Skills on AI

Active theme: Light

Legal Data Privacy Compliance

Use when asked about legal data privacy compliance — meeting obligations under data protection laws (such as GDPR, CCPA, and similar regimes) for collecting, using, and protecting personal data — as a specific, commonly audited compliance area.

Data privacy compliance covers an organization's legal obligations for collecting, using, storing, and protecting personal data under applicable data protection law — a landscape of multiple, sometimes overlapping regimes (such as the EU's GDPR, California's CCPA/CPRA, and similar laws in other jurisdictions) rather than one universal standard.

Common core obligations across regimes

  • Lawful basis for processing — many regimes require a specific, identifiable legal basis (consent, contractual necessity, legitimate interest, and others) for collecting and using personal data.
  • Transparency — informing individuals what data is collected and how it's used, typically via a privacy notice/policy (see Privacy Policy).
  • Data subject rights — many regimes grant individuals rights to access, correct, delete, or port their own data, which the organization must be able to fulfill within specified timeframes.
  • Security safeguards — reasonable technical and organizational measures to protect personal data from unauthorized access or disclosure.
  • Breach notification — many regimes require notifying regulators and affected individuals within a specified (often short) timeframe after discovering a data breach.

Why "one universal standard" is a myth

Data privacy law varies significantly by jurisdiction — in scope, specific obligations, and enforcement — and a compliance program built around only one regime's requirements can miss obligations under another that applies to the same data or activity (for instance, a company serving both EU and California residents).

Common pitfalls

  • Assuming compliance with one regime satisfies all applicable regimes — different jurisdictions impose different, sometimes conflicting, requirements on the same data.
  • Privacy notices that don't match actual data practices — a privacy policy describing data practices the organization doesn't actually follow is itself a compliance and enforcement risk.
  • Missing breach notification deadlines — many regimes impose short, strict windows (sometimes 72 hours or less) for notifying regulators after discovering a breach.
  • No process for fulfilling data subject rights requests — having a policy stating individuals have these rights, without an actual operational process to fulfill requests within required timeframes, is a common and risky gap.

Learn more

View legal-data-privacy-compliance/SKILL.md on GitHub