data-protection
296 skills across 24 jurisdictions.
Australia
2
User Input
[COMMUNITY] Generate a Privacy Impact Assessment (PIA) for Australian Government entities under Privacy Act 1988 s33D, assessing compliance with all …
Australia Privacy Act Compliance (2024 Amendments)
Guides compliance with Australia's Privacy Act 1988 including the 2024 reform amendments. Covers automated decision-making transparency, children's p…
Austria
2
User Input
[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Au…
Transparenz Check — Oesterreichisches Recht
Prueft Impressum, Datenschutzerklaerung und Vereinsangaben auf oesterreichische Rechtskonformitaet (ECG § 5, DSGVO Art. 13/14, VerG)
Azerbaijan
1
Azerbaijan + EU Website Privacy Compliance Audit
Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules…
Brazil
4
Brazil LGPD Compliance (Lei 13.709/2018)
Guides compliance with Brazil's Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018). Covers the 10 lawful bases under Art. 7, DPO appointment, ANP…
legal-compliance-check — Verificação de Conformidade
Executar uma verificação de conformidade em uma ação proposta, funcionalidade de produto ou iniciativa de negócio, identificando regulamentações apli…
legal-response — Gerar Resposta a partir de Templates
Gerar uma resposta a uma consulta jurídica comum usando templates configurados, com verificações de escalação para situações que não devem usar respo…
LGPD Compliance Skill
Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazili…
Canada
1
Canada PIPEDA Compliance
Guides compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Covers the 10 fair informatio…
China
1
China PIPL Compliance
Guides compliance with China's Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border trans…
European Union
6
AI Automated Decision-Making and Human Oversight
Implements GDPR Art. 22 automated decision-making and AI Act Art. 14 human oversight requirements for AI systems. Covers identification of solely aut…
AI System Pre-Deployment Privacy Checklist
Pre-deployment privacy compliance checklist for AI/ML systems covering DPIA completion, lawful basis verification, transparency notices, human oversi…
AI Transparency Requirements
Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capabili…
GDPR Skill
Use when the user asks about GDPR — lawful bases for processing, data subject rights (DSRs), Records of Processing Activities (ROPA, Article 30), Dat…
GDPR Compliance Skill
Ensure GDPR compliance for personal data processing in CIA platform with privacy-by-design principles
GDPR Expert
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data…
France
5
User Input
[COMMUNITY] Assess compliance with ANSSI security recommendations — Guide d'hygiène informatique (42 measures) and cloud security recommendations
User Input
[COMMUNITY] Conduct an EBIOS Risk Manager risk analysis study following the ANSSI methodology — five workshops from study framing to risk treatment a…
User Input
[COMMUNITY] Generate an Information System Security Policy (PSSI) for French public or private organisations — security objectives, principles, organ…
User Input
[COMMUNITY] Assess CNIL-specific GDPR obligations for French deployments — cookies, health data (HDS), minors, délibérations CNIL, and French enforce…
Implementing CNIL-Compliant Cookies
Implementation guide for CNIL cookie guidelines compliance. References the EUR 150M Google fine and EUR 60M Meta fine. Covers equal prominence accept…
Germany
45
Anonymisierung und Pseudonymisierung
Anonymisierung und Pseudonymisierung von Mandatsdaten vor KI-Eingabe: Anwendungsfall Anwalt will Mandatsdokument in KI-System eingeben und muss Namen…
Datenschutz-Triage neuer Verarbeitungsvorgänge
Datenschutzrechtlichen Sachverhalt einordnen und Bearbeitungsroute bestimmen. Art. 2 3 DSGVO Anwendungsbereich § 1 BDSG. Prüfraster: Anwendungsbereic…
Auftragsverarbeitungsvertrag prüfen
Auftragsverarbeitungsvertrag nach Art. 28 DSGVO bei KI-Anbietern prüfen: Anwendungsfall Kanzlei schließt Vertrag mit KI-Dienstleister und muss AVV au…
Automatisierte Entscheidungen Art. 22 DSGVO
Automatisierte Einzelentscheidungen nach Art. 22 DSGVO in Kanzleien prüfen: Anwendungsfall Kanzlei plant KI-gestützte Mandatszuordnung Honorarberechn…
AVV-Grenzprüfung Datenschutz
Kanzlei nutzt KI-Dienstleister und prüft ob AVV nach Art. 28 DSGVO die berufsrechtliche Prüfung ersetzt. Berufsrecht laeuft parallel und ist strenger…
