Studio Edition

Privacy Compliance Builder (GDPR & US State Laws)

RoPA, DPIAs, notices, cookies, DSARs and breach response for GDPR and US state laws

$299.00

Privacy Compliance Builder gives your agent a structured way to set up and run a privacy program under the GDPR / UK GDPR and US state privacy laws, including the CCPA/CPRA. It is built for founders, operations and engineering leads, and first privacy hires at small and mid-size companies who need working documents rather than theory.

How it works

The agent first works out which laws apply, then maps your processing into a Record of Processing Activities (CSV). A bundled Python script validates the record for missing or inconsistent fields (no lawful basis, special-category data without an Article 9 condition, transfers without a safeguard, vague retention) and screens every activity against the EDPB high-risk indicators to flag where a DPIA is likely needed. From the record, the agent drafts lawful-basis decisions, legitimate interests assessments, DPIAs, a layered privacy notice, CCPA notices at collection and a cookie policy. It also handles live events: data subject requests with deadlines and response letters, and personal data breaches on the GDPR 72-hour timeline.

What you get

  • RoPA template (37 columns) and a stdlib Python validator with DPIA screening
  • Lawful-basis guide, LIA and DPIA templates
  • Privacy notice, CCPA notice-at-collection and cookie policy templates
  • Cookie banner checklist, DSAR playbook with eight response templates
  • Vendor DPA checklist, breach runbook, notification templates and breach register
  • Two worked examples for a fictional online retailer

Important: this kit helps you prepare. It is not legal advice and does not make a company compliant or certified. Rules vary by jurisdiction and change often; items that vary are marked "verify current rules". Have counsel review before publishing notices or making notification decisions.

Highlights

  • RoPA template plus a validator that flags gaps and likely DPIAs
  • Lawful-basis guide, LIA and DPIA templates
  • Privacy notice, CCPA notice at collection and cookie policy templates
  • DSAR playbook with deadlines and eight response letters
  • Breach runbook on the GDPR 72-hour timeline, vendor DPA checklist

Example

Validate a RoPA
You

Here's our processing register as a CSV. Check it and tell me which activities need a DPIA.

Agent + skill
> Compliance support only, not legal advice. Verify current rules and have counsel review.

| Activity | Indicators | Screen result | DPIA status |
| TH-03 Product recommendations | profiling; large-scale; combining datasets | **DPIA likely required** | Screening |
| TH-04 Retargeting advertising | profiling; large-scale; combining datasets | **DPIA likely required** | - |
| TH-06 Warehouse CCTV | systematic monitoring; vulnerable subjects (employees) | **DPIA likely required** | Completed |

Errors
- TH-03: DPIA likely required (3 indicators) but dpia_status is 'Screening'
- TH-04: DPIA likely required (3 indicators) but dpia_status is 'blank'
Warnings
- TH-03: legitimate interests without lia_reference
- TH-07: last reviewed 465 days ago

Recommendation: one combined DPIA for TH-03 and TH-04 (same behavioral data and vendors). "Contract" does not fit recommendations - they are not necessary to sell the product - so keep legitimate interests with an LIA and a personalization switch. TH-04 is "sharing" under California law: add a Do Not Sell or Share link and honor Global Privacy Control on the US site.
California deletion request
You

A California customer emailed: 'Delete everything you have on me and stop selling my data.' What do we do and by when?

Agent + skill
> Compliance support only, not legal advice. Deadlines below follow the CCPA as generally understood; verify current rules.

Request DSAR-2026-032 - California - delete + opt out of sale/sharing - received Mon 2026-09-21

| Step | Deadline |
| Opt-out of sale/sharing | Apply no later than 2026-10-12 (15 business days) - do it today |
| Acknowledge | By 2026-10-05 (10 business days) |
| Deletion response | By 2026-11-05 (45 calendar days; one 45-day extension with notice) |

Verification: the email matches the account; send a confirmation link before deleting. The opt-out needs no verification.

Delete: account, wishlist, recommendation profile, tickets, call recordings; instruct processors.
Keep (exceptions): invoices (tax law) and warranty-related order data until 2028-04-11; tell him what was kept and why.
Opt-out: remove his hashed email from ad audiences and notify the ad platforms.

Program gap: the US site has no Do Not Sell or Share link or GPC handling - that is the real fix.
Possible breach
You

Yesterday afternoon we emailed a spreadsheet of about 3,000 customer records to the wrong vendor. Do we have to report this?

Agent + skill
> Compliance support only, not legal advice. Involve counsel now; verify current rules for each affected country and US state.

Awareness: Wed 2026-10-07 16:10 CEST, when the vendor confirmed receipt. 72-hour deadline (GDPR Art. 33): Sat 2026-10-10 16:10 CEST.

Facts to pin down in the next 4 hours:
1. Exact fields in the spreadsheet (any payment data, ID numbers, health data?)
2. Number of people and their countries / US states
3. Has the vendor deleted it? Get written confirmation and ask who opened it
4. Is the vendor under a contract with confidentiality terms?

Provisional risk view: names, emails and order history sent to one known business recipient under contract and confirmed deleted -> likely "unlikely to result in a risk": document in the breach register, no regulator notice. If the file held payment details or it cannot be confirmed deleted -> risk: notify the lead authority by Saturday 16:10; assess high risk for individual notice.

US residents: check each state's definition of personal information - name + email + order history usually does not trigger notice; card numbers or credentials would.

Next: open BR-2026-04 in the breach register with the decision record.

What's inside

privacy-compliance-builder/
├── agents/
│   └── openai.yaml
├── examples/
│   ├── worked-example-01-ropa-and-dpia-screening.md
│   └── worked-example-02-dsar-access-and-deletion.md
├── references/
│   ├── breach-notification-runbook.md
│   ├── cookie-banner-and-policy-guidance.md
│   ├── dsar-handling-playbook.md
│   ├── lawful-basis-decision-guide.md
│   └── us-state-privacy-notes.md
├── scripts/
│   └── validate_ropa.py
├── templates/
│   ├── 01-record-of-processing-activities.csv
│   ├── 02-legitimate-interests-assessment.md
│   ├── 03-dpia-template.md
│   ├── 04-privacy-notice-template.md
│   ├── 05-ccpa-notice-at-collection.md
│   ├── 06-cookie-policy-template.md
│   ├── 07-dsar-response-templates.md
│   ├── 08-vendor-dpa-checklist.md
│   ├── 09-breach-notification-templates.md
│   └── 10-breach-register.csv
├── LICENSE.txt
├── README.md
└── SKILL.md

Install by unzipping into your agent's skills folder. Install guide →