privacy-compliance
Guide teams through GDPR, CCPA/CPRA, and international privacy law obligations including DPA reviews, data subject access and deletion requests, cross-border data transfers, breach notification, and regulatory monitoring. Use when evaluating data processing agreements, handling DSAR or right-to-delete requests, assessing international data transfer mechanisms, reviewing privacy notices, or tracking privacy regulation changes.
What this skill does
## Global Privacy Landscape ### EU General Data Protection Regulation (GDPR) **Territorial reach**: Governs the processing of personal data belonging to individuals located in the EU/EEA, irrespective of where the processing entity is based. **Core obligations for in-house legal teams**: - **Legal basis documentation**: Every processing activity must rest on one of six recognized grounds -- consent, contractual necessity, legitimate interest, statutory obligation, protection of vital interests, or public authority function - **Individual rights fulfillment**: Requests for access, correction, deletion, portability, processing restriction, and objection must be resolved within one calendar month, with a two-month extension available for particularly involved requests - **Impact assessments (DPIAs)**: Mandatory when processing is expected to create elevated risk for individuals - **Incident reporting**: The competent supervisory authority must be notified within 72 hours of detecting a personal data breach; affected individuals require prompt notification when the breach poses high risk - **Processing inventory**: Maintain the register of processing activities mandated by Article 30 - **Cross-border safeguards**: Transfers outside the EEA require valid mechanisms such as Standard Contractual Clauses, adequacy determinations, or Binding Corporate Rules - **Data Protection Officer**: Appointment is required in specific situations -- public bodies, organizations conducting large-scale processing of sensitive categories, or those engaged in systematic large-scale monitoring **Where in-house teams most often engage**: - Evaluating vendor DPAs for regulatory alignment - Counseling product teams on embedding privacy into design - Managing communications with supervisory authorities - Maintaining and updating transfer mechanisms - Reviewing consent flows and privacy disclosures ### California CCPA / CPRA **Territorial reach**: Applies to businesses handling the personal information of California residents that satisfy specified revenue, data volume, or data monetization thresholds. **Core obligations**: - **Disclosure right**: Individuals may request a full accounting of personal information collected, used, and disclosed - **Deletion right**: Individuals may demand erasure of their personal information - **Opt-out right**: Individuals may prohibit the sale or sharing of their personal information - **Correction right**: Individuals may require amendment of inaccurate records (added by CPRA) - **Sensitive data limitation**: Individuals may restrict the use of sensitive personal information to enumerated purposes (added by CPRA) - **Equal treatment**: Organizations may not penalize individuals who exercise their statutory rights - **Collection notice**: A privacy disclosure must be provided at or before the point of collection, detailing categories gathered and their purposes - **Vendor agreements**: Contracts with service providers must confine personal information use to the specified business function **Fulfillment deadlines**: - Acknowledge receipt: 10 business days - Provide substantive response: 45 calendar days, with a 45-day extension available upon notice ### Additional Jurisdictions to Track | Framework | Territory | Distinguishing Features | |---|---|---| | **LGPD** | Brazil | Closely modeled on GDPR; DPO appointment mandatory; enforced by the ANPD | | **POPIA** | South Africa | Overseen by the Information Regulator; processing registration required | | **PIPEDA** | Canada (federal) | Consent-centric model; OPC oversight; modernization in progress | | **PDPA** | Singapore | Includes Do Not Call registry; mandatory breach notification; PDPC enforcement | | **Privacy Act** | Australia | Australian Privacy Principles (APPs); notifiable data breaches scheme | | **PIPL** | China | Stringent cross-border transfer requirements; data localization mandates; CAC oversight | | **UK GDPR** | United Kingdom | Post-Brexit adaptation; ICO supervision; substantively parallel to EU GDPR with UK-specific adequacy framework | ## Data Processing Agreement Review When evaluating a DPA or data processing addendum, verify the presence and adequacy of the following elements. ### Mandatory Components (per GDPR Article 28) - [ ] **Processing scope and timeline**: Clearly articulated subject matter, duration, and boundaries - [ ] **Processing activities**: Specific description of what operations will be performed and for what business reason - [ ] **Data categories**: Enumeration of the types of personal data involved - [ ] **Data subject populations**: Identification of whose data is being processed - [ ] **Controller prerogatives**: Specification of the controller's instruction authority and oversight rights ### Processor Commitments - [ ] **Instruction adherence**: Processor undertakes to act solely on documented controller instructions, except