Data Protection
Skills
Providing Direct Collection Information
Provides GDPR Article 13 information at the point of direct data collection, covering all required elements under Art. 13(1)(a)-(f) and Art. 13(2)(a)…
Providing Indirect Collection Information
Provides GDPR Article 14 information for personal data obtained from sources other than the data subject, covering timing requirements (within reason…
Pseudonymised vs Anonymised Data Classification
Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opi…
Purpose
Compliance review for auditability, GDPR/PII, retention, financial controls, consent, and regulatory traceability.
Recovery App Legal Terms
Generate legally-sound terms of service, privacy policies, and medical disclaimers for recovery and wellness applications. Expert in HIPAA, GDPR, CCP…
reg-gap-analysis-anthropics
Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates. Use w…
Retention Exception Management
Manages retention exception workflows including request-approval processes, duration limits, periodic review cycles, documentation requirements, and …
RoPA Maintenance Workflow
Establishes ongoing RoPA maintenance processes including update triggers, change management integration, version control, stakeholder review cycles, …
RoPA Tool Integration
Integrates Records of Processing Activities with privacy management platforms including OneTrust, TrustArc, Collibra, and DataGrail. Covers API-based…
Search Engine Erasure (Right to Be Forgotten)
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request pr…
Skill: privacy-policy-reviewer
Review a privacy policy or terms of service against a structured scorecard, combining TOSDR's human-curated ratings with LLM analysis. Use when a use…
Slovak to English GDPR Translation
Translates legal articles from Slovak to English with strict terminology mappings for GDPR terms ('prevádzkovateľ' to 'Controller', 'sprostredkovateľ…
Special Category Data Classification — GDPR Art. 9
Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, g…
Sub-Processor Management
GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification proced…
Supervisory Authority Inspection Preparation
Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for …
Terms of Service Analyzer
Analyze terms of service and privacy policies to identify concerning clauses, hidden permissions, and user rights implications
Terms Recon
Survey existing privacy and legal docs for completeness and GDPR compliance.
Universal Escalation Triggers (Apply to All Categories) (+2)
Sub-skill of canned-responses: Universal Escalation Triggers (Apply to All Categories) (+2).
use-case-triage
Quickly determine whether a processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed — surfaces privacy policy conflicts and routes to …
Vendor Privacy Audit
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classificatio…
Vendor Privacy Due Diligence
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, da…
vendor-ai-review-anthropics
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model chang…
개인정보처리방침 생성기
데이터 유형, 관할권, GDPR 및 컴플라이언스 고려사항, 법률 검토가 필요한 조항을 다루는 상세한 개인정보처리방침을 초안 작성합니다. 개인정보처리방침 작성, 데이터 보호 문서 업데이트, 또는 컴플라이언스 준비 시 사용하세요.
data-protection legal skills for GENERAL
Data protection work that crosses borders sits at the intersection of the GDPR, diverging national implementation laws, sector-specific rules like those governing health or financial data, and a growing body of enforcement decisions from regulators who increasingly coordinate across jurisdictions — making it one of the hardest areas to keep current across every relevant regime. The data protection legal skills collected under the general cross-jurisdiction category in the ThomasMore catalog address that complexity directly, covering consent-framework analysis, data subject rights workflows, breach notification timelines, transfer mechanism assessments, and vendor due diligence across multiple legal orders at once.
Each skill is agent-ready and reachable over MCP or as a download, so a practitioner mapping a multinational client's processing activities or drafting a binding corporate rules summary can run the relevant capability without rebuilding the analysis from scratch. The collection spans both regulatory compliance and contentious matters — responding to a supervisory authority inquiry, supporting a data protection impact assessment, or stress-testing a cross-border transfer against the current standard contractual clauses and any applicable adequacy decision. ThomasMore catalog contributors maintain these skills as enforcement priorities shift and new guidance from national data protection authorities emerges, meaning the tool you run today reflects the regulatory environment as it actually stands. Filter by jurisdiction to layer in the domestic rules that govern your specific matter, or by practice-area tag to narrow the collection to the data protection workflow your client needs next.