Maps which regulations apply to a product or business across every operating jurisdiction, translates them into concrete obligations, and produces a prioritized compliance-gap table. Use when someone asks "what regulations apply to my product", "are we GDPR or CCPA exposed", "run a compliance gap analysis", or is entering a new market or handling a new data type. Do NOT use for drafting the legal documents themselves - use terms-of-service instead. Do NOT use for assembling SOC 2 audit evidence - use soc2-evidence-helper instead. Do NOT use for patent landscape questions - use patent-prior-art instead.
Click to play with sound.
---
name: Regulatory Scanner
description: Maps which regulations apply to a product or business across every operating jurisdiction, translates them into concrete obligations, and produces a prioritized compliance-gap table. Use when someone asks "what regulations apply to my product", "are we GDPR or CCPA exposed", "run a compliance gap analysis", or is entering a new market or handling a new data type. Do NOT use for drafting the legal documents themselves - use terms-of-service instead. Do NOT use for assembling SOC 2 audit evidence - use soc2-evidence-helper instead. Do NOT use for patent landscape questions - use patent-prior-art instead.
---
# Regulatory Scanner
Produce a clear map of which regulations apply to a product and where the gaps are - research and triage, not legal advice. The costly failure this prevents is discovering an obligation from the enforcement letter: teams routinely learn that a checkout flow triggered a state privacy law, or a health-adjacent feature crossed into HIPAA territory, only after the exposure exists.
## Operating procedure
Jurisdiction drives everything, so scoping comes first; a scan that assumes US-only while the product sells into the EU is worse than no scan, because it creates false confidence.
### Step 1: Gather inputs
Collect from the user:
- What the product does, in plain terms, and the industry it serves.
- What data it collects, stores, or processes - especially personal data, health data, payment data, children's data, biometric data.
- Who the customers are (consumers vs. businesses; whether any are minors).
- Every jurisdiction where it operates, sells, or has users - not just where it is incorporated. Serving EU residents triggers GDPR regardless of company location.
- Company scale (revenue, user counts) - many regimes have applicability thresholds.
Label anything assumed as a guess and confirm before Step 2, because a wrong jurisdiction list invalidates the whole map.
… install to load the full skill