AVV-Review – Auftragsverarbeitungsvertrag Art. 28 DSGVO
Auftragsverarbeitungsvertrag nach Art. 28 DSGVO prüfen oder erstellen wenn Dritter Daten im Auftrag verarbeitet. Art. 28 DSGVO AVV-Pflicht § 62 BDSG.…
Consent Audit — Einwilligungspruefung
Prueft Einwilligungs-Flows auf DSGVO-Konformitaet: DOI-Token-Ablauf, Widerruf-Workflow, Cookie-Banner
Cyber-Incident-Response 72 Stunden
Sofortmassnahmen bei aktivem Cyber-Vorfall Ransomware Datenexfiltration oder Insider-Threat. Anwendungsfall Cyberangriff ist entdeckt und IT-rechtlic…
Datenpannen-Meldung (Art. 33/34 DSGVO)
Datenpanne nach Art. 33 34 DSGVO melden wenn Sicherheitsverletzung personenbezogener Daten vorliegt. Art. 33 34 DSGVO Meldepflichten § 65 BDSG. Prüfr…
Customize – Praxisprofil anpassen
Bestehende Datenschutzdokumentation oder Richtlinien an neue Anforderungen oder Verarbeitungstätigkeiten anpassen. Art. 5 24 DSGVO Rechenschaftspflic…
Mandat-Arbeitsbereich – Mehrmandat-Kanzlei
Datenschutzrechtliches Mandat strukturieren und Arbeitsbereich abgrenzen. Art. 5 24 DSGVO §§ 1 ff. BDSG. Prüfraster: Mandatsumfang Zuständigkeiten Fr…
Dienstleister Due Diligence
KI-Dienstleister Due Diligence für Kanzleien durchführen: Anwendungsfall Kanzlei moechte neuen KI-Dienst beauftragen und muss eigenverantwortlich Dat…
Dokumentationspflichten Protokoll
Dokumentationspflichten und beweissichere Protokollierung von KI-Nutzung in Kanzleien: Anwendungsfall Kanzlei muss KI-Inputs und KI-Outputs nachvollz…
Drittlandstransfer-Prüfung (Art. 44 ff. DSGVO)
Datentransfer in Drittlaender außerhalb EU und EWR auf Zulässigkeit prüfen. Art. 44 ff. DSGVO Kapitel V Drittlandstransfer. Prüfraster: Angemessenhei…
DSB-Bestellungspflicht und -Anforderungen
Bestellungspflicht für Datenschutzbeauftragten prüfen. Art. 37 DSGVO § 38 BDSG Bestellungspflicht. Prüfraster: Schwellenwerte Art. 37 Abs. 1 Betriebs…
DSFA – Datenschutz-Folgenabschätzung Art. 35 DSGVO
Datenschutz-Folgenabschaetzung nach Art. 35 DSGVO durchführen wenn hohes Risiko für Betroffene vorliegt. Art. 35 36 DSGVO DSFA § 67 BDSG. Prüfraster:…
DSGVO-Auskunftsrecht (Art. 15 DSGVO)
Auskunftsersuchen nach Art. 15 DSGVO prüfen und beantworten wenn Betroffener Auskunft verlangt. Art. 15 12 DSGVO Betroffenenrechte. Prüfraster: Ident…
Betroffenenanfragen – Art. 15–22 DSGVO
DSGVO-Auskunftsantwort an Betroffenen vollständig und rechtskonform gestalten. Art. 15 12 Abs. 3 DSGVO Antwortpflicht. Prüfraster: Antwortinhalt Form…
DSGVO-Compliance-Bausteine
DSGVO-Textbausteine für KI-Nutzungsrichtlinien in Kanzleien: Anwendungsfall Kanzlei erstellt oder aktualisiert KI-Richtlinie und benoetigt prazise da…
DSGVO-rechtswidriges Produkt
Produkt aus dem Ausland auf DSGVO-Rechtswidrigkeit prüfen: Richter oder Anwalt muss beurteilen ob Smartglasses oder IoT-Produkt DSGVO-konform ist. No…
ecc-claude-ra-qm-team-gdpr-dsgvo-expert
OpenClaw bridge skill for ra qm team gdpr dsgvo expert. Use when tasks match this specialized claude-skills capability and need OpenClaw-native execu…
Einwilligung-Hinweis-Datenschutz
Kanzlei bietet telefonischen Transkriptionsservice an und muss DSGVO-konforme Einwilligung einholen. Art. 6 Abs. 1 lit. a DSGVO Art. 13 DSGVO Informa…
Erforderlichkeit dokumentieren
Prüfe die Erforderlichkeit der Offenlegung von Berufsgeheimnissen gegenüber dem KI-Dienstleister nach Absatz eins der einschlaegigen Dienstleisterreg…
SCHUFA-Eintrag
Workflow-Skill zu fachanwalt bank kapitalmarktrecht schufa eintrag. Nutzt Normtext, Nutzerangaben und verifizierte Quellen; Rechtsprechung nur nach L…
Datenschutz-Folgenabschätzung
Datenschutz-Folgenabschaetzung DSFA nach Art. 35 DSGVO bei voraussichtlich hohem Risiko. Anwendungsfall neues Verarbeitungsverfahren mit hohem Risiko…
Fachanwalt für Informationstechnologierecht — Orientierung
Orientierung im IT-Recht für Mandate und Fachanwaltschaft nach FAO. Anwendungsfall Kanzlei will IT-Mandat beurteilen oder Anwalt bereitet sich auf Fa…
GDPR/DSGVO Expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Us…
Senior GDPR/DSGVO Expert and Auditor
Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact as…
GeschGehG-Bausteine
GeschGehG-Bausteine für KI-Nutzungsrichtlinien in Kanzleien: Anwendungsfall Kanzlei muss beim KI-Einsatz Geschäftsgeheimnisse von Mandanten und eigen…
Forprüfungs-Gutachten erstellen
