Compliance Policy Auditor
Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance gaps or risk levels in technical procedures.
Compliance Policy Auditor
Systematically reviews technical or procedural documentation to identify alignment or deviations from major regulatory frameworks.
🎯 When to Use
- User provides a "Privacy Policy" or "Data Retention Plan" for review.
- User asks: "Is this process SOC2 compliant?" or "What GDPR risks exist here?"
- Do NOT use for providing binding legal advice or drafting contracts.
- Do NOT use for auditing physical security (cams, locks) unless documented.
🧠 Core Workflow
Step 1 — Scope & Framework Selection IF user specifies a framework (GDPR/SOC2/HIPAA/ISO27001), prioritize its rules; ELSE, apply General Data Protection principles.
Step 2 — Data Mapping Identify PII (Personally Identifiable Information), PHI (Protected Health Information), or PCI data mentioned in the text.
Step 3 — Gap Analysis
- Data Minimization — Check if only necessary data is collected.
- Access Control — Audit description of "Who has access" (RBAC).
- Security Measures — Identify encryption, hashing, and log requirements.
Step 4 — Risk Scoring Assign Severity (Critical/Major/Minor) to gaps based on regulatory fine potential.
Step 5 — Return Output Provide a structured JSON audit report.
📋 Output Format
{
"frameworks_evaluated": ["GDPR", "SOC2"],
"pii_detected": ["email", "IP address"],
"findings": [
{
"severity": "critical",
"category": "Data Retention",
"issue": "Policy states data is kept indefinitely.",
"remediation": "Define a 7-year purge cycle per Article 5(1)(e)."
}
],
"risk_summary": "1 Critical Gap detected. High risk of non-compliance."
}
⚠️ Fallback Behavior
IF the input text is too vague to audit:
ASK for specific details regarding data storage, user consent, or encryption
No additional documents ship with this skill.
Related Skills
Data Subject Rights for AI Systems
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model…
Lawful Basis for AI Training Data
Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing…
Managing Consent for Analytics Cookies
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behav…
Applying Privacy Design Patterns
Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrat…
User Input
[COMMUNITY] Assess EU Data Act (Regulation 2023/2854) compliance for connected products, data holders, and data processing service providers