What problem does it solve?
Privacy and sanctions controls often fail operationally even when formally documented: sanctions screens are evaded via homoglyphs or unlisted aliases, consent signals are forgeable and stale without server-side binding, DSR erasure is marked complete without per-store proof or downstream propagation, and ROPA documentation drifts from actual data processing flows, leading to false compliance, regulatory penalties, and unmitigated privacy or sanctions risk.
Core Features & Use Cases
- Sanctions Screening Hardening: Normalizes input via Unicode confusable folding and alias/fuzzy matching to block homoglyph and alias evasion of prohibited party screening.
- Consent Integrity Management: Binds client-side consent signals to server-side records and re-validates purpose, expiry, and withdrawal status at processing time to prevent forged or stale consent usage.
- Evidence-Gated DSR Erasure: Requires per-store deletion proof and propagates erasure to all downstream copies, indexes, backups, and processors to ensure complete data removal.
- ROPA Reconciliation: Aligns record of processing documentation with actual data flows and processors on a regular cadence to eliminate hidden unregulated processing.
Use Case: A mid-2026 organization subject to GDPR, OFAC, and MSPA requirements can use this skill to audit and harden its privacy and sanctions workflows to avoid costly regulatory penalties from non-compliant processing or missed sanctions violations.
Quick Start
Use the privacy-consent-ops skill to audit your organization's sanctions screening, consent management, DSR erasure, and ROPA processes for operational integrity gaps and compliance theater.