Studio Edition
Privacy Compliance Builder (GDPR & US State Laws)
RoPA, DPIAs, notices, cookies, DSARs and breach response for GDPR and US state laws
Privacy Compliance Builder gives your agent a structured way to set up and run a privacy program under the GDPR / UK GDPR and US state privacy laws, including the CCPA/CPRA. It is built for founders, operations and engineering leads, and first privacy hires at small and mid-size companies who need working documents rather than theory.
How it works
The agent first works out which laws apply, then maps your processing into a Record of Processing Activities (CSV). A bundled Python script validates the record for missing or inconsistent fields (no lawful basis, special-category data without an Article 9 condition, transfers without a safeguard, vague retention) and screens every activity against the EDPB high-risk indicators to flag where a DPIA is likely needed. From the record, the agent drafts lawful-basis decisions, legitimate interests assessments, DPIAs, a layered privacy notice, CCPA notices at collection and a cookie policy. It also handles live events: data subject requests with deadlines and response letters, and personal data breaches on the GDPR 72-hour timeline.
What you get
- RoPA template (37 columns) and a stdlib Python validator with DPIA screening
- Lawful-basis guide, LIA and DPIA templates
- Privacy notice, CCPA notice-at-collection and cookie policy templates
- Cookie banner checklist, DSAR playbook with eight response templates
- Vendor DPA checklist, breach runbook, notification templates and breach register
- Two worked examples for a fictional online retailer
Important: this kit helps you prepare. It is not legal advice and does not make a company compliant or certified. Rules vary by jurisdiction and change often; items that vary are marked "verify current rules". Have counsel review before publishing notices or making notification decisions.
Highlights
- RoPA template plus a validator that flags gaps and likely DPIAs
- Lawful-basis guide, LIA and DPIA templates
- Privacy notice, CCPA notice at collection and cookie policy templates
- DSAR playbook with deadlines and eight response letters
- Breach runbook on the GDPR 72-hour timeline, vendor DPA checklist
Example
Here's our processing register as a CSV. Check it and tell me which activities need a DPIA.
> Compliance support only, not legal advice. Verify current rules and have counsel review. | Activity | Indicators | Screen result | DPIA status | | TH-03 Product recommendations | profiling; large-scale; combining datasets | **DPIA likely required** | Screening | | TH-04 Retargeting advertising | profiling; large-scale; combining datasets | **DPIA likely required** | - | | TH-06 Warehouse CCTV | systematic monitoring; vulnerable subjects (employees) | **DPIA likely required** | Completed | Errors - TH-03: DPIA likely required (3 indicators) but dpia_status is 'Screening' - TH-04: DPIA likely required (3 indicators) but dpia_status is 'blank' Warnings - TH-03: legitimate interests without lia_reference - TH-07: last reviewed 465 days ago Recommendation: one combined DPIA for TH-03 and TH-04 (same behavioral data and vendors). "Contract" does not fit recommendations - they are not necessary to sell the product - so keep legitimate interests with an LIA and a personalization switch. TH-04 is "sharing" under California law: add a Do Not Sell or Share link and honor Global Privacy Control on the US site.
A California customer emailed: 'Delete everything you have on me and stop selling my data.' What do we do and by when?
> Compliance support only, not legal advice. Deadlines below follow the CCPA as generally understood; verify current rules. Request DSAR-2026-032 - California - delete + opt out of sale/sharing - received Mon 2026-09-21 | Step | Deadline | | Opt-out of sale/sharing | Apply no later than 2026-10-12 (15 business days) - do it today | | Acknowledge | By 2026-10-05 (10 business days) | | Deletion response | By 2026-11-05 (45 calendar days; one 45-day extension with notice) | Verification: the email matches the account; send a confirmation link before deleting. The opt-out needs no verification. Delete: account, wishlist, recommendation profile, tickets, call recordings; instruct processors. Keep (exceptions): invoices (tax law) and warranty-related order data until 2028-04-11; tell him what was kept and why. Opt-out: remove his hashed email from ad audiences and notify the ad platforms. Program gap: the US site has no Do Not Sell or Share link or GPC handling - that is the real fix.
Yesterday afternoon we emailed a spreadsheet of about 3,000 customer records to the wrong vendor. Do we have to report this?
> Compliance support only, not legal advice. Involve counsel now; verify current rules for each affected country and US state. Awareness: Wed 2026-10-07 16:10 CEST, when the vendor confirmed receipt. 72-hour deadline (GDPR Art. 33): Sat 2026-10-10 16:10 CEST. Facts to pin down in the next 4 hours: 1. Exact fields in the spreadsheet (any payment data, ID numbers, health data?) 2. Number of people and their countries / US states 3. Has the vendor deleted it? Get written confirmation and ask who opened it 4. Is the vendor under a contract with confidentiality terms? Provisional risk view: names, emails and order history sent to one known business recipient under contract and confirmed deleted -> likely "unlikely to result in a risk": document in the breach register, no regulator notice. If the file held payment details or it cannot be confirmed deleted -> risk: notify the lead authority by Saturday 16:10; assess high risk for individual notice. US residents: check each state's definition of personal information - name + email + order history usually does not trigger notice; card numbers or credentials would. Next: open BR-2026-04 in the breach register with the decision record.
What's inside
privacy-compliance-builder/ ├── agents/ │ └── openai.yaml ├── examples/ │ ├── worked-example-01-ropa-and-dpia-screening.md │ └── worked-example-02-dsar-access-and-deletion.md ├── references/ │ ├── breach-notification-runbook.md │ ├── cookie-banner-and-policy-guidance.md │ ├── dsar-handling-playbook.md │ ├── lawful-basis-decision-guide.md │ └── us-state-privacy-notes.md ├── scripts/ │ └── validate_ropa.py ├── templates/ │ ├── 01-record-of-processing-activities.csv │ ├── 02-legitimate-interests-assessment.md │ ├── 03-dpia-template.md │ ├── 04-privacy-notice-template.md │ ├── 05-ccpa-notice-at-collection.md │ ├── 06-cookie-policy-template.md │ ├── 07-dsar-response-templates.md │ ├── 08-vendor-dpa-checklist.md │ ├── 09-breach-notification-templates.md │ └── 10-breach-register.csv ├── LICENSE.txt ├── README.md └── SKILL.md
Install by unzipping into your agent's skills folder. Install guide →