Erstelle das zusammenfassende Forprüfungs-Gutachten zum KI-Anbietervertrag. Aufbau Eingangsdaten Norm-Adapter Prüfpunkte Erforderlichkeit Verschwiege…
Internationale Buyout-Datenflows und Datenschutz
Datenfluesse bei internationalem bAV-Buyout datenschutzrechtlich absichern: DSGVO, Drittlandtransfers. Normen: DSGVO Art. 44 ff., BDSG. Prüfraster: D…
Gemeinsame Verantwortlichkeit Art. 26 DSGVO
Joint-Controller-Vereinbarung nach Art. 26 DSGVO erstellen wenn zwei oder mehr Verantwortliche gemeinsam entscheiden. Art. 26 DSGVO Gemeinsame Verant…
ki-folgenabschaetzung
KI-Folgenabschätzung (FRIA nach Art. 27 KI-VO + DSFA nach Art. 35 DSGVO) erstellen – strukturierte Aufnahme, Risikoanalyse, Regulierungsklassifizieru…
KI-Verordnung — Compliance-Prüfung
KI-Systeme auf Anforderungen der KI-VO und Datenschutz prüfen. KI-VO Risikoklassen Art. 5 9 DSGVO Einwilligung. Prüfraster: Risikoklasse Verbote Hoch…
mandanten-kommunikations-log
Mandantenkommunikation dokumentieren und Kommunikations-Log führen: Anwendungsfall Rechtsberatungsstelle muss Beratungsgespraeache E-Mails und Entsch…
Mandantendaten und KI-Dienstleister (§ 203 StGB, Art. 28 DSGVO)
Datenschutzkonforme Verwendung von Mandantendaten beim Einsatz von KI-Tools in der Kanzlei prüfen. Art. 5 6 DSGVO BRAO § 43a Verschwiegenheit. Prüfra…
Mandat-Triage IT-Recht
Strukturierte Eingangs-Abfrage für IT-rechtliche Mandate mit Fristen-Sofort-Check. Anwendungsfall neues IT-Rechtsmandat geht ein und muss schnell tri…
Privacy Policy and GDPR Transparency
Draft, review, or debug EU privacy policies and GDPR transparency notices for SaaS products. Use when mapping lawful basis by processing purpose, doc…
DS-Gap-Analyse – Datenschutzrecht
Regulatorische Luecken im Datenschutzrecht identifizieren und Handlungsoptionen aufzeigen. Art. 5 6 24 DSGVO BDSG. Prüfraster: Bestandsaufnahme beste…
Policy-Monitor – Drift-Monitoring Datenschutzerklärung
Datenschutzrichtlinien und Unternehmensanweisungen auf Aktualitaet und Konformität monitoren. Art. 24 32 DSGVO TOMs §§ 4 ff. BDSG. Prüfraster: Richtl…
Rückfragebrief an Anbieter
Erstelle einen strukturierten Rückfragebrief an den KI-Anbieter zur Klaerung der berufsrechtlichen und strafrechtlichen Pflichten. Aufbau Anschreiben…
TOM und Zertifizierungen prüfen
Prüfe technische und organisatorische Massnahmen des KI-Anbieters und seine Zertifizierungen. Maßstab Art. 32 DS-GVO ISO 27001 BSI C5 (Cloud Computin…
Transkriptionsdienst-Erklärung
Mandant kann seinen Fall nicht schriftlich schildern und soll stattdessen anrufen. Transkriptionsservice Erklärung in Erstantwort. Prüfraster: Telefo…
Transparenz gegenüber Mandanten
Transparenz gegenüber Mandanten bei KI-Einsatz in Kanzleien sicherstellen: Anwendungsfall Kanzlei muss Mandaten informieren dass KI-Systeme bei Manda…
VVT — Verzeichnis von Verarbeitungstätigkeiten
Verzeichnis der Verarbeitungstätigkeiten nach Art. 30 DSGVO erstellen oder aktualisieren. Art. 30 DSGVO VVT-Pflicht. Prüfraster: Pflichtangaben Art. …
India
2
India DPDPA — Digital Personal Data Protection Act, 2023 Skill
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DP…
India DPDPA Expert
India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal right…
Japan
2
Japan APPI Compliance (2022 Amendments)
Guides compliance with Japan's Act on the Protection of Personal Information (APPI, 2022 amendments). Covers individual rights expansion, cross-borde…
Japan APPI Expert
Japan APPI expert for the Act on the Protection of Personal Information. Reference-depth framework plugin with scope determination, evidence checklis…
Nigeria
1
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) 2023 compliance. Covers lawful basis for processing, data subject ri…
Singapore
1
Singapore - Personal Data Protection Ac (PDPA) (2012) Expert
Singapore - Personal Data Protection Ac (PDPA) (2012) expert. Reference-depth framework plugin with assessment, scope determination, and evidence che…
South Africa
1
South Africa POPIA Compliance
Implements compliance with South Africa's Protection of Personal Information Act (POPIA), Act No. 4 of 2013. Covers conditions for lawful processing,…
South Korea
2
South Korea PIPA Compliance
Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requiremen…
Korean Privacy & Terms (thin wrapper)
kimlawtech/korean-privacy-terms (Apache-2.0) 업스트림을 경유해 Next.js 프로젝트에 한국 법령(개인정보보호법·약관규제법·전자상거래법) 기반 개인정보처리방침·이용약관·쿠키 배너·동의 모달을 생성하는 thin wrapper 스킬.
