skills/data-privacy-law-explainer/SKILL.md
Explain U.S. state-by-state consumer data-privacy law (CCPA/CPRA, TDPSA, VCDPA, CPA, and the other comprehensive state acts) — who a law covers, applicability thresholds, privacy-policy requirements, consumer rights and opt-outs, private rights of action, and who enforces. Reads a bundled, source-cited snapshot per state. Use when the user says "CCPA," "CPRA," "state privacy law," "privacy policy," "data subject request," "consumer rights request," "opt-out of sale," "data broker," "sensitive data," asks "do I need to comply with <state>'s privacy law," or names a U.S. state together with privacy.
npx skillsauth add open-agreements/open-agreements data-privacy-law-explainerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Explain how a given U.S. state's comprehensive consumer-privacy law works, using bundled, source-cited practice notes. This skill explains what the law says — it does not give legal advice or render a compliance verdict on the user's own business or program.
snapshotAsOf date. Privacy law
moves fast (amendments, regulations, enforcement guidance). Always point the
user to the canonical URL to confirm currency.Use this skill when the user wants to understand state consumer-privacy law, e.g.:
manifest.json (at this skill's root). If they don't name one, ask which
state — and note that coverage is rolling out (see Coverage below).content/<slug>.md — and only that file.
Do not load other jurisdictions. (References stay one level deep.)snapshotAsOf and
lastReviewed, and surface any baked > [!WARNING] staleness block verbatim.canonicalUrl with the host agent's web access to check for changes. Ask
each time, and never send the user's facts, data inventory, or policies
upstream — fetch only the fixed canonical URL.When a user asks whether their own business must comply, or whether their program/policy is compliant:
The bundled states are listed in manifest.json at this skill's root (each
entry has slug, jurisdiction, countryCode, snapshotAsOf,
lastReviewed, and a stale flag). Coverage is rolling out state by state —
read that file to enumerate what's available before answering a "which states
do you cover?" question.
open-agreements/open-agreements@data-privacy-agreement
(install: npx skills add open-agreements/open-agreements).open-agreements/open-agreements@non-compete-contract-explainer.content/<slug>.md
carries its own attribution and canonical link.development
Explain U.S. state-by-state (and select international) non-compete and restrictive-covenant law — whether a non-compete is enforceable, blue-pencil reformation, tolling, choice of law, independent-contractor reach, and recent bans. Reads a bundled, source-cited snapshot per jurisdiction. Use when the user says "non-compete," "noncompete contract," "restrictive covenant," "non-solicit," "garden leave," "covenant not to compete," "employment agreement," asks "is my non-compete enforceable," or names a U.S. state.
development
Convert plain markdown contract drafts into OpenAgreements' canonical template.md authoring format — YAML frontmatter, Kind|Label|Value|Show When cover-term tables, oa:clause directives, [[Defined Term]] paragraphs, and oa:signer directives that compile to validated JSON specs and DOCX artifacts. Use when the user says "convert this to canonical markdown," "author a new OpenAgreements template," "migrate template to template.md," or "write a canonical-form contract."
testing
Draft and fill NVCA model documents — stock purchase agreement, certificate of incorporation, investors rights agreement, voting agreement, ROFR, co-sale, indemnification, management rights letter. Series A and venture financing templates. Produces signable DOCX files. Use when user says "Series A documents," "NVCA," "stock purchase agreement," "investors rights agreement," "voting agreement," or "venture financing docs."
development
Assess SOC 2 Type II readiness. Map Trust Services Criteria to controls, identify gaps, and build a remediation plan. Uses NIST SP 800-53 (public domain) as canonical reference with SOC 2 criterion cross-mapping. Use when user says "SOC 2 readiness," "SOC 2 preparation," "SOC 2 gap analysis," or "prepare for SOC 2 audit."