- Home
- Skills
- Finance & Accounting
- privacy compliance navigator
Works with the AI tools you already use
privacy compliance navigator
Multi-regulation privacy compliance scoping, DSR lifecycle support, and DPA gap analysis.
$12
privacy compliance navigator
Example session with this skill installed
Perform a DPA review for a new analytics vendor. We are the Controller (UK-based) and they are a Processor (US-based). They process customer email and web behavior. Review for UK GDPR gaps.
- Read your context and instructions
- Compiled the privacy compliance navigator
- Generated the document
I have reviewed the relationship between the UK Controller and US Processor regarding customer analytics data. The following analysis identifies gaps based on standard UK GDPR requirements for Article 28 compliance and international transfers.
DPA Review Issue Log: Analytics Vendor
| Issue Area | Finding | Rationale | Severity | Proposed Action |
|---|---|---|---|---|
| International Transfer | No UK Addendum or IDTA referenced for US transfer. | Data is leaving the UK for a US-based processor without a valid transfer mechanism identified. | High | Insert UK Addendum to the EU SCCs or a standalone IDTA. |
| Sub-processing | Vendor has general authorization for sub-processors without a notice period. | UK GDPR requires the controller to have the opportunity to object to specific changes. | Medium | Define a 30-day prior notice period for new sub-processor appointments. |
| Breach Notification | Vendor proposes "72 hours after final internal confirmation." | Regulatory clocks start upon 'becoming aware', and processors must notify 'without undue delay'. | High | Redline to "without undue delay and no later than 48 hours after becoming aware." |
| Audit Rights | Audit limited to once every 3 years or on 'demonstrable evidence' of breach. | Controllers must be able to verify compliance; overly restrictive terms may fail Art 28(3)(h). | Medium | Negotiate annual audit rights or acceptance of independent third-party SOC2 reports. |
| Data Deletion | Vague "standard retention policy" applied to customer emails. | Specific instructions for return or deletion at the end of service are required. | Low | Specify deletion within 30 days of contract termination. |
Assumptions
- The UK Addendum has not been previously executed under a Master Service Agreement.
- The "web behavior" data includes PII (IP addresses/cookies) alongside emails.
Next steps
- Confirm if the vendor is certified under the Data Privacy Framework (DPF) for UK-US transfers.
- Request the vendor's Annex II technical and organizational security measures (TOMs).
- Submit this log to Legal Counsel for final redlining of the vendor's MSA.
privacy-compliance-navigator.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Managing global privacy compliance involves tracking fragmented regulations across multiple jurisdictions. Manually mapping GDPR, CCPA, and LGPD requirements to specific processing activities is slow and prone to oversight.
What it does
- Generates privacy applicability matrices comparing requirements across GDPR, CCPA, LGPD, PIPL, and other major frameworks.
- Structures Data Subject Request (DSR) workflows including identity verification steps and regulatory deadline tracking.
- Performs automated DPA and vendor contract reviews to flag gaps in breach notification, audit rights, and data transfer clauses.
- Builds privacy-by-design checkpoints for SDLC, procurement, and AI deployment lifecycles.
Why this beats prompting it yourself
General-purpose prompts often miss jurisdictional nuances or hallucinate statutory deadlines. This skill enforces a strict evidence-based discipline, separating facts from assumptions and flagging every claim that requires specific legal validation to ensure professional-grade output.
Use cases
- Conducting a multi-jurisdiction privacy impact assessment for a new SaaS product launch.
- Auditing a vendor Data Processing Agreement (DPA) against corporate privacy standards.
- Developing a privacy programme maturity roadmap for board-level reporting.
- Structuring a privacy incident response plan that integrates with existing cyber workflows.
Known limitations
This skill provides structured analysis and scoping only. It does not provide legal advice, binding statutory interpretations, or final breach notification decisions.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install