{
  "schema": "https://ai-atoms.com/schemas/skill-v1.json",
  "type": "skill",
  "id": "skill/compliance-check",
  "version": "1.0.0",
  "name": "compliance-check",
  "description": "Run a compliance check on a proposed action, product feature, or business initiative, surfacing applicable regulations, required approvals, and risk areas. Use when launching a feature that touches personal data, when marketing or product proposes something with regulatory implications, or when you need to know which approvals and jurisdictional requirements apply before proceeding.",
  "system_prompt_fragment": "# /compliance-check -- Compliance Review\n\n> If you see unfamiliar placeholders or need to check which tools are connected, see [CONNECTORS.md](../../CONNECTORS.md).\n\nRun a compliance check on a proposed action, product feature, marketing campaign, or business initiative.\n\n**Important**: This command assists with legal workflows but does not provide legal advice. Compliance assessments should be reviewed by qualified legal professionals. Regulatory requirements change frequently; always verify current requirements with authoritative sources.\n\n## Usage\n\n```\n/compliance-check $ARGUMENTS\n```\n\n## What I Need From You\n\nDescribe what you're planning to do. Examples:\n- \"We want to launch a referral program with cash rewards\"\n- \"We're adding biometric authentication to our mobile app\"\n- \"We need to process EU customer data in our US data center\"\n- \"Marketing wants to use customer testimonials in ads\"\n\n## Output\n\n```markdown\n## Compliance Check: [Initiative]\n\n### Summary\n[Quick assessment: Proceed / Proceed with conditions / Requires further review]\n\n### Applicable Regulations and Policies\n| Regulation/Policy | Relevance | Key Requirements |\n|-------------------|-----------|-----------------|\n| [GDPR / CCPA / HIPAA / etc.] | [How it applies] | [What you need to do] |\n\n### Requirements\n| # | Requirement | Status | Action Needed |\n|---|-------------|--------|---------------|\n| 1 | [Requirement] | [Met / Not Met / Unknown] | [What to do] |\n\n### Risk Areas\n| Risk | Severity | Mitigation |\n|------|----------|------------|\n| [Risk] | [High/Med/Low] | [How to address] |\n\n### Recommended Actions\n1. [Most important action]\n2. [Second priority]\n3. [Third priority]\n\n### Approvals Needed\n| Approver | Why | Status |\n|----------|-----|--------|\n| [Person/Team] | [Reason] | [Pending] |\n\n### Further Review Recommended\n[Areas where outside counsel or specialist review is advised]\n```\n\n## Privacy Regulation Overview\n\n### GDPR (General Data Protection Regulation)\n\n**Scope**: Applies to processing of personal data of individuals in the EU/EEA, regardless of where the processing organization is located.\n\n**Key Obligations for In-House Legal Teams**:\n- **Lawful basis**: Identify and document lawful basis for each processing activity (consent, contract, legitimate interest, legal obligation, vital interest, public task)\n- **Data subject rights**: Respond to access, rectification, erasure, portability, restriction, and objection requests within 30 days (extendable by 60 days for complex requests)\n- **Data protection impact assessments (DPIAs)**: Required for processing likely to result in high risk to individuals\n- **Breach notification**: Notify supervisory authority within 72 hours of becoming aware of a personal data breach; notify affected individuals without undue delay if high risk\n- **Records of processing**: Maintain Article 30 records of processing activities\n- **International transfers**: Ensure appropriate safeguards for transfers outside EEA (SCCs, adequacy decisions, BCRs)\n- **DPO requirement**: Appoint a Data Protection Officer if required (public authority, large-scale processing of special categories, large-scale systematic monitoring)\n\n**Common In-House Legal Touchpoints**:\n- Reviewing vendor DPAs for GDPR compliance\n- Advising product teams on privacy by design requirements\n- Responding to supervisory authority inquiries\n- Managing cross-border data transfer mechanisms\n- Reviewing consent mechanisms and privacy notices\n\n### CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)\n\n**Scope**: Applies to businesses that collect personal information of California residents and meet revenue, data volume, or data sale thresholds.\n\n**Key Obligations**:\n- **Right to know**: Consumers can request disclosure of personal information collected, used, and shared\n- **Right to delete**: Consumers can request deletion of their personal information\n- **Right to opt-out**: Consumers can opt out of the sale or sharing of personal information\n- **Right to correct**: Consumers can request correction of inaccurate personal information (CPRA addition)\n- **Right to limit use of sensitive personal information**: Consumers can limit use of sensitive PI to specific purposes (CPRA addition)\n- **Non-discrimination**: Cannot discriminate against consumers who exercise their rights\n- **Privacy notice**: Must provide a privacy notice at or before collection describing categories of PI collected and purposes\n- **Service provider agreements**: Contracts with service providers must restrict use of PI to the specified business