Spain
3
eipd
Generador de Evaluación de Impacto en Protección de Datos (EIPD) — genera una EIPD en el formato house configurado. Evalúa si es obligatoria según ar…
gap
Gap regulatorio de privacidad — compara un cambio normativo o una guía nueva de la AEPD/CEPD contra la política de privacidad y los procedimientos ac…
rat
Crea o actualiza el Registro de Actividades de Tratamiento (RAT) conforme al art. 30 del RGPD, en el formato recomendado por la AEPD. Genera una fich…
Switzerland
1
Swiss FADP Expert
Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notific…
Türkiye
4
dpa-review-zekaisuni
Veri işleme sözleşmesi, veri işleyen sözleşmesi, DPA veya kişisel veri aktarımı içeren tedarikçi/müşteri ekini Türk KVKK uygulamasına göre inceler. V…
KVKK Denetim Aracı
Türkiye Kişisel Verilerin Korunması Kanunu (KVKK / 6698 sayılı Kanun) uyum denetimi. Gizlilik politikası, aydınlatma metni, açık rıza formu oluşturma…
matter-workspace-23
Privacy/KVKK matter workspace'lerini yönetir: yeni dosya açma, listeleme, aktif dosya değiştirme, arşivleme veya practice-level çalışmaya dönme. Çok …
Turkey KVKK Compliance
Implements compliance with Turkey's Personal Data Protection Law (Kisisel Verilerin Korunmasi Kanunu, KVKK, Law No. 6698). Covers data controller obl…
United Arab Emirates
3
User Request
[COMMUNITY] Generate a Data Sharing Agreement under the UAE Government Services Data Sharing Policy. Captures collect-once mapping, federation/API pl…
User Request
[COMMUNITY] Generate a UAE PDPL (Federal Decree-Law 45/2021) compliance assessment including DPIA, lawful-basis register, data-subject-rights procedu…
UAE Personal Data Protection Law Compliance
Implements compliance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDP Law) and its Executive Regulations. …
United Kingdom
2
Building a Universal DSAR Intake System
Builds a multi-channel DSAR intake system supporting web form, email, phone, and in-person requests with identity verification tiers, automated routi…
GDPR Privacy Policy & Compliance Document Generator
Generate UK/EU GDPR compliance documents — privacy policies, cookie policies, DPIAs, ROPA, DSAR responses, data breach notifications, and consent for…
United States
29
Data Breach Notification Letter
Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG require…
BYOD Policy
Drafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryptio…
CCPA/CPRA Compliance Advisor
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights ful…
CCPA/CPRA Compliance
Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Includes consumer rights framework, business obligations, …
CCPA/CPRA Privacy Expert
CCPA and CPRA privacy compliance automation. Audits organizations for California privacy law compliance, maps personal information flows, validates c…
CCPA/CPRA Privacy Policy
Drafts a CCPA/CPRA-compliant privacy policy covering all required statutory disclosures under Cal. Civil Code §§ 1798.100–1798.199. Use when drafting…
CCPA/CPRA Right to Delete
Implements CCPA Section 1798.105 right to delete and CPRA amendments including service provider obligations, statutory exceptions for legal, security…
Colorado Privacy Act (CPA) Compliance
Colorado Privacy Act (CPA) compliance implementation. Covers universal opt-out mechanism required since July 2024, profiling opt-out rights, sensitiv…
Consumer Breach Notification Letter
Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal informati…
COPPA Compliance — Children's Online Privacy Protection Act
Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including si…
Consumer Data Breach Notification Letter
Drafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produ…
Data Retention and Destruction Policy
Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protoco…
Implementing Global Privacy Control (GPC)
Implementation guide for Global Privacy Control (GPC) automated opt-out signal per CPRA Section 1798.135(e). Covers Sec-GPC HTTP header detection, Ja…
Incident Response Plan and Playbook
Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, …
Incident Response Plan and Playbook
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.…
Iowa Consumer Data Protection Act (ICDPA)
Iowa Consumer Data Protection Act (ICDPA) compliance. Effective January 1, 2025. Covers consumer rights (access, delete, opt-out), controller thresho…
Kentucky Consumer Privacy Protection Act (KPPA)
Kentucky Consumer Privacy Protection Act (KPPA) compliance. Effective January 1, 2026. Covers consumer rights, controller thresholds at 100,000 consu…
Montana Consumer Data Privacy Act (MTDPA)
Montana Consumer Data Privacy Act (MTDPA) compliance. Lowest consumer threshold at 50,000 consumers. Covers sensitive data consent, universal opt-out…
New Jersey Data Privacy Act (NJDPA)
New Jersey Data Privacy Act (NJDPA) compliance, effective January 15, 2025. Covers consumer rights (access, correction, deletion, portability, opt-ou…
NYDFS Expert
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including al…
Oregon Consumer Privacy Act (OCPA)
Oregon Consumer Privacy Act (OCPA) compliance. Unique provisions for de-identified data requirements, employee data partial exemption, nonprofit appl…
SOC 2 Type II Privacy Trust Services Criteria
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including n…
State Privacy Law Applicability Assessment
US state privacy law applicability assessment tool. Evaluates revenue thresholds, data volume thresholds, business exemptions (GLBA, HIPAA, nonprofit…
Texas Data Privacy and Security Act (TDPSA)
Texas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses. Covers data broker registration requirements,…
Universal Opt-Out Mechanism Implementation
Universal opt-out mechanism implementation across US state privacy laws. Covers Global Privacy Control (GPC) signal technical implementation, state-b…
California Consumer Privacy Act / California Privacy Rights Act Expert
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CP…
US Federal Privacy Landscape
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed fede…
Virginia Consumer Data Protection Act (VCDPA)
Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, op…
Written Information Security Program (WISP)
Drafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-D…
Vietnam
1
Tuân thủ & Pháp lý (Legal & Compliance Checklists)
Kích hoạt khi người dùng muốn: Kiểm tra tính tuân thủ pháp lý của website/ứng dụng, soạn thảo Điều khoản dịch vụ (TOS), Chính sách bảo mật (Privacy P…
CROSS-JURISDICTION 50
Age Verification and Estimation Methods
Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, sel…
Conducting AI System Privacy Assessment
Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training da…
Managing APAC Cross-Border Transfers
Guides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan…
APEC Cross-Border Privacy Rules Certification
Guides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accounta…
User Input
[COMMUNITY] Assess NIS2 Directive compliance obligations for EU member state operators of essential services and important entities
User Input
[COMMUNITY] Generate GDPR (EU 2016/679) compliance assessment for EU/EEA data processing — legal basis mapping, data subject rights, transfers, DPIA …
Managing Multi-Jurisdiction Breach Notification
Manages coordinated breach notification across multiple legal jurisdictions including EU member states (72-hour GDPR deadline), US state breach notif…
Children's Data Minimisation and Retention Limits
Implements strict data minimization and retention limits for children's personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and CO…
Children's Profiling Restrictions
Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural a…
Clause
Legal document review for Terms of Service, Privacy Policy, and Tokushoho compliance. Clause gap detection, risk flagging, and regulatory alignment. …
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
Verificación de cumplimiento normativo
Usar para verificar cumplimiento RGPD, NIS2 y CRA. También: verificar RGPD, cumplimiento normativo, NIS2, CRA, Cyber Resilience Act, protección de da…
Workflow
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
Maestro Compliance Check
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
Compliance Check
Regulatory and legal compliance audit. Discovers which frameworks apply based on jurisdiction, industry, and data types, then checks the codebase aga…
Compliance Skill
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding t…
Managing Conflicting Privacy Requirements
Guides managing conflicting privacy requirements across jurisdictions. Covers data localisation vs transfer freedom, consent standards variation, age…
Evaluating Consent Management Platforms
Framework for evaluating and selecting Consent Management Platforms (CMPs). Covers TCF v2.2 certification requirements, Global Privacy Control suppor…
Cookie Consent Banner and Policy
Drafts publication-ready cookie policies, banner copy, and consent-flow language under GDPR/ePrivacy, CCPA/CPRA, and major U.S. state privacy laws. C…
Cyber Law Compliance Summary
Produces structured cyber law compliance memoranda covering GDPR, CCPA, state privacy laws, and sector-specific regulations for US and EU operations.…
data-privacy-agreement
Draft and fill data privacy agreement templates — DPA, data processing agreement, GDPR, HIPAA BAA, business associate agreement, AI addendum. Produce…
Digital Media Law Summary
Generates Bluebook-cited summaries of digital media law across copyright/IP, privacy/data protection, and content liability pillars. Trigger when tra…
DPA Checklist Review
Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains …
DPA Checklist Review
Use when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains …
DSAR Form
Drafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. …
GDPR/DSGVO Expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Us…
Gdpr Privacy
Use when implementing GDPR compliance, handling data subject requests, conducting DPIAs, managing consent, or responding to data breaches - covers al…
Assessing Health Data Processing
Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial…
Implementing GDPR Data Subject Access Request (DSAR) Workflow
Automates GDPR Data Subject Access Request (DSAR) workflows including identity verification, PII discovery across databases and files using regex and…
KVKK & GDPR Compliance Patterns
KVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification.
Legal Document Generation & Compliance
Legal document generation and compliance guidance for indie Apple developers. Covers privacy policies, terms of service, EULAs, GDPR/CCPA/DPDP compli…
Use this skill when
Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreemen…
Use this skill when
Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements.
Regulatory Compliance Assessment Report
Ensure business operations comply with GDPR, CCPA, HIPAA, SOX, PCI-DSS and other regulations across multiple jurisdictions. Adapted from msitarzewski…
Legal Compliance Agent
Generate legally compliant privacy policies, terms of service, HIPAA documentation, and compliance pages for healthcare SaaS platforms. Ensures Googl…
Managing Consent for Children
Guide for managing consent for children's personal data under GDPR Article 8 and COPPA. Covers parental consent mechanisms, age verification methods,…
Privacy Impact Assessment for Health Data
Conducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations. Covers spe…
Key principles
Use this skill when implementing GDPR or CCPA compliance, designing consent management, conducting DPIAs, or managing data processing agreements. Tri…
Privacy Policy Generator
Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-par…
Privacy Law Change Monitoring and Impact Assessment
Guides privacy law change monitoring and impact assessment for multi-jurisdiction organisations. Covers regulatory tracking sources, change classific…
Privacy Law Updates
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance …
Privacy Policy & Legal Document Generator
Generate privacy policies, terms of service, and EULAs for Apple platform apps. Detects data collection patterns, third-party SDKs, and generates reg…
Privacy Policy Drafting
Generate GDPR and CCPA-compliant privacy policies tailored to specific business models and data collection practices.
