skills/legal/cyber-law-compliance-summary/SKILL.md
Produces structured cyber law compliance memoranda covering GDPR, CCPA, state privacy laws, and sector-specific regulations for US and EU operations. Includes Bluebook citations, jurisdiction comparison tables, penalty exposure, and regulatory trends. Use when advising on digital operations compliance, privacy program design, incident response readiness, or preparing compliance gap assessments.
npx skillsauth add casemark/skills cyber-law-compliance-summaryInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a jurisdiction-tailored compliance memorandum translating GDPR, CCPA, and applicable cyber law obligations into actionable business guidance. Output covers data collection, security, consumer rights, cross-border transfers, and online conduct standards.
Gather before drafting:
Use this template for each section:
| Element | Content | |---|---| | Legal Requirement | Statutory/regulatory citation (Bluebook) | | Business Obligation | What the business must do | | Required Documentation | Policies, records, contracts needed | | Penalty / Enforcement | Fines, enforcement trends, recent actions |
Sections to cover:
| # | Topic | Key Authorities |
|---|---|---|
| 1 | Data Collection & Processing | GDPR Arts. 5–6, 13–14; CCPA §1798.100; state equivalents |
| 2 | Security & Breach Notification | GDPR Arts. 32–33; Cal. Civ. Code §1798.82; NIST CSF [VERIFY] |
| 3 | Consumer Rights & Transparency | GDPR Arts. 15–22; CCPA §§1798.110–.125; CAN-SPAM; COPPA |
| 4 | Cross-Border Data Transfers | GDPR Arts. 44–49; SCCs (2021); EU-U.S. Data Privacy Framework |
| 5 | Online Conduct Standards | FTC Act §5; TCPA; state consumer protection statutes |
When multiple jurisdictions apply, produce side-by-side:
| Obligation | GDPR (EU) | CCPA/CPRA (CA) | [Other State] | |---|---|---|---| | Consent basis | Lawful basis required | Opt-out (sensitive: opt-in) | … | | Breach notification | 72 hrs to DPA | 72 hrs if 500+ CA residents | … | | Data subject rights | Access, erasure, portability | Access, deletion, opt-out of sale | … |
| Category | Governing Law | Heightened Requirement | |---|---|---| | Health / medical | HIPAA, GDPR Art. 9 | Explicit consent; BAA with vendors | | Financial | GLBA, PCI-DSS | Safeguards Rule; contractual flow-downs | | Children's data | COPPA, GDPR Art. 8 | Verifiable parental consent | | Biometric | IL BIPA, TX/WA statutes | Written consent; retention limits |
[VERIFY]Key changes from the original:
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.