purpose\n\n**Response Timelines**:\n- Acknowledge receipt within 10 business days\n- Respond substantively within 45 calendar days (extendable by 45 days with notice)\n\n### Other Key Regulations to Monitor\n\n| Regulation | Jurisdiction | Key Differentiators |\n|---|---|---|\n| **LGPD** (Brazil) | Brazil | Similar to GDPR; requires DPO appointment; National Data Protection Authority (ANPD) enforcement |\n| **POPIA** (South Africa) | South Africa | Information Regulator oversight; required registration of processing |\n| **PIPEDA** (Canada) | Canada (federal) | Consent-based framework; OPC oversight; being modernized |\n| **PDPA** (Singapore) | Singapore | Do Not Call registry; mandatory breach notification; PDPC enforcement |\n| **Privacy Act** (Australia) | Australia | Australian Privacy Principles (APPs); notifiable data breaches scheme |\n| **PIPL** (China) | China | Strict cross-border transfer rules; data localization requirements; CAC oversight |\n| **UK GDPR** | United Kingdom | Post-Brexit UK version; ICO oversight; similar to EU GDPR with UK-specific adequacy |\n\n## DPA Review Checklist\n\nWhen reviewing a Data Processing Agreement or Data Processing Addendum, verify the following:\n\n### Required Elements (GDPR Article 28)\n\n- [ ] **Subject matter and duration**: Clearly defined scope and term of processing\n- [ ] **Nature and purpose**: Specific description of what processing will occur and why\n- [ ] **Type of personal data**: Categories of personal data being processed\n- [ ] **Categories of data subjects**: Whose personal data is being processed\n- [ ] **Controller obligations and rights**: Controller's instructions and oversight rights\n\n### Processor Obligations\n\n- [ ] **Process only on documented instructions**: Processor commits to process only per controller's instructions (with exception for legal requirements)\n- [ ] **Confidentiality**: Personnel authorized to process have committed to confidentiality\n- [ ] **Security measures**: Appropriate technical and organizational measures described (Article 32 reference)\n- [ ] **Sub-processor requirements**:\n  - [ ] Written authorization requirement (general or specific)\n  - [ ] If general authorization: notification of changes with opportunity to object\n  - [ ] Sub-processors bound by same obligations via written agreement\n  - [ ] Processor remains liable for sub-processor performance\n- [ ] **Data subject rights assistance**: Processor will assist controller in responding to data subject requests\n- [ ] **Security and breach assistance**: Processor will assist with security obligations, breach notification, DPIAs, and prior consultation\n- [ ] **Deletion or return**: On termination, delete or return all personal data (at controller's choice) and delete existing copies unless legal retention required\n- [ ] **Audit rights**: Controller has right to conduct audits and inspections (or accept third-party audit reports)\n- [ ] **Breach notification**: Processor will notify controller of personal data breaches without undue delay (ideally within 24-48 hours; must enable controller to meet 72-hour regulatory deadline)\n\n### International Transfers\n\n- [ ] **Transfer mechanism identified**: SCCs, adequacy decision, BCRs, or other valid mechanism\n- [ ] **SCCs version**: Using current EU SCCs (June 2021 version) if applicable\n- [ ] **Correct module**: Appropriate SCC module selected (C2P, C2C, P2P, P2C)\n- [ ] **Transfer impact assessment**: Completed if transferring to countries without adequacy decisions\n- [ ] **Supplementary measures**: Technical, organizational, or contractual measures to address gaps identified in transfer impact assessment\n- [ ] **UK addendum**: If UK personal data is in scope, UK International Data Transfer Addendum included\n\n### Practical Considerations\n\n- [ ] **Liability**: DPA liability provisions align with (or don't conflict with) the main services agreement\n- [ ] **Termination alignment**: DPA term aligns with the services agreement\n- [ ] **Data locations**: Processing locations specified and acceptable\n- [ ] **Security standards**: Specific security standards or certifications required (SOC 2, ISO 27001, etc.)\n- [ ] **Insurance**: Adequate insurance coverage for data processing activities\n\n### Common DPA Issues\n\n| Issue | Risk | Standard Position |\n|---|---|---|\n| Blanket sub-processor authorization without notification | Loss of control over processing chain | Require notification with right to object |\n| Breach notification timeline > 72 hours | May prevent timely regulatory notification | Require notification within 24-48 hours |\n| No audit rights (or audit rights only via third-party reports) | Cannot verify compliance | Accept SOC 2 Type II + right to audit upon cause |\n| Data deletion timeline not specified | Data retained indefinitely | Require deletion within 30-90 days of termination |\n| No data processing locations specified | Data could be processed anywhere | Require disclosure of processing locations |\n| Outdated SCCs | Invalid transfer mechanism | Require current EU SCCs (2021 version) |\n\n## Data Subject Request Handling\n\n### Request Intake\n\nWhen a data subject request is received:\n\n1. **Identify the request type**:\n   - Access (copy of personal data)\n   - Rectification (correction of inaccurate data)\n   - Erasure / deletion (\"right to be forgotten\")\n   - Restriction of processing\n   - Data portability (structured, machine-readable format)\n   - Objection to processing\n   - Opt-out of sale/sharing (CCPA/CPRA)\n   - Limit use of sensitive personal information (CPRA)\n\n2. **Identify applicable regulation(s)**:\n   - Where is the data subject located?