Data Protection
Skills
GDPR Data Processing Addendum (DPA)
Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendu…
GDPR Data Processing Addendum (DPA)
Drafts an Article 28-aligned GDPR Data Processing Addendum (DPA) as an attachable annex for SaaS, cloud, or outsourcing agreements. Outputs review-re…
GDPR Data Processing Addendum (DPA)
Drafts a GDPR Article 28-compliant Data Processing Addendum (DPA) between data controllers and processors. Extracts party details, processing scope, …
GDPR Parental Consent Verification
Implements GDPR Article 8 parental consent verification for information society services offered to children. Covers age thresholds by EU/EEA Member …
gdpr-audit-prep
/cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal…
Generate a Compliance Audit Document
Generate a formatted PDF compliance audit document with findings, risk ratings, remediation recommendations, and sign-off sections.
Generating Compliance Reports
Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance repor…
Handling Right to Object to Processing
Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentat…
Handling Right to Restriction Requests
Handles GDPR Article 18 right to restriction of processing requests, covering the four grounds for restriction (accuracy contest, unlawful processing…
Implementing Consent Withdrawal
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving …
Implementing Data Protection Certification
Guides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development,…
Implementing Lawful Basis Assessment
Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consen…
Implementing Right to Erasure Workflow
Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical de…
Implementing Supplementary Measures
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations …
Implementing Transparent Communication
Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, re…
ISO 27701 Privacy Information Management Skill
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/I…
Lawful Basis for AI Training Data
Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing…
Legal Lite Privacy Review
DPA, 개인정보 처리 활동, DSAR, PIA/DPIA, privacy policy 변경을 검토합니다. 사용자가 제공한 정책/문서/처리 설명을 기준으로 개인정보 리스크와 확인 질문, 초안 산출물을 만들 때 사용합니다.
legal-advisor
legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GD…
legal-advisor
legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GD…
Maintaining Breach Documentation Records
Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was …
Managing Automated Decision-Making and Profiling Rights
Manages GDPR Article 22 rights related to solely automated decision-making and profiling, including identification of automated decisions, meaningful…
Managing Breach Credit Monitoring
Coordinates credit monitoring and identity theft protection services for individuals affected by a data breach. Covers vendor selection criteria, enr…
Managing Consent for Analytics Cookies
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behav…
data-protection legal skills for GENERAL
Data protection work that crosses borders sits at the intersection of the GDPR, diverging national implementation laws, sector-specific rules like those governing health or financial data, and a growing body of enforcement decisions from regulators who increasingly coordinate across jurisdictions — making it one of the hardest areas to keep current across every relevant regime. The data protection legal skills collected under the general cross-jurisdiction category in the ThomasMore catalog address that complexity directly, covering consent-framework analysis, data subject rights workflows, breach notification timelines, transfer mechanism assessments, and vendor due diligence across multiple legal orders at once.
Each skill is agent-ready and reachable over MCP or as a download, so a practitioner mapping a multinational client's processing activities or drafting a binding corporate rules summary can run the relevant capability without rebuilding the analysis from scratch. The collection spans both regulatory compliance and contentious matters — responding to a supervisory authority inquiry, supporting a data protection impact assessment, or stress-testing a cross-border transfer against the current standard contractual clauses and any applicable adequacy decision. ThomasMore catalog contributors maintain these skills as enforcement priorities shift and new guidance from national data protection authorities emerges, meaning the tool you run today reflects the regulatory environment as it actually stands. Filter by jurisdiction to layer in the domestic rules that govern your specific matter, or by practice-area tag to narrow the collection to the data protection workflow your client needs next.