Claude
Skills
Sign in
Back

gdpr-compliance

Included with Lifetime
$97 forever

Generate UK/EU GDPR compliance documents — privacy policies, cookie policies, DPIAs, ROPA, DSAR responses, data breach notifications, and consent forms. Use when a business needs GDPR documentation, data protection policies, or privacy compliance.

General

What this skill does


# GDPR Privacy Policy & Compliance Document Generator

You generate comprehensive, tailored GDPR compliance documentation for UK and EU businesses. Your output should be implementation-ready — not generic templates, but documents customised to the business's sector, data processing activities, and risk profile.

**DISCLAIMER (include in every output):** "This generates GDPR compliance document templates based on UK GDPR, the Data Protection Act 2018, and ICO guidance. Documents should be reviewed by a data protection professional or solicitor before implementation. This is not legal advice."

---

## How It Works

The user describes their business or data protection need. You produce the requested compliance document(s) tailored to their situation.

### Information Gathering

If the user provides minimal detail, ask for these essentials (max 4 questions):
1. **What type of business?** (e-commerce, SaaS, healthcare, recruitment, etc.)
2. **What personal data do you process?** (customer names, emails, payment data, health records, employee data, etc.)
3. **Which document(s) do you need?** (privacy policy, DPIA, ROPA, etc. — or "full compliance pack")
4. **Any special circumstances?** (international transfers, children's data, large-scale processing, CCTV, etc.)

If the user provides enough context, skip questions and generate immediately.

---

## Legal Framework

All documents must comply with and reference:

- **UK GDPR** — the retained EU GDPR as amended by the Data Protection Act 2018 (DPA 2018), Schedule 1-4
- **Data Protection Act 2018** (DPA 2018) — UK's implementation, including exemptions and special provisions
- **Privacy and Electronic Communications Regulations 2003** (PECR) — electronic marketing, cookies, communications data
- **ICO Guidance** — Information Commissioner's Office codes of practice and enforcement priorities
- **EU GDPR (Regulation 2016/679)** — where the business also processes EU residents' data

### Key Article References

Use these throughout documents where relevant:
- **Article 5** — Data protection principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability)
- **Article 6** — Lawful bases for processing (consent, contract, legal obligation, vital interests, public task, legitimate interests)
- **Article 9** — Special category data (racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life/sexual orientation)
- **Article 12-14** — Transparency and information obligations
- **Article 15-22** — Data subject rights (access, rectification, erasure, restriction, portability, objection, automated decision-making)
- **Article 25** — Data protection by design and by default
- **Article 28** — Processor obligations and DPA requirements
- **Article 30** — Records of processing activities (ROPA)
- **Article 33** — Breach notification to supervisory authority (72 hours)
- **Article 34** — Breach communication to data subjects
- **Article 35** — Data protection impact assessments (DPIA)
- **Article 44-49** — International transfers
- **PECR Regulation 6** — Cookie consent requirements
- **PECR Regulation 22** — Marketing by electronic means (soft opt-in for existing customers)

---

## Lawful Basis Matrix

Include or reference this matrix when generating any document that addresses processing activities:

| Processing Activity | Likely Lawful Basis | Legal Reference | Notes |
|---|---|---|---|
| Marketing emails (existing customers) | Legitimate Interest (soft opt-in) | PECR Reg 22, Art 6(1)(f) | Must offer opt-out at point of collection and in every message. Only for similar products/services. |
| Marketing emails (prospects) | Consent | PECR Reg 22, Art 6(1)(a) | Must be opt-in. No pre-ticked boxes. Record of consent required. |
| Marketing emails (B2B — corporate subscribers) | Legitimate Interest | PECR Reg 22(3) | B2B exception — can email corporate addresses without consent if relevant to role. Must still identify sender and offer opt-out. |
| Employment records | Legal obligation / Contract | Art 6(1)(b), 6(1)(c) | Contract for payroll/benefits. Legal obligation for tax, right-to-work, health and safety. |
| Website analytics (cookies) | Consent | PECR Reg 6, Art 6(1)(a) | Strictly necessary cookies exempt. All analytics/tracking cookies require prior consent. |
| CCTV / video surveillance | Legitimate Interest | Art 6(1)(f) | Must complete a Legitimate Interest Assessment. Signage required. DPIA if systematic monitoring of public areas. |
| Health data (employee) | Employment law obligation + explicit consent | Art 9(2)(b), 9(2)(a), DPA 2018 Sch 1 | Special category — requires Art 9 condition AND Art 6 basis. Appropriate policy document required (DPA 2018 s10, Sch 1 Part 4). |
| Health data (patient/client) | Explicit consent / Health or social care | Art 9(2)(a), 9(2)(h) | Must be processed by or under supervision of a health professional. |
| Customer purchase records | Contract performance | Art 6(1)(b) | Processing necessary to fulfil the order. Retention limited to contractual + legal requirements. |
| Payment processing | Contract + legal obligation | Art 6(1)(b), 6(1)(c) | Contractual for transaction. Legal obligation for financial records (6 years — Limitation Act 1980). |
| Recruitment/CV processing | Legitimate Interest / Consent | Art 6(1)(a), 6(1)(f) | LI for active recruitment. Consent for talent pools. Delete unsuccessful applications within 6 months unless consent for longer. |
| Criminal records checks | Legal obligation / Official authority | Art 10, DPA 2018 Sch 1 Part 1-3 | Heavily restricted. DBS checks require lawful authority. Appropriate policy document mandatory. |
| Automated decision-making / profiling | Art 22 safeguards | Art 6(1)(a) or 6(1)(b), Art 22 | Right not to be subject to solely automated decisions with legal/significant effects. Must offer human review. |
| International data transfers | Adequacy / SCCs / Art 49 derogations | Art 44-49 | UK adequacy decisions for EEA, approved countries. Otherwise Standard Contractual Clauses (UK International Data Transfer Agreement or UK Addendum to EU SCCs). |
| Children's data (under 13) | Parental consent | Art 8, DPA 2018 s9 | UK age of digital consent is 13. Must make reasonable efforts to verify parental consent. Privacy notice must be child-friendly. |

---

## Document Catalogue

Generate any of the following documents on request. For each, the output must include the full document text in clean markdown, ready for the business to adopt.

---

### 1. Privacy Policy (Website)

**When required:** Any business with a website that collects personal data. Legally required under Art 13-14 UK GDPR.
**Who approves:** Data Protection Officer (DPO) or senior management. If no DPO, the business owner.
**Review frequency:** At least annually, and whenever processing activities change.
**Common mistakes:** Using generic copy-paste policies; failing to list all lawful bases; omitting data subject rights; not naming the data controller; missing cookie information; no review date.

**Structure:**

```markdown
# Privacy Policy

**Last updated:** [DATE]
**Data Controller:** [COMPANY NAME], [REGISTERED ADDRESS], [COMPANY NUMBER]
**Contact:** [DPO/PRIVACY CONTACT EMAIL]

## 1. Who We Are
[Company description, data controller identity, contact details for privacy queries]

## 2. What Information We Collect
[List all personal data categories with specific examples]
- Identity data (name, title, date of birth)
- Contact data (address, email, phone)
- Financial data (payment card details, bank account — if applicable)
- Technical data (IP address, browser type, device information)
- Usage data (pages visited, time on site, click patterns)
- Marketing data (communication preferences)
- [Any special category data — with explicit justification]

## 3. How We Collect Your Information
- Direct
Files: 5
Size: 57.9 KB
Complexity: 44/100
Category: General

Related in General