\n   - Which laws apply based on your organization's presence and activities?\n   - What are the specific requirements and timelines?\n\n3. **Verify identity**:\n   - Confirm the requester is who they claim to be\n   - Use reasonable verification measures proportionate to the sensitivity of the data\n   - Do not require excessive documentation\n\n4. **Log the request**:\n   - Date received\n   - Request type\n   - Requester identity\n   - Applicable regulation\n   - Response deadline\n   - Assigned handler\n\n### Response Timelines\n\n| Regulation | Initial Acknowledgment | Substantive Response | Extension |\n|---|---|---|---|\n| GDPR | Not specified (best practice: promptly) | 30 days | +60 days (with notice) |\n| CCPA/CPRA | 10 business days | 45 calendar days | +45 days (with notice) |\n| UK GDPR | Not specified (best practice: promptly) | 30 days | +60 days (with notice) |\n| LGPD | Not specified | 15 days | Limited extensions |\n\n### Exemptions and Exceptions\n\nBefore fulfilling a request, check whether any exemptions apply:\n\n**Common exemptions across regulations**:\n- Legal claims defense or establishment\n- Legal obligations requiring retention\n- Public interest or official authority\n- Freedom of expression and information (for erasure requests)\n- Archiving in the public interest or scientific/historical research\n\n**Organization-specific considerations**:\n- Litigation hold: Data subject to a legal hold cannot be deleted\n- Regulatory retention: Financial records, employment records, and other categories may have mandatory retention periods\n- Third-party rights: Fulfilling the request might adversely affect the rights of others\n\n### Response Process\n\n1. Gather all personal data of the requester across systems\n2. Apply any exemptions and document the basis\n3. Prepare response: fulfill the request or explain why (in whole or part) it cannot be fulfilled\n4. If denying (in whole or part): cite the specific legal basis for denial\n5. Inform the requester of their right to lodge a complaint with the supervisory authority\n6. Document the response and retain records of the request and response\n\n## Regulatory Monitoring Basics\n\n### What to Monitor\n\nMaintain awareness of developments in:\n- **Regulatory guidance**: New or updated guidance from supervisory authorities (ICO, CNIL, FTC, state AGs, etc.)\n- **Enforcement actions**: Fines, orders, and settlements that signal regulatory priorities\n- **Legislative changes**: New privacy laws, amendments to existing laws, implementing regulations\n- **Industry standards**: Updates to ISO 27001, SOC 2, NIST frameworks, and sector-specific requirements\n- **Cross-border transfer developments**: Adequacy decisions, SCC updates, data localization requirements\n\n### Monitoring Approach\n\n1. **Subscribe to regulatory authority communications** (newsletters, RSS feeds, official announcements)\n2. **Track relevant legal publications** for analysis of new developments\n3. **Review industry association updates** for sector-specific guidance\n4. **Maintain a regulatory calendar** of known upcoming deadlines, effective dates, and compliance milestones\n5. **Brief the legal team** on material developments that affect the organization's processing activities\n\n### Escalation Criteria\n\nEscalate regulatory developments to senior counsel or leadership when:\n- A new regulation or guidance directly affects the organization's core business activities\n- An enforcement action in the organization's sector signals heightened regulatory scrutiny\n- A compliance deadline is approaching that requires organizational changes\n- A data transfer mechanism the organization relies on is challenged or invalidated\n- A regulatory authority initiates an inquiry or investigation involving the organization\n\n## Tips\n\n1. **Be specific** — \"We want to email all our users\" is better than \"marketing campaign.\"\n2. **Include the geography** — Compliance requirements vary by jurisdiction.\n3. **Mention the data** — What personal data is involved? This drives most compliance requirements.",
  "applicable_domains": [
    "legal",
    "compliance"
  ],
  "invocation": [
    "/compliance-check",
    "/compliance-check <action or initiative to check>"
  ],
  "tags": [
    "legal",
    "anthropics",
    "knowledge-work"
  ],
  "authored_by": "anthropics",
  "source_url": "https://github.com/anthropics/knowledge-work-plugins/blob/main/legal/skills/compliance-check/SKILL.md",
  "lifecycle": "stable",
  "category": "legal",
  "provenance": {
    "source": "anthropics/knowledge-work-plugins",
    "source_url": "https://github.com/anthropics/knowledge-work-plugins/blob/main/legal/skills/compliance-check/SKILL.md",
    "author": "Anthropic",
    "license": "Apache-2.0",
    "notes": "Imported by scripts/import-anthropic-skills.py."
  }
}