Data Protection

Skill packages tagged with “Data Protection”

CCPA/CPRA Privacy Program — Compliance Documentation Package

Draft and validate the core privacy compliance documentation package required under the California Consumer Privacy Act as amended by CPRA. Covers the privacy policy, DSAR procedures, data inventory, privacy impact assessment, opt-out mechanisms, and service provider/contractor agreements.

    Learn More
    Data Privacy — AIPD (CNIL Standard)

    Conduct a Privacy Impact Assessment (AIPD) under the CNIL standard for France (RGPD). Three-step methodology: Context, Principles, Risks. Validates retention periods against CNIL 'droit à l'oubli' (right to erasure).

      Learn More
      Data Processing Agreement (DPA) — SCC & sub-processor sync

      Draft the legal annex for DPAs governing controller–processor data transfers under GDPR and CCPA. Inserts the correct Standard Contractual Clauses by data importer country and validates sub-processor list against the privacy portal.

        Learn More
        DPC Cross-Border Data Processing (Lead SSA)

        Draft Article 30 Records of Processing Activities for US firms using Ireland as Lead Supervisory Authority. Covers main establishment justification (GDPR Art. 4(16), EDPB criteria) and validation so the Irish DPC remains the competent authority.

          Learn More
          GDPR Consent Form (Art. 7)

          Draft consent forms and consent notices for personal data processing under GDPR Article 7. Covers all conditions for valid consent: freely given, specific, informed, unambiguous. Includes validation against EDPB Guidelines 05/2020.

            Learn More
            GDPR Gap Assessment

            Perform a structured gap assessment against GDPR (Regulation 2016/679). Mandatory artifact detector scans for missing compliance documents; maturity rater suggests 0-5 maturity per domain across all compliance domains (principles, lawful basis, transparency, data subject rights including Art. 19, controller obligations, security, breach notification, DPIA including Art. 36 prior consultation, DPO governance, processor management, international transfers, training). Produces findings register and prioritized remediation roadmap with Art. 83 fine tier analysis.

              Learn More
              GDPR Legitimate Interest Assessment (Art. 6(1)(f))

              Conduct a three-part Legitimate Interest Assessment (LIA) under GDPR Art. 6(1)(f): purpose test, necessity test, and balancing test. Validates against EDPB Opinion 08/2024, WP217, and CJEU case law (Rigas, Fashion ID, Meta/Bundeskartellamt).

                Learn More
                GDPR Privacy by Design & Default (Art. 25)

                Assess and document data protection by design and by default measures per GDPR Article 25 and EDPB Guidelines 4/2019. Covers the seven foundational principles, Hoepman's eight design strategies, Art. 25(2) four-dimension default settings review, controller/processor scope, DPIA necessity assessment (EDPB WP248 rev.01), and organisational measures.

                  Learn More
                  GDPR ROPA & DPIA Author

                  Guided elaboration of Records of Processing Activities (ROPA) and Data Protection Impact Assessments (DPIA): processing purposes, legal basis, data categories, recipients, retention, safeguards, and DPIA necessity assessment and risk mitigation.

                    Learn More
                    GDPR Vendor & Processor Audit (Art. 28)

                    Plan and document processor audits under GDPR Art. 28(3)(h). Covers Art. 28(3)(a-h) contract compliance, sub-processor chain review, international transfer assessment (SCCs, adequacy, BCRs, TIA), Art. 32 technical measures evaluation, Art. 28(5) certification review, and corrective action tracking.

                      Learn More
                      India DPDP Act — Data Protection Impact Assessment

                      Draft and validate a Data Protection Impact Assessment for Significant Data Fiduciaries under India's Digital Personal Data Protection Act 2023. Covers processing inventory, consent framework, data principal rights, and cross-border transfers.

                        Learn More
                        Japan APPI — Privacy Impact Assessment

                        Draft and validate a Privacy Impact Assessment for processing under Japan's Act on the Protection of Personal Information (APPI, amended 2022). Covers data categorisation, cross-border transfer assessment, and PPC guidelines compliance.

                          Learn More
                          King IV and POPIA Narrative

                          Draft the POPIA–King IV governance narrative linking data protection compliance to King IV Principles 12 and 13 for South African organisations.

                            Learn More
                            Multi-Jurisdiction Data Processing Agreement (GDPR + CCPA + UK)

                            Draft an integrated Data Processing Agreement covering EU GDPR Article 28, EU Standard Contractual Clauses (SCCs), UK IDTA or UK Addendum, and US state privacy laws (CCPA/CPRA, CPA, VCDPA). Includes jurisdiction checker, SCC module selection, and Transfer Impact Assessment.

                              Learn More
                              PDPA — Data Protection Management Programme (Singapore)

                              Draft and validate the Data Protection Management Programme (DPMP) required by Singapore's Personal Data Protection Act 2012. Covers governance, data inventory, DPIA, breach management plan, and DPO appointment per PDPC guidance.

                                Learn More
                                PIIA (SA) — Risk Assessment

                                Draft the risk assessment for a POPIA PIIA: analyse risks to data subjects' rights and freedoms, including harm, discrimination, and financial loss.

                                  Learn More
                                  PIIA (SA) — Systematic Description of Processing

                                  Draft the systematic description of processing for a POPIA PIIA: step-by-step description of how personal information is collected, used, stored, and deleted.

                                    Learn More
                                    POPIA Compliance Framework — Manual & PAIA Manual (South Africa)

                                    Draft and validate POPIA (Act 4 of 2013) compliance framework documentation and the mandatory PAIA Manual. Covers the eight conditions for lawful processing, PAIA manual, Information Officer registration, and breach notification.

                                      Learn More
                                      Saudi PDPL — Personal Data Protection Assessment

                                      Draft and validate data protection compliance documentation under Saudi Arabia's Personal Data Protection Law (Royal Decree M/19 of 2021, amended 2023) and its Implementing Regulations. Covers data inventory, consent, cross-border transfers, and 72-hour breach notification.

                                        Learn More
                                        UAE Federal PDPL — Data Protection Impact Assessment

                                        Draft and validate a DPIA under UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data (PDPL) and its Executive Regulations. Covers data inventory, lawful basis, cross-border transfers, and 72-hour breach notification.

                                          Learn More
                                          UK GDPR & DPIA (Data Protection)

                                          Conduct and validate Data Protection Impact Assessments (DPIAs) under the UK GDPR and ICO guidance for high-risk processing. Suggests technical and organisational safeguards aligned with UK Adequacy standards. Validates breach-notification policies against the 72-hour ICO reporting window.

                                            Learn More
                                            Whistleblower System Design (HinSchG)

                                            Erstellt Verfahrensordnungen fuer interne Meldestellen gemaess dem Hinweisgeberschutzgesetz (HinSchG). Validiert Pflichtabschnitte, gesetzliche Fristen (7 Tage Eingangsbestaetigung, 3 Monate Rueckmeldung) und die 3-Jahres-Loeschfrist.

                                              Learn More
                                              Works Council Agreements (BetrVG)

                                              Negotiation-based drafting and validation of Betriebsvereinbarungen (Works Agreements) for IT systems under the Betriebsverfassungsgesetz (BetrVG). Ensures Leistungs- und Verhaltenskontrolle (performance and behavior monitoring) clauses comply with §87 Abs. 1 Nr. 6 BetrVG and validates BDSG §26 / DSGVO Art. 88 alignment for employee data protection.

                                                Learn More

                                                Ready to let your expertise drive the workflow?

                                                Stop wrestling with rigid templates and generic chatbots. Describe your process, let the agent handle the rest.

                                                Get Started Free — No Sign-Up