Privacy Policy Generator
Gizlilik politikası şablonu, çerez politikası, veri işleme açıklamaları ve hak sahipleri.
Privacy Policy
When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.
regdata-kyc-aml
Extract beneficial ownership data from Poland's CRBR registry, financial license status from KNF, non-anonymized board members from KRS, company prof…
Regulatory Compliance Skill
Validate systems and processes against GDPR/CCPA privacy regulations, privacy-by-design principles, ADA/WCAG accessibility standards, data processing…
SafeAI ASEAN Data Protection — System Instructions
ASEAN data protection compliance engine — VN, SG, TH, MY, ID, PH regulatory frameworks. (v5.0.0)
Terms of Service Generator
Generates comprehensive terms of service by analyzing a website or application to detect business type, data collection, and user interactions. Use w…
Workplace Email Privacy
Implements email and internet monitoring compliance in the workplace per Barbulescu v Romania (ECHR Grand Chamber), EDPB guidance, and national labou…
GENERAL 127
Data Subject Rights for AI Systems
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model…
Lawful Basis for AI Training Data
Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing…
Managing Consent for Analytics Cookies
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behav…
Applying Privacy Design Patterns
Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrat…
User Input
[COMMUNITY] Assess EU Data Act (Regulation 2023/2854) compliance for connected products, data holders, and data processing service providers
GDPR Compliance Assessment
Conduct a GDPR compliance assessment for a system or processing activity.
Audit Compliance
Check that your legal compliance is still in good shape. Pick what to check: your privacy policy, your privacy vendor list, or your contract template…
Managing Automated Decision-Making and Profiling Rights
Manages GDPR Article 22 rights related to solely automated decision-making and profiling, including identification of automated decisions, meaningful…
Backup Retention and Erasure Management
Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, …
Establishing Binding Corporate Rules
Guides development and approval of Binding Corporate Rules under GDPR Article 47 for intra-group international data transfers. Covers Art. 47(2)(a)-(…
Assessing Biometric Processing Privacy
Guides DPIA for biometric processing systems including facial recognition, fingerprint, voice, iris, and gait analysis. Covers Art. 9 special categor…
BosskuAI Legal / Compliance
Use this for product-facing legal and compliance readiness such as privacy posture, consent, retention, vendor/data obligations, policy alignment, an…
Managing Breach Credit Monitoring
Coordinates credit monitoring and identity theft protection services for individuals affected by a data breach. Covers vendor selection criteria, enr…
Maintaining Breach Documentation Records
Maintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was …
Designing Breach Simulation Exercise
Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with real…
Managing Data Subject Breach Communication
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in …
Cybersecurity Breach Summary
Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, …
Universal Escalation Triggers (Apply to All Categories) (+2)
Sub-skill of canned-responses: Universal Escalation Triggers (Apply to All Categories) (+2).
cite-check — Copilot CLI Skill
Verifiable legal-citation tooling for product counsel reviews. Two modes: (1) ORIGINATE — turn a PPL issue into a Word document of Citation Cards whe…
Cloud Service Provider Privacy Assessment
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, share…
cold-start-interview-10
Run the cold-start interview — learns your privacy practice and writes CLAUDE.md from your policy, DPA template, and a reference PIA. Use on first ru…
Compliance and Audit
Use when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when prod…
Compliance Checklist Skill
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a com…
Compliance Checklist Generation
Generate compliance checklists for SOC2, HIPAA, PCI-DSS, and GDPR with gap analysis and remediation priorities.
compliance-evidence
Use when the user needs compliance and privacy evidence.
Compliance Policy Auditor
Audit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance…
Purpose
Compliance review for auditability, GDPR/PII, retention, financial controls, consent, and regulatory traceability.
Managing Consent for Transfers
Guide for obtaining explicit consent for international data transfers under GDPR Article 49(1)(a). Covers informed consent requirements including ris…
Implementing Consent Withdrawal
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving …
Controller RoPA Creation
Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and cont…
Pages: Cookie Policy
When the user wants to create or optimize a cookie policy page. Also use when the user mentions "cookie policy," "cookies," "cookie consent," "GDPR c…
Criminal Conviction and Offence Data Handling — GDPR Art. 10
Handles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and com…
customize-11
Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, esca…
Cybersecurity Breach Summary
Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response r…
Data Inventory and Mapping for Classification
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, thir…
Executing Data Portability Requests
Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller t…
Critical rules
Ensure data privacy compliance covering GDPR obligations, user consent management, data retention policies, PII detection, and data anonymisation wit…
GDPR Data Processing Addendum (DPA)
Drafts a GDPR Article 28-compliant Data Processing Addendum (DPA) between data controllers and processors. Extracts party details, processing scope, …
Approach
GDPR compliance analysis covering lawful basis assessment, privacy notices, processor agreements, and breach response.
