Marketplace Create skill Sign in

data-protection

272 skills across 25 jurisdictions.

Skills

CROSS-JURISDICTION · data-protection

Age Verification and Estimation Methods

Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, sel…

mukul975
European Union flagEuropean Union · data-protection

AI Automated Decision-Making and Human Oversight

Implements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems. Covers identification of solely aut…

mukul975
European Union flagEuropean Union · data-protection

AI System Pre-Deployment Privacy Checklist

Pre-deployment privacy compliance checklist for AI/ML systems covering DPIA completion, lawful basis verification, transparency notices, human oversi…

mukul975
European Union flagEuropean Union · data-protection

AI Transparency Requirements

Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capabili…

mukul975
Germany flagGermany · data-protection

Anonymisierung und Pseudonymisierung

Anonymisierung und Pseudonymisierung von Mandatsdaten vor KI-Eingabe: Anwendungsfall Anwalt will Mandatsdokument in KI-System eingeben und muss Namen…

Klotzkette
CROSS-JURISDICTION · data-protection

APEC Cross-Border Privacy Rules Certification

Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accounta…

mukul975
GENERAL · data-protection

Applying Privacy Design Patterns

Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrat…

mukul975
Poland flagPoland · data-protection

applying-rodo

Use when drafting or reviewing RODO documents — mapping GDPR articles to obligations, legal basis (art. 6/9), klauzule informacyjne (art. 13–14), umo…

crankshift
GENERAL · data-protection

Appointing EU Representative

Guides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. A…

mukul975
GENERAL · data-protection

Approach

GDPR compliance analysis covering lawful basis assessment, privacy notices, processor agreements, and breach response.

stella
GENERAL · data-protection

Assessing Biometric Processing Privacy

Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special categor…

mukul975
CROSS-JURISDICTION · data-protection

Assessing Health Data Processing

Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial…

mukul975
GENERAL · data-protection

Assessing Legitimate Interest vs Consent

Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, condit…

mukul975
GENERAL · data-protection

Assessing Marketing Analytics Privacy

Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) coo…

mukul975
GENERAL · data-protection

Audit Compliance

Check that your legal compliance is still in good shape. Pick what to check: your privacy policy, your privacy vendor list, or your contract template…

gethouston
Germany flagGermany · data-protection

Auftragsverarbeitungsvertrag prüfen

Auftragsverarbeitungsvertrag nach Art. 28 DSGVO bei KI-Anbietern prüfen: Anwendungsfall Kanzlei schließt Vertrag mit KI-Dienstleister und muss AVV au…

Klotzkette
Australia flagAustralia · data-protection

Australia Privacy Act Compliance (2024 Amendments)

Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's p…

mukul975
Germany flagGermany · data-protection

Automatisierte Entscheidungen Art. 22 DSGVO

Automatisierte Einzelentscheidungen nach Art. 22 DSGVO in Kanzleien prüfen: Anwendungsfall Kanzlei plant KI-gestützte Mandatszuordnung Honorarberechn…

Klotzkette
Germany flagGermany · data-protection

AVV-Grenzprüfung Datenschutz

Kanzlei nutzt KI-Dienstleister und prüft ob AVV nach Art. 28 DSGVO die berufsrechtliche Prüfung ersetzt. Berufsrecht laeuft parallel und ist strenger…

Klotzkette
Germany flagGermany · data-protection

AVV-Review – Auftragsverarbeitungsvertrag Art. 28 DSGVO

Auftragsverarbeitungsvertrag nach Art. 28 DSGVO prüfen oder erstellen wenn Dritter Daten im Auftrag verarbeitet. Art. 28 DSGVO AVV-Pflicht § 62 BDSG.…

Klotzkette
Azerbaijan flagAzerbaijan · data-protection

Azerbaijan + EU Website Privacy Compliance Audit

Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules…

GENERAL · data-protection

Backup Retention and Erasure Management

Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, …

mukul975
Germany flagGermany · data-protection

Betroffenenanfragen – Art. 15–22 DSGVO

DSGVO-Auskunftsantwort an Betroffenen vollständig und rechtskonform gestalten. Art. 15 12 Abs. 3 DSGVO Antwortpflicht. Prüfraster: Antwortinhalt Form…

Klotzkette
GENERAL · data-protection

BosskuAI Legal / Compliance

Use this for product-facing legal and compliance readiness such as privacy posture, consent, retention, vendor/data obligations, policy alignment, an…

wankimmy

data-protection legal skills by jurisdiction

Data protection work is defined by the tension between rapidly evolving regulatory requirements and the need for consistent, jurisdiction-specific compliance — a DPA investigation in Germany, a cross-border data transfer impact assessment under the GDPR, and a breach notification to a national authority each demand a different set of steps, timelines, and substantive rules. The data protection legal skills assembled in the ThomasMore catalog address that breadth: drafting privacy notices and data processing agreements, mapping lawful bases for processing, conducting data protection impact assessments, and building incident response workflows across dozens of regulatory regimes. Every skill is agent-ready, meaning an AI agent can execute the underlying task — running over MCP or downloaded as a file — without requiring practitioners to rebuild the logic from scratch for each matter.

Coverage spans frameworks from the GDPR and its national implementation laws through sector-specific and regional regimes, reflecting the reality that a single multinational client may face overlapping obligations across Europe, Asia-Pacific, Latin America, and beyond. Authors maintain these skills as regulators update guidance, adequacy decisions shift, and enforcement priorities change, so the catalog reflects current standards rather than yesterday's rules. The collection is useful across the full spectrum of advisory work — counsel advising data controllers or processors, those handling regulatory investigations, and those advising on international data flows will each find targeted capabilities here. Filter by jurisdiction to bring the right regulatory framework into focus for the matter in front of you.