Privacy

Skill packages tagged with “Privacy”

Canada Privacy & PIA

Guide to Canadian privacy law (PIPEDA, provincial private-sector laws, Bill C-27 status) and Privacy Impact Assessments for federal and private-sector data handling. Use with privacy_impact_validator to elaborate PIAs.

    Learn More
    CCPA/CPRA Privacy Program — Compliance Documentation Package

    Draft and validate the core privacy compliance documentation package required under the California Consumer Privacy Act as amended by CPRA. Covers the privacy policy, DSAR procedures, data inventory, privacy impact assessment, opt-out mechanisms, and service provider/contractor agreements.

      Learn More
      Data Privacy — AIPD (CNIL Standard)

      Conduct a Privacy Impact Assessment (AIPD) under the CNIL standard for France (RGPD). Three-step methodology: Context, Principles, Risks. Validates retention periods against CNIL 'droit à l'oubli' (right to erasure).

        Learn More
        Data Processing Agreement (DPA) — SCC & sub-processor sync

        Draft the legal annex for DPAs governing controller–processor data transfers under GDPR and CCPA. Inserts the correct Standard Contractual Clauses by data importer country and validates sub-processor list against the privacy portal.

          Learn More
          DPC Cross-Border Data Processing (Lead SSA)

          Draft Article 30 Records of Processing Activities for US firms using Ireland as Lead Supervisory Authority. Covers main establishment justification (GDPR Art. 4(16), EDPB criteria) and validation so the Irish DPC remains the competent authority.

            Learn More
            FERPA Compliance Documentation — Student Records Policy

            Draft and validate FERPA compliance documentation: annual notification, directory information policy, records access and amendment, disclosure log, and school official exception for edtech vendors per 34 CFR Part 99.

              Learn More
              GDPR ROPA & DPIA Author

              Guided elaboration of Records of Processing Activities (ROPA) and Data Protection Impact Assessments (DPIA): processing purposes, legal basis, data categories, recipients, retention, safeguards, and DPIA necessity assessment and risk mitigation.

                Learn More
                India DPDP Act — Data Protection Impact Assessment

                Draft and validate a Data Protection Impact Assessment for Significant Data Fiduciaries under India's Digital Personal Data Protection Act 2023. Covers processing inventory, consent framework, data principal rights, and cross-border transfers.

                  Learn More
                  ISO 27701 PIMS Extension Author

                  Guided elaboration of PIMS documentation as an extension to ISMS: PII processing inventory, privacy objectives, processing purposes and legal basis, and controller/processor annex controls.

                    Learn More
                    Japan APPI — Privacy Impact Assessment

                    Draft and validate a Privacy Impact Assessment for processing under Japan's Act on the Protection of Personal Information (APPI, amended 2022). Covers data categorisation, cross-border transfer assessment, and PPC guidelines compliance.

                      Learn More
                      NDB Incident Drafter

                      Draft and validate the Statement to the Commissioner and Notification to Individuals under Australia's Notifiable Data Breaches (NDB) scheme. Ensures the four mandatory sections under Privacy Act s 26WK are present and supports assessment of likelihood of serious harm by data type (e.g. TFN, Medicare).

                        Learn More
                        PDPA — Data Protection Management Programme (Singapore)

                        Draft and validate the Data Protection Management Programme (DPMP) required by Singapore's Personal Data Protection Act 2012. Covers governance, data inventory, DPIA, breach management plan, and DPO appointment per PDPC guidance.

                          Learn More
                          PIPEDA Privacy Management Framework

                          Draft and validate the Privacy Management Framework documentation for compliance with Canada's PIPEDA and the ten CSA Model Code principles. Covers privacy governance, PIA, breach reporting, and cross-border transfer documentation.

                            Learn More
                            POPIA Compliance Framework — Manual & PAIA Manual (South Africa)

                            Draft and validate POPIA (Act 4 of 2013) compliance framework documentation and the mandatory PAIA Manual. Covers the eight conditions for lawful processing, PAIA manual, Information Officer registration, and breach notification.

                              Learn More
                              Saudi PDPL — Personal Data Protection Assessment

                              Draft and validate data protection compliance documentation under Saudi Arabia's Personal Data Protection Law (Royal Decree M/19 of 2021, amended 2023) and its Implementing Regulations. Covers data inventory, consent, cross-border transfers, and 72-hour breach notification.

                                Learn More
                                UAE Federal PDPL — Data Protection Impact Assessment

                                Draft and validate a DPIA under UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data (PDPL) and its Executive Regulations. Covers data inventory, lawful basis, cross-border transfers, and 72-hour breach notification.

                                  Learn More
                                  UK GDPR & DPIA (Data Protection)

                                  Conduct and validate Data Protection Impact Assessments (DPIAs) under the UK GDPR and ICO guidance for high-risk processing. Suggests technical and organisational safeguards aligned with UK Adequacy standards. Validates breach-notification policies against the 72-hour ICO reporting window.

                                    Learn More

                                    Ready to let your expertise drive the workflow?

                                    Stop wrestling with rigid templates and complex tooling. Write your process in markdown, let the agent handle the rest.

                                    Get Started