data-protection
272 skills across 25 jurisdictions.
Skills
Brazil LGPD Compliance (Lei 13.709/2018)
Guides compliance with Brazil's Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018). Covers the 10 lawful bases under Art. 7, DPO appointment, ANP…
Building a Universal DSAR Intake System
Builds a multi-channel DSAR intake system supporting web form, email, phone, and in-person requests with identity verification tiers, automated routi…
BYOD Policy
Drafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryptio…
California Consumer Privacy Act / California Privacy Rights Act Expert
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CP…
Canada PIPEDA Compliance
Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair informatio…
Canned Responses Skill
Generate templated responses for common legal inquiries and identify when situations require individualized attention. Use when responding to routine…
CCPA/CPRA Compliance
Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Includes consumer rights framework, business obligations, …
CCPA/CPRA Compliance Advisor
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights ful…
CCPA/CPRA Privacy Expert
CCPA and CPRA privacy compliance automation. Audits organizations for California privacy law compliance, maps personal information flows, validates c…
CCPA/CPRA Privacy Policy
Drafts a CCPA/CPRA-compliant privacy policy covering all required statutory disclosures under Cal. Civil Code §§ 1798.100–1798.199. Use when drafting…
CCPA/CPRA Right to Delete
Implements CCPA Section 1798.105 right to delete and CPRA amendments including service provider obligations, statutory exceptions for legal, security…
Children's Data Minimisation and Retention Limits
Implements strict data minimization and retention limits for children's personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and CO…
Children's Profiling Restrictions
Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural a…
China PIPL Compliance
Guides compliance with China's Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border trans…
cite-check — Copilot CLI Skill
Verifiable legal-citation tooling for product counsel reviews. Two modes: (1) ORIGINATE — turn a PPL issue into a Word document of Citation Cards whe…
Cloud Service Provider Privacy Assessment
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, share…
cold-start-interview-10
Run the cold-start interview — learns your privacy practice and writes CLAUDE.md from your policy, DPA template, and a reference PIA. Use on first ru…
Colorado Privacy Act (CPA) Compliance
Colorado Privacy Act (CPA) compliance implementation. Covers universal opt-out mechanism required since July 2024, profiling opt-out rights, sensitiv…
Compliance Checklist Generation
Generate compliance checklists for SOC2, HIPAA, PCI-DSS, and GDPR with gap analysis and remediation priorities.
Compliance Checklist Skill
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a com…
Compliance Policy Auditor
Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance…
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
compliance-evidence
Use when the user needs compliance and privacy evidence.
data-protection legal skills by jurisdiction
Data protection work is defined by the tension between rapidly evolving regulatory requirements and the need for consistent, jurisdiction-specific compliance — a DPA investigation in Germany, a cross-border data transfer impact assessment under the GDPR, and a breach notification to a national authority each demand a different set of steps, timelines, and substantive rules. The data protection legal skills assembled in the ThomasMore catalog address that breadth: drafting privacy notices and data processing agreements, mapping lawful bases for processing, conducting data protection impact assessments, and building incident response workflows across dozens of regulatory regimes. Every skill is agent-ready, meaning an AI agent can execute the underlying task — running over MCP or downloaded as a file — without requiring practitioners to rebuild the logic from scratch for each matter.
Coverage spans frameworks from the GDPR and its national implementation laws through sector-specific and regional regimes, reflecting the reality that a single multinational client may face overlapping obligations across Europe, Asia-Pacific, Latin America, and beyond. Authors maintain these skills as regulators update guidance, adequacy decisions shift, and enforcement priorities change, so the catalog reflects current standards rather than yesterday's rules. The collection is useful across the full spectrum of advisory work — counsel advising data controllers or processors, those handling regulatory investigations, and those advising on international data flows will each find targeted capabilities here. Filter by jurisdiction to bring the right regulatory framework into focus for the matter in front of you.