/DSGVO Expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Us…
Implementing GDPR Data Subject Access Request (DSAR) Workflow
Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and…
Key principles
Use this skill when implementing GDPR or CCPA compliance, designing consent management, conducting DPIAs, or managing data processing agreements. Tri…
KVKK & GDPR Compliance Patterns
KVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification.
Legal Compliance Agent
Generate legally compliant privacy policies, terms of service, HIPAA documentation, and compliance pages for healthcare SaaS platforms. Ensures Googl…
Legal Document Generation & Compliance
Legal document generation and compliance guidance for indie Apple developers. Covers privacy policies, terms of service, EULAs, GDPR/CCPA/DPDP compli…
Maestro Compliance Check
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
Managing APAC Cross-Border Transfers
Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan…
Managing Conflicting Privacy Requirements
Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age…
data-protection legal skills for CROSS-JURISDICTION
Cross-border data flows sit at the intersection of multiple, often conflicting legal regimes: the GDPR and EU supervisory authority decisions, national implementations that diverge in scope and remedy, sector-specific rules, and adequacy frameworks that can be withdrawn at short notice. A transfer impact assessment that works for a UK-to-EU transfer looks materially different from one covering an EU-to-US transfer under the EU–US Data Privacy Framework, and different again for flows into jurisdictions without an adequacy decision. The data protection legal skills for cross-jurisdiction matters in the ThomasMore catalog are built around that operational reality — mapping transfer mechanisms, drafting standard contractual clauses and addenda, screening processor agreements, and assembling breach notification timelines that account for multiple lead authority deadlines simultaneously.
Each skill is agent-ready, callable over MCP or available as a download, so counsel handling a multinational incident or a global vendor review can run the relevant capability without rebuilding the analysis from scratch. The ThomasMore catalog organises these tools by jurisdiction, license, and author, making it straightforward to stack a country-specific skill alongside a cross-jurisdiction one when a matter demands both layers. Because data protection law changes fast — new guidance from supervisory authorities, revised standard contractual clauses, evolving adequacy decisions — open-source contributions here are maintained with that velocity in mind. Use the jurisdiction filter above to anchor these cross-border data protection legal skills to the specific national regime your next matter actually touches.