Providing Direct Collection Information
Provides GDPR Article 13 information at the point of direct data collection, covering all required elements under Art. 13(1)(a)-(f) and Art. 13(2)(a)…
Supervisory Authority Inspection Preparation
Guides preparation for supervisory authority (DPA) inspections and investigations including document readiness checklists, interview preparation for …
dpa-review
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
dpa-review-anthropics
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
DPA Review
Review a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the …
dpa-review-zhou210712
依据你的数据处理协议(DPA)操作手册审查一份DPA——自动检测你是受托处理者 还是处理者,并应用操作手册正确的半部分。当用户说"审查这份DPA""检查这份 数据处理附录""客户发来了他们的DPA""这份DPA可以吗",或附上一份DPA时使用。
DPIA Risk Scoring Methodology
Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likeli…
Draft Cybersecurity Website Terms and Cookie Policies
Generates Terms of Use and Cookie Policy documents for a cybersecurity company website, strictly limiting data usage to newsletters and event updates…
Processing Data Subject Access Requests
Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day dead…
dsar-response
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
dsar-response-anthropics
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
DSAR Response
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data syste…
Employee DSAR Response
Manages Data Subject Access Request procedures for employee requests under Art. 15 GDPR. Covers scope of disclosable HR records, emails, CCTV footage…
Employee Monitoring DPIA
Conducts Data Protection Impact Assessments for employee monitoring systems per EDPB Guidelines 3/2019 on workplace data processing. Covers video sur…
Employment Consent Limits
Analyses the limitations on consent as a lawful basis for processing employee data under Art. 88 GDPR and WP29 Opinion 2/2017. Addresses power imbala…
encargo
Revisor de encargos de tratamiento — revisa un contrato de encargado del tratamiento contra el playbook configurado (como responsable o como encargad…
ePrivacy Directive Article 5(3) Essential Cookie Exemption
Applying the ePrivacy Directive Article 5(3) strictly necessary exemption to classify cookies that do not require consent. Covers exemption criteria,…
gdpr-audit-prep
/cs:gdpr-audit-prep <scope> — GDPR audit 6-question Article-cited forcing interrogation. Use before annual internal GDPR review, post-breach internal…
Implementing Data Protection Certification
Guides implementation of GDPR Article 42-43 data protection certification mechanisms including accredited certification bodies, criteria development,…
Developing Codes of Conduct
Guides development of GDPR Article 40-41 codes of conduct for industry sectors including drafting, submission, and monitoring body requirements. Acti…
Conducting Data Protection Audit
Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Inclu…
GDPR Compliance for Marketing
Ensure GDPR compliance for marketing activities including consent management, data processing, privacy notices, and data subject rights
GDPR Compliance
GDPR compliance - data subject rights, lawful basis, DPIA, privacy by design, breach notification, consent management, cross-border transfers, PII masking
GDPR Data Processing Addendum (DPA)
Drafts an Article 28-aligned GDPR Data Processing Addendum (DPA) as an attachable annex for SaaS, cloud, or outsourcing agreements. Outputs review-re…
GDPR Data Processing Addendum (DPA)
Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendu…
Appointing EU Representative
Guides appointment of GDPR Article 27 EU representative for non-EU controllers or processors. Covers criteria, responsibilities, and documentation. A…
GDPR Parental Consent Verification
Implements GDPR Article 8 parental consent verification for information society services offered to children. Covers age thresholds by EU/EEA Member …
Conducting Prior Consultation Process
Guides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirem…
Creating GDPR Remediation Roadmap
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation. Activate when building com…
Performing GDPR Controller Self-Assessment
Guides comprehensive controller self-assessment covering GDPR Articles 5-49 with scoring methodology and reporting format. Activate when conducting i…
Generate a Compliance Audit Document
Generate a formatted PDF compliance audit document with findings, risk ratings, remediation recommendations, and sign-off sections.
Generating Compliance Reports
Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance repor…
Configuring Google Consent Mode v2
Configuring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA…
Providing Indirect Collection Information
Provides GDPR Article 14 information for personal data obtained from sources other than the data subject, covering timing requirements (within reason…
Information Security Policy
Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notificati…
Tabletop Exercise Script for Incident Response Plan
Drafts a tabletop exercise script to stress-test an organization's Incident Response Plan against cybersecurity threats and breach notification oblig…
ISO 27701 Privacy Information Management Skill
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/I…
Managing Joint Controller Arrangements
Guides the establishment and management of joint controller arrangements under GDPR Article 26, including determination of joint controllership, allo…
Canned Responses Skill
Generate templated responses for common legal inquiries and identify when situations require individualized attention. Use when responding to routine…
Implementing Lawful Basis Assessment
Guides determination of the correct lawful basis under GDPR Article 6(1)(a)-(f) for each processing activity. Includes decision tree logic for consen…
legal-advisor
legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GD…
legal-advisor
legal-advisor workflow skill. Use this skill when the user needs Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GD…
Privacy & Terms Generator
Generate jurisdiction-aware Privacy Policies and Terms & Conditions for SaaS products, apps, and digital services. Use this skill whenever the user a…
Legal Lite Privacy Review
DPA, 개인정보 처리 활동, DSAR, PIA/DPIA, privacy policy 변경을 검토합니다. 사용자가 제공한 정책/문서/처리 설명을 기준으로 개인정보 리스크와 확인 질문, 초안 산출물을 만들 때 사용합니다.