where overridden by applicable law - [ ] **Personnel confidentiality**: All individuals authorized to handle personal data have binding confidentiality commitments - [ ] **Security posture**: Adequate technical and organizational safeguards are described, referencing Article 32 standards - [ ] **Sub-processing governance**: - [ ] Prior written authorization requirement (general or specific) - [ ] For general authorization: advance notification of sub-processor changes with a meaningful objection window - [ ] Sub-processors contractually bound to equivalent obligations - [ ] Processor retains liability for sub-processor conduct - [ ] **Rights request support**: Processor commits to assisting the controller with individual rights fulfillment - [ ] **Incident and assessment support**: Processor provides assistance with security compliance, breach reporting, impact assessments, and prior consultation - [ ] **End-of-term data handling**: Upon contract conclusion, all personal data is deleted or returned at the controller's election; residual copies are destroyed unless law mandates retention - [ ] **Verification rights**: Controller holds the right to audit and inspect, or to accept independent third-party audit reports - [ ] **Breach alerting**: Processor will report personal data breaches without undue delay, ideally within 24 to 48 hours, ensuring the controller can meet the 72-hour regulatory window ### International Transfer Provisions - [ ] **Mechanism specified**: SCCs, adequacy determination, Binding Corporate Rules, or other recognized safeguard identified - [ ] **SCC version**: Current EU SCCs (adopted June 2021) employed where applicable - [ ] **Module selection**: Correct SCC module chosen for the relationship (Controller-to-Processor, Controller-to-Controller, Processor-to-Processor, Processor-to-Controller) - [ ] **Transfer risk evaluation**: Completed for destinations lacking an adequacy determination - [ ] **Supplemental safeguards**: Technical, organizational, or contractual measures addressing gaps revealed by the transfer risk evaluation - [ ] **UK coverage**: If UK personal data is within scope, the UK International Data Transfer Addendum is appended ### Operational Alignment - [ ] **Liability coordination**: DPA liability terms are consistent with (and do not undermine) the master services agreement - [ ] **Term synchronization**: DPA duration aligns with the underlying services contract - [ ] **Geographic specificity**: Processing locations are enumerated and acceptable - [ ] **Security certifications**: Relevant standards or attestations required (SOC 2 Type II, ISO 27001, etc.) - [ ] **Risk transfer**: Adequate insurance coverage for data processing activities confirmed ### Recurring DPA Weaknesses | Weakness | Exposure | Recommended Position | |---|---|---| | Blanket sub-processor approval without notification | Erodes controller oversight of the processing chain | Mandate advance notice with right to object | | Breach notification window exceeding 72 hours | Controller may miss reg
Related in Data & Analytics
clawarr-suite
IncludedComprehensive management for self-hosted media stacks (Sonarr, Radarr, Lidarr, Readarr, Prowlarr, Bazarr, Overseerr, Plex, Tautulli, SABnzbd, Recyclarr, Unpackerr, Notifiarr, Maintainerr, Kometa, FlareSolverr). Deep library exploration, analytics, dashboard generation, content management, request handling, subtitle management, indexer control, download monitoring, quality profile sync, library cleanup automation, notification routing, collection/overlay management, and media tracker integration (Trakt, Letterboxd, Simkl).
querying-soql
IncludedSOQL query generation, optimization, and analysis with 100-point scoring. Use this skill when the user needs SOQL/SOSL authoring or optimization: natural-language-to-query generation, relationship queries, aggregates, query-plan analysis, and performance or safety improvements for Salesforce queries. TRIGGER when: user writes, optimizes, or debugs SOQL/SOSL queries, touches .soql files, or asks about relationship queries, aggregates, or query performance. DO NOT TRIGGER when: bulk data operations (use handling-sf-data), Apex DML logic (use generating-apex), or report/dashboard queries.
app-store-optimization
IncludedApp Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklists, and tracking ranking changes.
habit-flow
IncludedAI-powered atomic habit tracker with natural language logging, streak tracking, smart reminders, and coaching. Use for creating habits, logging completions naturally ("I meditated today"), viewing progress, and getting personalized coaching.
app-store-optimization
IncludedApp Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklists, and tracking ranking changes.
visualizing-data
IncludedBuilds dashboards, reports, and data-driven interfaces requiring charts, graphs, or visual analytics. Provides systematic framework for selecting appropriate visualizations based on data characteristics and analytical purpose. Includes 24+ visualization types organized by purpose (trends, comparisons, distributions, relationships, flows, hierarchies, geospatial), accessibility patterns (WCAG 2.1 AA compliance), colorblind-safe palettes, and performance optimization strategies. Use when creating visualizations, choosing chart types, displaying data graphically, or designing data interfaces.