Jurisdiction: GENERAL
964 skills across 26 practice areas.
Skills
dpa-review
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
Supervisory Authority Inspection Preparation
Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for …
Providing Direct Collection Information
Provides GDPR Article 13 information at the point of direct data collection, covering all required elements under Art. 13(1)(a)-(f) and Art. 13(2)(a)…
Approach
GDPR compliance analysis covering lawful basis assessment, privacy notices, processor agreements, and breach response.
GDPR Data Processing Addendum (DPA)
Drafts a GDPR Article 28-compliant Data Processing Addendum (DPA) between data controllers and processors. Extracts party details, processing scope, …
Critical rules
Ensure data privacy compliance covering GDPR obligations, user consent management, data retention policies, PII detection, and data anonymisation wit…
Executing Data Portability Requests
Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller t…
Data Inventory and Mapping for Classification
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, thir…
customize-11
Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, esca…
Criminal Conviction and Offence Data Handling — GDPR Art. 10
Handles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and com…
Pages: Cookie Policy
When the user wants to create or optimize a cookie policy page. Also use when the user mentions "cookie policy," "cookies," "cookie consent," "GDPR c…
Controller RoPA Creation
Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and cont…
Implementing Consent Withdrawal
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving …
Managing Consent for Transfers
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including ris…
Purpose
Compliance review for auditability, GDPR/PII, retention, financial controls, consent, and regulatory traceability.
Compliance Policy Auditor
Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance…
compliance-evidence
Use when the user needs compliance and privacy evidence.
Compliance Checklist Generation
Generate compliance checklists for SOC2, HIPAA, PCI-DSS, and GDPR with gap analysis and remediation priorities.
Compliance Checklist Skill
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a com…
cold-start-interview-10
Run the cold-start interview — learns your privacy practice and writes CLAUDE.md from your policy, DPA template, and a reference PIA. Use on first ru…
Cloud Service Provider Privacy Assessment
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, share…
cite-check — Copilot CLI Skill
Verifiable legal-citation tooling for product counsel reviews. Two modes: (1) ORIGINATE — turn a PPL issue into a Word document of Citation Cards whe…
Universal Escalation Triggers (Apply to All Categories) (+2)
Sub-skill of canned-responses: Universal Escalation Triggers (Apply to All Categories) (+2).
Managing Data Subject Breach Communication
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in …
Legal agent skills for GENERAL
Some matters resist easy jurisdictional labeling — cross-border contracts that straddle multiple legal systems, international arbitration seated in a neutral forum, or compliance frameworks drawn from supranational rules that apply regardless of where a client is incorporated. The ThomasMore catalog addresses exactly this category through its general jurisdiction hub, which groups legal skills that operate above or across any single national boundary. These agent-ready capabilities cover tasks where the governing law is contested, chosen by the parties, or irrelevant to the drafting work at hand.
A practitioner might use them to build a template NDA designed to travel across legal systems, to structure an arbitration clause referencing institutional rules, or to run a conflict-of-laws analysis before committing to a seat. Each skill runs over MCP or downloads as a standalone file, slotting into your existing workflow without retooling. The collection spans practice areas from dispute resolution and transactional drafting to legal research and document review — all maintained as open-source contributions that evolve with international practice norms. If your matter is anchored to a specific country, the jurisdiction filters above will narrow the ThomasMore catalog to the precise regime your work requires.