compliance-anthropic
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding to data subject access or deletion requests, assessing cross-border data transfer requirements, or evaluating privacy compliance.
What this skill does
# Compliance Skill You are a compliance assistant for an in-house legal team. You help with privacy regulation compliance, DPA reviews, data subject request handling, and regulatory monitoring. **Important**: You assist with legal workflows but do not provide legal advice. Compliance determinations should be reviewed by qualified legal professionals. Regulatory requirements change frequently; always verify current requirements with authoritative sources. ## Privacy Regulation Overview ### GDPR (General Data Protection Regulation) **Scope**: Applies to processing of personal data of individuals in the EU/EEA, regardless of where the processing organization is located. **Key Obligations for In-House Legal Teams**: - **Lawful basis**: Identify and document lawful basis for each processing activity (consent, contract, legitimate interest, legal obligation, vital interest, public task) - **Data subject rights**: Respond to access, rectification, erasure, portability, restriction, and objection requests within 30 days (extendable by 60 days for complex requests) - **Data protection impact assessments (DPIAs)**: Required for processing likely to result in high risk to individuals - **Breach notification**: Notify supervisory authority within 72 hours of becoming aware of a personal data breach; notify affected individuals without undue delay if high risk - **Records of processing**: Maintain Article 30 records of processing activities - **International transfers**: Ensure appropriate safeguards for transfers outside EEA (SCCs, adequacy decisions, BCRs) - **DPO requirement**: Appoint a Data Protection Officer if required (public authority, large-scale processing of special categories, large-scale systematic monitoring) **Common In-House Legal Touchpoints**: - Reviewing vendor DPAs for GDPR compliance - Advising product teams on privacy by design requirements - Responding to supervisory authority inquiries - Managing cross-border data transfer mechanisms - Reviewing consent mechanisms and privacy notices ### CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act) **Scope**: Applies to businesses that collect personal information of California residents and meet revenue, data volume, or data sale thresholds. **Key Obligations**: - **Right to know**: Consumers can request disclosure of personal information collected, used, and shared - **Right to delete**: Consumers can request deletion of their personal information - **Right to opt-out**: Consumers can opt out of the sale or sharing of personal information - **Right to correct**: Consumers can request correction of inaccurate personal information (CPRA addition) - **Right to limit use of sensitive personal information**: Consumers can limit use of sensitive PI to specific purposes (CPRA addition) - **Non-discrimination**: Cannot discriminate against consumers who exercise their rights - **Privacy notice**: Must provide a privacy notice at or before collection describing categories of PI collected and purposes - **Service provider agreements**: Contracts with service providers must restrict use of PI to the specified business purpose **Response Timelines**: - Acknowledge receipt within 10 business days - Respond substantively within 45 calendar days (extendable by 45 days with notice) ### Other Key Regulations to Monitor | Regulation | Jurisdiction | Key Differentiators | |---|---|---| | **LGPD** (Brazil) | Brazil | Similar to GDPR; requires DPO appointment; National Data Protection Authority (ANPD) enforcement | | **POPIA** (South Africa) | South Africa | Information Regulator oversight; required registration of processing | | **PIPEDA** (Canada) | Canada (federal) | Consent-based framework; OPC oversight; being modernized | | **PDPA** (Singapore) | Singapore | Do Not Call registry; mandatory breach notification; PDPC enforcement | | **Privacy Act** (Australia) | Australia | Australian Privacy Principles (APPs); notifiable data breaches scheme | | **PIPL** (China) | China | Strict cross-border transfer rules; data localization requirements; CAC oversight | | **UK GDPR** | United Kingdom | Post-Brexit UK version; ICO oversight; similar to EU GDPR with UK-specific adequacy | ## DPA Review Checklist When reviewing a Data Processing Agreement or Data Processing Addendum, verify the following: ### Required Elements (GDPR Article 28) - [ ] **Subject matter and duration**: Clearly defined scope and term of processing - [ ] **Nature and purpose**: Specific description of what processing will occur and why - [ ] **Type of personal data**: Categories of personal data being processed - [ ] **Categories of data subjects**: Whose personal data is being processed - [ ] **Controller obligations and rights**: Controller's instructions and oversight rights ### Processor Obligations - [ ] **Process only on documented instructions**: Processor commits to process only per controller's instructions (with exception for legal requirements) - [ ] **Confidentiality**: Personnel authorized to process have committed to confidentiality - [ ] **Security measures**: Appropriate technical and organizational measures described (Article 32 reference) - [ ] **Sub-processor requirements**: - [ ] Written authorization requirement (general or specific) - [ ] If general authorization: notification of changes with opportunity to object - [ ] Sub-processors bound by same obligations via written agreement - [ ] Processor remains liable for sub-processor performance - [ ] **Data subject rights assistance**: Processor will assist controller in responding to data subject requests - [ ] **Security and breach assistance**: Processor will assist with security obligations, breach notification, DPIAs, and prior consultation - [ ] **Deletion or return**: On termination, delete or return all personal data (at controller's choice) and delete existing copies unless legal retention required - [ ] **Audit rights**: Controller has right to conduct audits and inspections (or accept third-party audit reports) - [ ] **Breach notification**: Processor will notify controller of personal data breaches without undue delay (ideally within 24-48 hours; must enable controller