privacy-compliance

Build and maintain privacy compliance programs for GDPR, CCPA/CPRA, and HIPAA.

364|53|Updated May 9, 2026
One-click install
npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill privacy-compliance-cosmicstack-labs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: privacy-compliance
Source: https://github.com/cosmicstack-labs/mercury-agent-skills/tree/main/categories/finance-legal/privacy-compliance
Command: npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill privacy-compliance-cosmicstack-labs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Privacy compliance programs struggle to stay consistent across GDPR/CCPA/HIPAA requirements, data mapping, consent records, and data subject requests (DSRs), leading to audit risk and delayed incident response.

Core Features & Use Cases

  • Major-Regulation Coverage: Aligns your program to GDPR, CCPA/CPRA, HIPAA, and related frameworks with practical expectations for consent, rights, and governance.
  • Data Mapping & Privacy by Design: Creates and maintains a documented view of data flows, legal basis, third-party processors, and minimization/retention controls.
  • Consent & DSR Handling: Defines how to capture consent and execute DSR workflows (access, deletion, correction, portability, objection) with clear timelines and process steps.
  • Use Case: Prepare for compliance audits and operationalize privacy workflows for a product that collects PII/sensitive data and relies on third-party processors.

Quick Start

Use this skill to draft your organization’s privacy program plan for GDPR/CCPA/HIPAA coverage, including data mapping, consent management, and DSR execution procedures.

Frequently Asked Questions about privacy-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a privacy compliance program that covers GDPR, CCPA, and HIPAA?

Build a privacy compliance program by aligning governance activities to GDPR, CCPA/CPRA, and HIPAA requirements, establishing documented data flows, legal basis mapping, and privacy by design controls. This creates a consistent framework across multiple regulations.

What is the best way to handle data subject requests across different privacy regulations?

Handle data subject requests by defining DSR workflows for access, deletion, correction, portability, and objection with clear timelines and process steps. This ensures consistent execution across enterprise and third-party processing environments.

How does consent management work when collecting PII with third-party processors?

Consent management works by defining processes to capture, record, and withdraw consent for PII collection processed by third parties. This satisfies regulatory requirements for documented consent states and user rights.

What do I need to prepare for a GDPR or CCPA compliance audit?

Prepare for a compliance audit by drafting a privacy program plan with documented data mapping, consent records, and DSR execution procedures. This demonstrates operationalized privacy workflows and privacy by design controls.

Can I use one compliance framework for both enterprise data and third-party processing environments?

You can use one framework by applying privacy governance activities across both enterprise and third-party processing environments. This covers data flows, retention limits, and encryption controls consistently.