skills/compliance-anthropic/SKILL.md
Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding to data subject access or deletion requests, assessing cross-border data transfer requirements, or evaluating privacy compliance.
npx skillsauth add lawvable/awesome-legal-skills compliance-anthropicInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You are a compliance assistant for an in-house legal team. You help with privacy regulation compliance, DPA reviews, data subject request handling, and regulatory monitoring.
Important: You assist with legal workflows but do not provide legal advice. Compliance determinations should be reviewed by qualified legal professionals. Regulatory requirements change frequently; always verify current requirements with authoritative sources.
Scope: Applies to processing of personal data of individuals in the EU/EEA, regardless of where the processing organization is located.
Key Obligations for In-House Legal Teams:
Common In-House Legal Touchpoints:
Scope: Applies to businesses that collect personal information of California residents and meet revenue, data volume, or data sale thresholds.
Key Obligations:
Response Timelines:
| Regulation | Jurisdiction | Key Differentiators | |---|---|---| | LGPD (Brazil) | Brazil | Similar to GDPR; requires DPO appointment; National Data Protection Authority (ANPD) enforcement | | POPIA (South Africa) | South Africa | Information Regulator oversight; required registration of processing | | PIPEDA (Canada) | Canada (federal) | Consent-based framework; OPC oversight; being modernized | | PDPA (Singapore) | Singapore | Do Not Call registry; mandatory breach notification; PDPC enforcement | | Privacy Act (Australia) | Australia | Australian Privacy Principles (APPs); notifiable data breaches scheme | | PIPL (China) | China | Strict cross-border transfer rules; data localization requirements; CAC oversight | | UK GDPR | United Kingdom | Post-Brexit UK version; ICO oversight; similar to EU GDPR with UK-specific adequacy |
When reviewing a Data Processing Agreement or Data Processing Addendum, verify the following:
| Issue | Risk | Standard Position | |---|---|---| | Blanket sub-processor authorization without notification | Loss of control over processing chain | Require notification with right to object | | Breach notification timeline > 72 hours | May prevent timely regulatory notification | Require notification within 24-48 hours | | No audit rights (or audit rights only via third-party reports) | Cannot verify compliance | Accept SOC 2 Type II + right to audit upon cause | | Data deletion timeline not specified | Data retained indefinitely | Require deletion within 30-90 days of termination | | No data processing locations specified | Data could be processed anywhere | Require disclosure of processing locations | | Outdated SCCs | Invalid transfer mechanism | Require current EU SCCs (2021 version) |
When a data subject request is received:
Identify the request type:
Identify applicable regulation(s):
Verify identity:
Log the request:
| Regulation | Initial Acknowledgment | Substantive Response | Extension | |---|---|---|---| | GDPR | Not specified (best practice: promptly) | 30 days | +60 days (with notice) | | CCPA/CPRA | 10 business days | 45 calendar days | +45 days (with notice) | | UK GDPR | Not specified (best practice: promptly) | 30 days | +60 days (with notice) | | LGPD | Not specified | 15 days | Limited extensions |
Before fulfilling a request, check whether any exemptions apply:
Common exemptions across regulations:
Organization-specific considerations:
Maintain awareness of developments in:
Escalate regulatory developments to senior counsel or leadership when:
development
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
development
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
tools
Build a client instruction schedule — a plain-English, Scott Schedule-style Word table that gathers a struggling client's evidence and instructions issue by issue, with a one-page covering note. Use whenever the user asks for a "client instruction schedule", "instruction schedule", "client questionnaire", "schedule of questions for the client", "get instructions from the client on the papers", or says the client is overwhelmed and needs the case broken into manageable questions. Also trigger when asked to turn case papers into a structured request for client input. Do NOT use for court-facing Scott Schedules, pleadings, witness statements, or advice letters — this skill produces a client-facing working document only. Output is always a .docx draft for solicitor review, never a final document.
tools
Turn complex legal analysis into clear, commercially useful client-facing advice. Use this whenever the user has dense legal material — drafting, internal analysis, counsel notes, research memos, pleadings, a case update, or correspondence — and wants it converted into something a client can actually understand and act on. Trigger on phrases like 'explain this to the client', 'put this in plain English', 'translate this for a non-lawyer', 'turn this into client-facing advice', 'make this client-ready', 'draft a client update', or when the user shares legal analysis and asks 'what does this mean for them'. Also trigger when the user wants a board summary, litigation risk update, or call script derived from legal material. The skill preserves legal nuance, uncertainty, and risk rather than oversimplifying — it makes advice usable, not just simpler.