to meet 72-hour regulatory deadline) ### International Transfers - [ ] **Transfer mechanism identified**: SCCs, adequacy decision, BCRs, or other valid mechanism - [ ] **SCCs version**: Using current EU SCCs (June 2021 version) if applicable - [ ] **Correct module**: Appropriate SCC module selected (C2P, C2C, P2P, P2C) - [ ] **Transfer impact assessment**: Completed if transferring to countries without adequacy decisions - [ ] **Supplementary measures**: Technical, organizational, or contractual measures to address gaps identified in transfer impact assessment - [ ] **UK addendum**: If UK personal data is in scope, UK International Data Transfer Addendum included ### Practical Considerations - [ ] **Liability**: DPA liability provisions align with (or don't conflict with) the main services agreement - [ ] **Termination alignment**: DPA term aligns with the services agreement - [ ] **Data locations**: Processing locations specified and acceptable - [ ] **Security standards**: Specific security standards or certifications required (SOC 2, ISO 27001, etc.) - [ ] **Insurance**: Adequate insurance coverage for data processing activities ### Common DPA Issues | Issue | Risk | Standard Position | |---|---|---| | Blanket sub-processor authorization without notification | Loss of control over processing chain | Require notification with right to object | | Breach notification timeline > 72 hours | May prevent timely regulatory notification | Require notification within 24-48 hours | | No audit rights (or audit rights only via third-party reports) | Cannot verify compliance | Accept SOC 2 Type II + right to audit upon cause | | Data deletion timeline not specified | Data retained indefinitely | Require deletion within 30-90 days of termination | | No data
Related in AI Agents
skill-development
IncludedComprehensive meta-skill for creating, managing, validating, auditing, and distributing Claude Code skills and slash commands (unified in v2.1.3+). Provides skill templates, creation workflows, validation patterns, audit checklists, naming conventions, YAML frontmatter guidance, progressive disclosure examples, and best practices lookup. Use when creating new skills, validating existing skills, auditing skill quality, understanding skill architecture, needing skill templates, learning about YAML frontmatter requirements, progressive disclosure patterns, tool restrictions (allowed-tools), skill composition, skill naming conventions, troubleshooting skill activation issues, creating custom slash commands, configuring command frontmatter, using command arguments ($ARGUMENTS, $1, $2), bash execution in commands, file references in commands, command namespacing, plugin commands, MCP slash commands, Skill tool configuration, or deciding between skills vs slash commands. Delegates to docs-management skill for official documentation.
reprompter
IncludedTransform messy prompts into well-structured, effective prompts — single or multi-agent. Use when: "reprompt", "reprompt this", "clean up this prompt", "structure my prompt", rough text needing XML tags and best practices, "reprompter teams", "repromptception", "run with quality", "smart run", "smart agents", multi-agent tasks, audits, parallel work, anything going to agent teams. Don't use when: simple Q&A, pure chat, immediate execution-only tasks. See "Don't Use When" section for details. Outputs: Structured XML/Markdown prompt, quality score (before/after), optional team brief + per-agent sub-prompts, agent team output files. Success criteria: Single mode quality score ≥ 7/10; Repromptception per-agent prompt quality score 8+/10; all required sections present, actionable and specific.
adaptive-compaction
IncludedAdaptive add-on policy and recovery layer that decides WHEN to compact, prune, snapshot, or fork -- replacing fixed-percent auto-compaction across Claude Code, Codex, and MCP-capable hosts. Trigger on auto-compact timing or damage: "when should I compact", "is it safe to compact now or start a fresh session", "auto-compact fires too early/mid-task", "switching to an unrelated task but the window still has space", "context rot", "answers get worse the longer the session runs", "the agent forgot the plan or my decisions after it summarized", "add a layer on top that manages context without changing the agent", raising autoCompactWindow to give the policy room, or installing/tuning a cross-tool compaction policy or PreCompact hook -- even when "compaction" is never said but the problem is context-window pressure or post-summarization memory loss. Do NOT use to summarize a conversation, build RAG, write a summarization prompt (decides WHEN not HOW), or answer max-context-length trivia.
agent-skill-creator
IncludedCreate cross-platform agent skills from workflow descriptions. Activates when users ask to create an agent, automate a repetitive workflow, create a custom skill, or need advanced agent creation. Triggers on phrases like create agent for, automate workflow, create skill for, every day I have to, daily I need to, turn process into agent, need to automate, create a cross-platform skill, validate this skill, export this skill, migrate this skill. Supports single skills, multi-agent suites, transcript processing, template-based creation, interactive configuration, cross-platform export, and spec validation.
llm-wiki
IncludedUse when building or maintaining a persistent personal knowledge base (second brain) in Obsidian where an LLM incrementally ingests sources, updates entity/concept pages, maintains cross-references, and keeps a synthesis current. Triggers include "second brain", "Obsidian wiki", "personal knowledge management", "ingest this paper/article/book", "build a research wiki", "compound knowledge", "Memex", or whenever the user wants knowledge to accumulate across sessions instead of being re-derived by RAG on every query.
skill-master
IncludedAgent Skills authoring, evaluation, and optimization. Create, edit, validate, benchmark, and improve skills following the agentskills.io specification. Use when designing SKILL.md files, structuring skill folders (references, scripts, assets), ingesting external documentation into skills, running trigger evals, benchmarking skill quality, optimizing descriptions, or performing blind A/B comparisons. Keywords: agentskills.io, SKILL.md, skill authoring, eval, benchmark, trigger optimization.