Data Protection
Skills
Managing Consent for Research
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions. Covers ethical review board coordin…
Managing Consent for Transfers
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including ris…
Managing Data Subject Breach Communication
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in …
Managing Joint Controller Arrangements
Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allo…
Managing PIA Review and Update Cadence
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breac…
NIST Privacy Framework — IDENTIFY Function
Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk as…
Pages: Cookie Policy
When the user wants to create or optimize a cookie policy page. Also use when the user mentions "cookie policy," "cookies," "cookie consent," "GDPR c…
Pages: Privacy Policy
When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data pr…
Performing GDPR Controller Self-Assessment
Guides comprehensive controller self-assessment covering GDPR Articles 5-49 with scoring methodology and reporting format. Activate when conducting i…
Performing Legitimate Interest Assessment
Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Act…
Personal Data Classification Test — GDPR Art. 4(1)
Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU…
PIA Generation
Generate a Privacy Impact Assessment in house format for a new feature, product, or processing activity, using the structure learned from your seed PIA.
pia-generation
Generate a Privacy Impact Assessment in house format for a new feature, product, or processing activity, using the structure learned from your seed P…
policy-monitor-anthropics
Keep the privacy policy current with practice. Two modes: weekly sweep of saved PIAs, DPA reviews, and triage results to find policy drift; or direct…
policy-redraft-zekaisuni
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir. Kaynak politika dosyasını d…
Privacy & Terms Generator
Generate jurisdiction-aware Privacy Policies and Terms & Conditions for SaaS products, apps, and digital services. Use this skill whenever the user a…
Privacy Check Skill
Use to assess Privacy by Design compliance and GDPR/data protection alignment for a feature or system.
Privacy Guideline
Privacy and data protection - GDPR, CCPA, consent. Use when handling user data.
Privacy Impact Assessment for Large-Scale Monitoring
Conducts Privacy Impact Assessment for large-scale systematic monitoring under GDPR Article 35(3)(c). Covers CCTV and video surveillance, employee mo…
Privacy Law Gap Analysis for Market Entry
Guides conducting privacy law gap analysis for market entry into new jurisdictions. Covers target jurisdiction assessment, existing compliance mappin…
Privacy Policy Generator
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when cre…
Privacy policy paperclipai
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review
Processing Data Subject Access Requests
Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day dead…
Processing Right to Rectification
Processes GDPR Article 16 right to rectification requests, covering verification of corrected data accuracy, notification to recipients under Article…
data-protection legal skills for GENERAL
Data protection work that crosses borders sits at the intersection of the GDPR, diverging national implementation laws, sector-specific rules like those governing health or financial data, and a growing body of enforcement decisions from regulators who increasingly coordinate across jurisdictions — making it one of the hardest areas to keep current across every relevant regime. The data protection legal skills collected under the general cross-jurisdiction category in the ThomasMore catalog address that complexity directly, covering consent-framework analysis, data subject rights workflows, breach notification timelines, transfer mechanism assessments, and vendor due diligence across multiple legal orders at once.
Each skill is agent-ready and reachable over MCP or as a download, so a practitioner mapping a multinational client's processing activities or drafting a binding corporate rules summary can run the relevant capability without rebuilding the analysis from scratch. The collection spans both regulatory compliance and contentious matters — responding to a supervisory authority inquiry, supporting a data protection impact assessment, or stress-testing a cross-border transfer against the current standard contractual clauses and any applicable adequacy decision. ThomasMore catalog contributors maintain these skills as enforcement priorities shift and new guidance from national data protection authorities emerges, meaning the tool you run today reflects the regulatory environment as it actually stands. Filter by jurisdiction to layer in the domestic rules that govern your specific matter, or by practice-area tag to narrow the collection to the data protection workflow your client needs next.