compliance

Provide GDPR, CCPA/CPRA, and UK GDPR compliance guidance for in-house legal teams.

Updated Apr 16, 2026
One-click install
npx skills add https://github.com/yethikrishna/humble --skill compliance-yethikrishna
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance
Source: https://github.com/yethikrishna/humble/tree/main/core/kortix-master/opencode/skills/GENERAL-KNOWLEDGE-WORKER/compliance
Command: npx skills add https://github.com/yethikrishna/humble --skill compliance-yethikrishna

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps in-house legal teams reduce risk and operational friction when managing privacy obligations by providing concise guidance, checklists, and review recommendations for data protection regulation compliance and data subject requests.

Core Features & Use Cases

  • DPA Review Checklist: Clause-level guidance for Article 28 compliance, sub-processor controls, breach notification timelines, international transfer mechanisms, liability and termination alignment.
  • Data Subject Request Handling: Intake, verification, logging, applicable-law determination, timelines, exemptions, and documented response procedures for access, rectification, erasure, portability, and opt-outs.
  • Regulatory Monitoring & Escalation: Guidance on monitoring supervisory authority guidance, enforcement trends, legislative changes, and when to escalate to senior counsel.
  • Use Case: Have the assistant review a vendor DPA, highlight GDPR risks, propose contract edits, and list operational actions needed to remediate gaps.

Quick Start

Ask the compliance assistant to review the attached vendor DPA and provide a GDPR risk summary, required clause edits, and recommended operational controls.

Frequently Asked Questions about compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a vendor DPA for GDPR compliance risks?

Reviewing a vendor DPA for GDPR compliance involves evaluating Article 28 clauses, sub-processor controls, breach notification timelines, and liability alignment. The assistant provides clause-level recommendations, operational gap remediation actions, and specific contract edits to reduce privacy risk.

What is the process for handling GDPR data subject requests?

Handling GDPR data subject requests requires structured intake, identity verification, and logging. The assistant delivers actionable workflows for access, rectification, erasure, portability, and opt-outs, including applicable-law determination, exemptions, timelines, and documented response procedures.

How do I manage cross-border data transfer assessments for privacy compliance?

Managing cross-border data transfer assessments requires evaluating international transfer mechanisms under GDPR, CCPA/CPRA, and UK GDPR. The assistant provides actionable checklists and guidance for in-house legal teams to determine appropriate transfer safeguards and maintain regulatory compliance.

Can I use this for both GDPR and CCPA/CPRA compliance guidance?

Yes, you can use this for both GDPR and CCPA/CPRA compliance. The assistant supports DPA reviews, data subject request handling, and breach notification procedures across GDPR, CCPA/CPRA, UK GDPR, and similar privacy laws, delivering actionable checklists for operational teams.

When should I escalate regulatory monitoring signals to senior counsel?

Regulatory monitoring signals should be escalated to senior counsel when supervisory authority guidance, enforcement trends, or legislative changes impact your privacy obligations. The assistant provides monitoring guidance to identify material shifts in data protection regulation and determine appropriate escalation timing.

What should be included in a breach notification procedure for data protection regulation compliance?

A breach notification procedure for data protection regulation compliance must include defined timelines and documented response steps. The assistant provides actionable checklists covering breach notification procedures aligned with GDPR, CCPA/CPRA, and UK GDPR requirements to reduce operational friction.