Assessing Legitimate Interest vs Consent
Decision framework for choosing between consent and legitimate interest as the lawful basis for processing. Covers power imbalance indicators, condit…
Performing Legitimate Interest Assessment
Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Act…
Managing Consent for Research
Guide for managing consent for scientific research under GDPR Article 89 and Recital 33 broad consent provisions. Covers ethical review board coordin…
Assessing Marketing Analytics Privacy
Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) coo…
NIST Privacy Framework — IDENTIFY Function
Implement the NIST Privacy Framework IDENTIFY function including ID.BE business environment, ID.DA data actions, ID.IM improvement, and ID.RA risk as…
Personal Data Classification Test — GDPR Art. 4(1)
Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU…
pia-generation
Generate a Privacy Impact Assessment in house format for a new feature, product, or processing activity, using the structure learned from your seed P…
PIA Generation
Generate a Privacy Impact Assessment in house format for a new feature, product, or processing activity, using the structure learned from your seed PIA.
Privacy Impact Assessment for Large-Scale Monitoring
Conducts Privacy Impact Assessment for large-scale systematic monitoring under GDPR Article 35(3)(c). Covers CCTV and video surveillance, employee mo…
Managing PIA Review and Update Cadence
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breac…
policy-monitor-anthropics
Keep the privacy policy current with practice. Two modes: weekly sweep of saved PIAs, DPA reviews, and triage results to find policy drift; or direct…
policy-redraft-zekaisuni
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir. Kaynak politika dosyasını d…
Privacy Guideline
Privacy and data protection - GDPR, CCPA, consent. Use when handling user data.
Privacy Check Skill
Use to assess Privacy by Design compliance and GDPR/data protection alignment for a feature or system.
Privacy Law Gap Analysis for Market Entry
Guides conducting privacy law gap analysis for market entry into new jurisdictions. Covers target jurisdiction assessment, existing compliance mappin…
Pages: Privacy Policy
When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data pr…
개인정보처리방침 생성기
데이터 유형, 관할권, GDPR 및 컴플라이언스 고려사항, 법률 검토가 필요한 조항을 다루는 상세한 개인정보처리방침을 초안 작성합니다. 개인정보처리방침 작성, 데이터 보호 문서 업데이트, 또는 컴플라이언스 준비 시 사용하세요.
Privacy policy paperclipai
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review
Privacy Policy Generator
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when cre…
Skill: privacy-policy-reviewer
Review a privacy policy or terms of service against a structured scorecard, combining TOSDR's human-curated ratings with LLM analysis. Use when a use…
Pseudonymised vs Anonymised Data Classification
Classifies data as pseudonymised or anonymised using Recital 26 reasonably likely test, Breyer ruling C-582/14, motivated intruder test, and WP29 Opi…
Recovery App Legal Terms
Generate legally-sound terms of service, privacy policies, and medical disclaimers for recovery and wellness applications. Expert in HIPAA, GDPR, CCP…
reg-gap-analysis-anthropics
Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates. Use w…
Handling Right to Restriction Requests
Handles GDPR Article 18 right to restriction of processing requests, covering the four grounds for restriction (accuracy contest, unlawful processing…
Retention Exception Management
Manages retention exception workflows including request-approval processes, duration limits, periodic review cycles, documentation requirements, and …
Implementing Right to Erasure Workflow
Implements the GDPR Article 17 right to erasure (right to be forgotten) workflow, covering all six grounds for erasure, five exceptions, technical de…
Handling Right to Object to Processing
Handles GDPR Article 21 right to object to processing, including compelling legitimate grounds assessment, ceasing processing obligations, documentat…
Processing Right to Rectification
Processes GDPR Article 16 right to rectification requests, covering verification of corrected data accuracy, notification to recipients under Article…
RoPA Maintenance Workflow
Establishes ongoing RoPA maintenance processes including update triggers, change management integration, version control, stakeholder review cycles, …
RoPA Tool Integration
Integrates Records of Processing Activities with privacy management platforms including OneTrust, TrustArc, Collibra, and DataGrail. Covers API-based…
Search Engine Erasure (Right to Be Forgotten)
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request pr…
Slovak to English GDPR Translation
Translates legal articles from Slovak to English with strict terminology mappings for GDPR terms ('prevádzkovateľ' to 'Controller', 'sprostredkovateľ…
Special Category Data Classification — GDPR Art. 9
Identifies and classifies GDPR Art. 9 special category data including racial origin, political opinions, religious beliefs, trade union membership, g…
Sub-Processor Management
GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification proced…
Implementing Supplementary Measures
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations …
Terms of Service Analyzer
Analyze terms of service and privacy policies to identify concerning clauses, hidden permissions, and user rights implications
Terms Recon
Survey existing privacy and legal docs for completeness and GDPR compliance.
Conducting Transfer Impact Assessment
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country…
Implementing Transparent Communication
Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, re…
use-case-triage
Quickly determine whether a processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed — surfaces privacy policy conflicts and routes to …
vendor-ai-review-anthropics
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model chang…
Vendor Privacy Audit
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classificatio…
Vendor Privacy Due Diligence
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, da…
Vendor Security Assessment Questionnaire
Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor resp…