policy-monitor

Detect gaps between published 152-FZ policies and actual data processing practices.

17|4|Updated May 25, 2026
One-click install
npx skills add https://github.com/AlsKozlov/ru-legal --skill policy-monitor-alskozlov
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: policy-monitor
Source: https://github.com/AlsKozlov/ru-legal/tree/main/packs/data-protection/skills/policy-monitor
Command: npx skills add https://github.com/AlsKozlov/ru-legal --skill policy-monitor-alskozlov

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Russian operators are required by Article 18.1 of Federal Law 152-FZ to publish a personal data processing policy, but these policies frequently fall out of sync with actual business practices, creating compliance gaps that risk regulatory fines from Roskomnadzor.

Core Features & Use Cases

  • Dual operation modes: Run a full sweep of recent data processing outputs (privacy impact assessments, data processing agreements, use case triages, DSAR responses) to identify drift, or run a direct check for a specific planned new business activity.
  • Structured gap classification: Categorize identified gaps by severity (critical violations, internal inconsistencies, improvement opportunities) with clear risk labels tied to 152-FZ requirements.
  • Actionable drift reports: Generate formatted reports with specific recommended policy updates, compliance action items, and timelines for DPO review and policy publication. Common use cases include quarterly compliance audits, pre-launch validation of new initiatives like AI-powered candidate screening, and ad-hoc checks when teams propose changes to data processing workflows.

Quick Start

Use the policy-monitor skill to run a full sweep of your recent data processing outputs to identify gaps between your published personal data policy and actual business practices, or check if a planned new activity like AI-powered candidate screening requires policy updates.

Frequently Asked Questions about policy-monitor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect privacy policy drift for 152-FZ compliance?

To detect privacy policy drift for 152-FZ compliance, run a full sweep of recent data processing outputs to identify misalignment between published policies and actual business practices. This generates structured gap reports with severity classifications and recommended policy updates for DPO review.

What is policy drift in personal data processing?

Policy drift in personal data processing occurs when your published privacy policy falls out of sync with actual business practices. It creates compliance gaps risking regulatory fines from Roskomnadzor under Article 18.1 of Federal Law 152-FZ, requiring periodic audits to identify and resolve misalignments.

Can I check a planned new business activity for 152-FZ compliance?

Yes, you can check a planned new business activity for 152-FZ compliance using a direct check mode. This validates new initiatives like AI-powered candidate screening against your current published personal data policy to determine if specific updates or new compliance action items are required before launch.

How do I prepare for a Roskomnadzor data processing audit?

To prepare for a Roskomnadzor data processing audit, perform a quarterly compliance sweep of privacy impact assessments, data processing agreements, and DSAR responses. This identifies internal inconsistencies and critical violations, providing formatted drift reports with timelines for policy publication.

What is the best way to classify compliance gaps in a personal data policy?

The best way to classify compliance gaps in a personal data policy is to categorize identified misalignments by severity. This includes critical violations, internal inconsistencies, and improvement opportunities, with clear risk labels tied directly to 152-FZ requirements for actionable DPO review.