data-protection
272 skills across 25 jurisdictions.
Skills
Managing Conflicting Privacy Requirements
Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age…
Managing Consent for Analytics Cookies
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behav…
Managing Consent for Children
Guide for managing consent for children's personal data under GDPR Article 8 and COPPA. Covers parental consent mechanisms, age verification methods,…
Managing Consent for Research
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions. Covers ethical review board coordin…
Managing Consent for Transfers
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including ris…
Managing Data Subject Breach Communication
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in …
Managing Joint Controller Arrangements
Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allo…
Managing Multi-Jurisdiction Breach Notification
Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notif…
Managing PIA Review and Update Cadence
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breac…
mandanten-kommunikations-log
Mandantenkommunikation dokumentieren und Kommunikations-Log führen: Anwendungsfall Rechtsberatungsstelle muss Beratungsgespraeache E-Mails und Entsch…
Mandantendaten und KI-Dienstleister (§ 203 StGB, Art. 28 DSGVO)
Datenschutzkonforme Verwendung von Mandantendaten beim Einsatz von KI-Tools in der Kanzlei prüfen. Art. 5 6 DSGVO BRAO § 43a Verschwiegenheit. Prüfra…
Mandat-Arbeitsbereich – Mehrmandat-Kanzlei
Datenschutzrechtliches Mandat strukturieren und Arbeitsbereich abgrenzen. Art. 5 24 DSGVO §§ 1 ff. BDSG. Prüfraster: Mandatsumfang Zuständigkeiten Fr…
Mandat-Triage IT-Recht
Strukturierte Eingangs-Abfrage für IT-rechtliche Mandate mit Fristen-Sofort-Check. Anwendungsfall neues IT-Rechtsmandat geht ein und muss schnell tri…
matter-workspace-23
Privacy/KVKK matter workspace'lerini yönetir: yeni dosya açma, listeleme, aktif dosya değiştirme, arşivleme veya practice-level çalışmaya dönme. Çok …
Montana Consumer Data Privacy Act (MTDPA)
Montana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out…
New Jersey Data Privacy Act (NJDPA)
New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-ou…
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) 2023 compliance. Covers lawful basis for processing, data subject ri…
NIST Privacy Framework — IDENTIFY Function
Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk as…
Oregon Consumer Privacy Act (OCPA)
Oregon Consumer Privacy Act (OCPA) compliance. Unique provisions for de-identified data requirements, employee data partial exemption, nonprofit appl…
Pages: Cookie Policy
When the user wants to create or optimize a cookie policy page. Also use when the user mentions "cookie policy," "cookies," "cookie consent," "GDPR c…
Pages: Privacy Policy
When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data pr…
Performing GDPR Controller Self-Assessment
Guides comprehensive controller self-assessment covering GDPR Articles 5-49 with scoring methodology and reporting format. Activate when conducting i…
Performing Legitimate Interest Assessment
Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Act…
Personal Data Classification Test — GDPR Art. 4(1)
Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU…
data-protection legal skills by jurisdiction
Data protection work is defined by the tension between rapidly evolving regulatory requirements and the need for consistent, jurisdiction-specific compliance — a DPA investigation in Germany, a cross-border data transfer impact assessment under the GDPR, and a breach notification to a national authority each demand a different set of steps, timelines, and substantive rules. The data protection legal skills assembled in the ThomasMore catalog address that breadth: drafting privacy notices and data processing agreements, mapping lawful bases for processing, conducting data protection impact assessments, and building incident response workflows across dozens of regulatory regimes. Every skill is agent-ready, meaning an AI agent can execute the underlying task — running over MCP or downloaded as a file — without requiring practitioners to rebuild the logic from scratch for each matter.
Coverage spans frameworks from the GDPR and its national implementation laws through sector-specific and regional regimes, reflecting the reality that a single multinational client may face overlapping obligations across Europe, Asia-Pacific, Latin America, and beyond. Authors maintain these skills as regulators update guidance, adequacy decisions shift, and enforcement priorities change, so the catalog reflects current standards rather than yesterday's rules. The collection is useful across the full spectrum of advisory work — counsel advising data controllers or processors, those handling regulatory investigations, and those advising on international data flows will each find targeted capabilities here. Filter by jurisdiction to bring the right regulatory framework into focus for the matter in front of you.