skills/legal/cyber-law-compliance-summary/SKILL.md
Produces structured cyber law compliance memoranda covering GDPR, CCPA, state privacy laws, and sector-specific regulations for US and EU operations. Includes Bluebook citations, jurisdiction comparison tables, penalty exposure, and regulatory trends. Use when advising on digital operations compliance, privacy program design, incident response readiness, or preparing compliance gap assessments.
npx skillsauth add casemark/skills cyber-law-compliance-summaryInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a jurisdiction-tailored compliance memorandum translating GDPR, CCPA, and applicable cyber law obligations into actionable business guidance. Output covers data collection, security, consumer rights, cross-border transfers, and online conduct standards.
Gather before drafting:
Use this template for each section:
| Element | Content | |---|---| | Legal Requirement | Statutory/regulatory citation (Bluebook) | | Business Obligation | What the business must do | | Required Documentation | Policies, records, contracts needed | | Penalty / Enforcement | Fines, enforcement trends, recent actions |
Sections to cover:
| # | Topic | Key Authorities |
|---|---|---|
| 1 | Data Collection & Processing | GDPR Arts. 5–6, 13–14; CCPA §1798.100; state equivalents |
| 2 | Security & Breach Notification | GDPR Arts. 32–33; Cal. Civ. Code §1798.82; NIST CSF [VERIFY] |
| 3 | Consumer Rights & Transparency | GDPR Arts. 15–22; CCPA §§1798.110–.125; CAN-SPAM; COPPA |
| 4 | Cross-Border Data Transfers | GDPR Arts. 44–49; SCCs (2021); EU-U.S. Data Privacy Framework |
| 5 | Online Conduct Standards | FTC Act §5; TCPA; state consumer protection statutes |
When multiple jurisdictions apply, produce side-by-side:
| Obligation | GDPR (EU) | CCPA/CPRA (CA) | [Other State] | |---|---|---|---| | Consent basis | Lawful basis required | Opt-out (sensitive: opt-in) | … | | Breach notification | 72 hrs to DPA | 72 hrs if 500+ CA residents | … | | Data subject rights | Access, erasure, portability | Access, deletion, opt-out of sale | … |
| Category | Governing Law | Heightened Requirement | |---|---|---| | Health / medical | HIPAA, GDPR Art. 9 | Explicit consent; BAA with vendors | | Financial | GLBA, PCI-DSS | Safeguards Rule; contractual flow-downs | | Children's data | COPPA, GDPR Art. 8 | Verifiable parental consent | | Biometric | IL BIPA, TX/WA statutes | Written consent; retention limits |
[VERIFY]Key changes from the original:
development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.