Data Protection
Skills
Applying Privacy Design Patterns
Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrat…
Appointing EU Representative
Guides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. A…
Approach
GDPR compliance analysis covering lawful basis assessment, privacy notices, processor agreements, and breach response.
Assessing Biometric Processing Privacy
Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special categor…
Assessing Legitimate Interest vs Consent
Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, condit…
Assessing Marketing Analytics Privacy
Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) coo…
Audit Compliance
Check that your legal compliance is still in good shape. Pick what to check: your privacy policy, your privacy vendor list, or your contract template…
Backup Retention and Erasure Management
Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, …
BosskuAI Legal / Compliance
Use this for product-facing legal and compliance readiness such as privacy posture, consent, retention, vendor/data obligations, policy alignment, an…
Canned Responses Skill
Generate templated responses for common legal inquiries and identify when situations require individualized attention. Use when responding to routine…
cite-check — Copilot CLI Skill
Verifiable legal-citation tooling for product counsel reviews. Two modes: (1) ORIGINATE — turn a PPL issue into a Word document of Citation Cards whe…
Cloud Service Provider Privacy Assessment
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, share…
cold-start-interview-10
Run the cold-start interview — learns your privacy practice and writes CLAUDE.md from your policy, DPA template, and a reference PIA. Use on first ru…
Compliance Checklist Generation
Generate compliance checklists for SOC2, HIPAA, PCI-DSS, and GDPR with gap analysis and remediation priorities.
Compliance Checklist Skill
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a com…
Compliance Policy Auditor
Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance…
compliance-evidence
Use when the user needs compliance and privacy evidence.
Conducting Data Protection Audit
Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Inclu…
Conducting Prior Consultation Process
Guides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirem…
Conducting Transfer Impact Assessment
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country…
Configuring Google Consent Mode v2
Configuring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA…
Controller RoPA Creation
Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and cont…
Creating GDPR Remediation Roadmap
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation. Activate when building com…
Criminal Conviction and Offence Data Handling — GDPR Art. 10
Handles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and com…
data-protection legal skills for GENERAL
Data protection work that crosses borders sits at the intersection of the GDPR, diverging national implementation laws, sector-specific rules like those governing health or financial data, and a growing body of enforcement decisions from regulators who increasingly coordinate across jurisdictions — making it one of the hardest areas to keep current across every relevant regime. The data protection legal skills collected under the general cross-jurisdiction category in the ThomasMore catalog address that complexity directly, covering consent-framework analysis, data subject rights workflows, breach notification timelines, transfer mechanism assessments, and vendor due diligence across multiple legal orders at once.
Each skill is agent-ready and reachable over MCP or as a download, so a practitioner mapping a multinational client's processing activities or drafting a binding corporate rules summary can run the relevant capability without rebuilding the analysis from scratch. The collection spans both regulatory compliance and contentious matters — responding to a supervisory authority inquiry, supporting a data protection impact assessment, or stress-testing a cross-border transfer against the current standard contractual clauses and any applicable adequacy decision. ThomasMore catalog contributors maintain these skills as enforcement priorities shift and new guidance from national data protection authorities emerges, meaning the tool you run today reflects the regulatory environment as it actually stands. Filter by jurisdiction to layer in the domestic rules that govern your specific matter, or by practice-area tag to narrow the collection to the data protection workflow your client needs next.