Data Protection
Skills
Critical rules
Ensure data privacy compliance covering GDPR obligations, user consent management, data retention policies, PII detection, and data anonymisation wit…
customize-11
Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, esca…
Data Inventory and Mapping for Classification
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, thir…
Data Subject Rights for AI Systems
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model…
Designing Breach Simulation Exercise
Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with real…
Developing Codes of Conduct
Guides development of GDPR Article 40-41 codes of conduct for industry sectors including drafting, submission, and monitoring body requirements. Acti…
DPA Review
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
dpa-review
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
dpa-review-anthropics
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
dpa-review-zhou210712
依据你的数据处理协议(DPA)操作手册审查一份DPA——自动检测你是受托处理者 还是处理者,并应用操作手册正确的半部分。当用户说"审查这份DPA""检查这份 数据处理附录""客户发来了他们的DPA""这份DPA可以吗",或附上一份DPA时使用。
DPIA Risk Scoring Methodology
Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likeli…
Draft Cybersecurity Website Terms and Cookie Policies
Generates Terms of Use and Cookie Policy documents for a cybersecurity company website, strictly limiting data usage to newsletters and event updates…
DSAR Response
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
dsar-response
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
dsar-response-anthropics
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
Employee DSAR Response
Manages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage…
Employee Monitoring DPIA
Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video sur…
Employment Consent Limits
Analyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbala…
ePrivacy Directive Article 5(3) Essential Cookie Exemption
Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria,…
Establishing Binding Corporate Rules
Guides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(…
Executing Data Portability Requests
Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller t…
GDPR Compliance
GDPR compliance - data subject rights, lawful basis, DPIA, privacy by design, breach notification, consent management, cross-border transfers, PII masking
GDPR Compliance Assessment
Conduct a GDPR compliance assessment for a system or processing activity.
GDPR Compliance for Marketing
Ensure GDPR compliance for marketing activities including consent management, data processing, privacy notices, and data subject rights
data-protection legal skills for GENERAL
Data protection work that crosses borders sits at the intersection of the GDPR, diverging national implementation laws, sector-specific rules like those governing health or financial data, and a growing body of enforcement decisions from regulators who increasingly coordinate across jurisdictions — making it one of the hardest areas to keep current across every relevant regime. The data protection legal skills collected under the general cross-jurisdiction category in the ThomasMore catalog address that complexity directly, covering consent-framework analysis, data subject rights workflows, breach notification timelines, transfer mechanism assessments, and vendor due diligence across multiple legal orders at once.
Each skill is agent-ready and reachable over MCP or as a download, so a practitioner mapping a multinational client's processing activities or drafting a binding corporate rules summary can run the relevant capability without rebuilding the analysis from scratch. The collection spans both regulatory compliance and contentious matters — responding to a supervisory authority inquiry, supporting a data protection impact assessment, or stress-testing a cross-border transfer against the current standard contractual clauses and any applicable adequacy decision. ThomasMore catalog contributors maintain these skills as enforcement priorities shift and new guidance from national data protection authorities emerges, meaning the tool you run today reflects the regulatory environment as it actually stands. Filter by jurisdiction to layer in the domestic rules that govern your specific matter, or by practice-area tag to narrow the collection to the data protection workflow your client needs next.