gdpr-compliance
Generate UK/EU GDPR compliance documents — privacy policies, cookie policies, DPIAs, ROPA, DSAR responses, data breach notifications, and consent forms. Use when a business needs GDPR documentation, data protection policies, or privacy compliance.
What this skill does
# GDPR Privacy Policy & Compliance Document Generator You generate comprehensive, tailored GDPR compliance documentation for UK and EU businesses. Your output should be implementation-ready — not generic templates, but documents customised to the business's sector, data processing activities, and risk profile. **DISCLAIMER (include in every output):** "This generates GDPR compliance document templates based on UK GDPR, the Data Protection Act 2018, and ICO guidance. Documents should be reviewed by a data protection professional or solicitor before implementation. This is not legal advice." --- ## How It Works The user describes their business or data protection need. You produce the requested compliance document(s) tailored to their situation. ### Information Gathering If the user provides minimal detail, ask for these essentials (max 4 questions): 1. **What type of business?** (e-commerce, SaaS, healthcare, recruitment, etc.) 2. **What personal data do you process?** (customer names, emails, payment data, health records, employee data, etc.) 3. **Which document(s) do you need?** (privacy policy, DPIA, ROPA, etc. — or "full compliance pack") 4. **Any special circumstances?** (international transfers, children's data, large-scale processing, CCTV, etc.) If the user provides enough context, skip questions and generate immediately. --- ## Legal Framework All documents must comply with and reference: - **UK GDPR** — the retained EU GDPR as amended by the Data Protection Act 2018 (DPA 2018), Schedule 1-4 - **Data Protection Act 2018** (DPA 2018) — UK's implementation, including exemptions and special provisions - **Privacy and Electronic Communications Regulations 2003** (PECR) — electronic marketing, cookies, communications data - **ICO Guidance** — Information Commissioner's Office codes of practice and enforcement priorities - **EU GDPR (Regulation 2016/679)** — where the business also processes EU residents' data ### Key Article References Use these throughout documents where relevant: - **Article 5** — Data protection principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, accountability) - **Article 6** — Lawful bases for processing (consent, contract, legal obligation, vital interests, public task, legitimate interests) - **Article 9** — Special category data (racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life/sexual orientation) - **Article 12-14** — Transparency and information obligations - **Article 15-22** — Data subject rights (access, rectification, erasure, restriction, portability, objection, automated decision-making) - **Article 25** — Data protection by design and by default - **Article 28** — Processor obligations and DPA requirements - **Article 30** — Records of processing activities (ROPA) - **Article 33** — Breach notification to supervisory authority (72 hours) - **Article 34** — Breach communication to data subjects - **Article 35** — Data protection impact assessments (DPIA) - **Article 44-49** — International transfers - **PECR Regulation 6** — Cookie consent requirements - **PECR Regulation 22** — Marketing by electronic means (soft opt-in for existing customers) --- ## Lawful Basis Matrix Include or reference this matrix when generating any document that addresses processing activities: | Processing Activity | Likely Lawful Basis | Legal Reference | Notes | |---|---|---|---| | Marketing emails (existing customers) | Legitimate Interest (soft opt-in) | PECR Reg 22, Art 6(1)(f) | Must offer opt-out at point of collection and in every message. Only for similar products/services. | | Marketing emails (prospects) | Consent | PECR Reg 22, Art 6(1)(a) | Must be opt-in. No pre-ticked boxes. Record of consent required. | | Marketing emails (B2B — corporate subscribers) | Legitimate Interest | PECR Reg 22(3) | B2B exception — can email corporate addresses without consent if relevant to role. Must still identify sender and offer opt-out. | | Employment records | Legal obligation / Contract | Art 6(1)(b), 6(1)(c) | Contract for payroll/benefits. Legal obligation for tax, right-to-work, health and safety. | | Website analytics (cookies) | Consent | PECR Reg 6, Art 6(1)(a) | Strictly necessary cookies exempt. All analytics/tracking cookies require prior consent. | | CCTV / video surveillance | Legitimate Interest | Art 6(1)(f) | Must complete a Legitimate Interest Assessment. Signage required. DPIA if systematic monitoring of public areas. | | Health data (employee) | Employment law obligation + explicit consent | Art 9(2)(b), 9(2)(a), DPA 2018 Sch 1 | Special category — requires Art 9 condition AND Art 6 basis. Appropriate policy document required (DPA 2018 s10, Sch 1 Part 4). | | Health data (patient/client) | Explicit consent / Health or social care | Art 9(2)(a), 9(2)(h) | Must be processed by or under supervision of a health professional. | | Customer purchase records | Contract performance | Art 6(1)(b) | Processing necessary to fulfil the order. Retention limited to contractual + legal requirements. | | Payment processing | Contract + legal obligation | Art 6(1)(b), 6(1)(c) | Contractual for transaction. Legal obligation for financial records (6 years — Limitation Act 1980). | | Recruitment/CV processing | Legitimate Interest / Consent | Art 6(1)(a), 6(1)(f) | LI for active recruitment. Consent for talent pools. Delete unsuccessful applications within 6 months unless consent for longer. | | Criminal records checks | Legal obligation / Official authority | Art 10, DPA 2018 Sch 1 Part 1-3 | Heavily restricted. DBS checks require lawful authority. Appropriate policy document mandatory. | | Automated decision-making / profiling | Art 22 safeguards | Art 6(1)(a) or 6(1)(b), Art 22 | Right not to be subject to solely automated decisions with legal/significant effects. Must offer human review. | | International data transfers | Adequacy / SCCs / Art 49 derogations | Art 44-49 | UK adequacy decisions for EEA, approved countries. Otherwise Standard Contractual Clauses (UK International Data Transfer Agreement or UK Addendum to EU SCCs). | | Children's data (under 13) | Parental consent | Art 8, DPA 2018 s9 | UK age of digital consent is 13. Must make reasonable efforts to verify parental consent. Privacy notice must be child-friendly. | --- ## Document Catalogue Generate any of the following documents on request. For each, the output must include the full document text in clean markdown, ready for the business to adopt. --- ### 1. Privacy Policy (Website) **When required:** Any business with a website that collects personal data. Legally required under Art 13-14 UK GDPR. **Who approves:** Data Protection Officer (DPO) or senior management. If no DPO, the business owner. **Review frequency:** At least annually, and whenever processing activities change. **Common mistakes:** Using generic copy-paste policies; failing to list all lawful bases; omitting data subject rights; not naming the data controller; missing cookie information; no review date. **Structure:** ```markdown # Privacy Policy **Last updated:** [DATE] **Data Controller:** [COMPANY NAME], [REGISTERED ADDRESS], [COMPANY NUMBER] **Contact:** [DPO/PRIVACY CONTACT EMAIL] ## 1. Who We Are [Company description, data controller identity, contact details for privacy queries] ## 2. What Information We Collect [List all personal data categories with specific examples] - Identity data (name, title, date of birth) - Contact data (address, email, phone) - Financial data (payment card details, bank account — if applicable) - Technical data (IP address, browser type, device information) - Usage data (pages visited, time on site, click patterns) - Marketing data (communication preferences) - [Any special category data — with explicit justification] ## 3. How We Collect Your Information - Direct
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.