Generate, review, and update privacy policies compliant with GDPR, CCPA, and global data protection laws.
---
name: privacy-policy
description: When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.
related: [terms-of-service, soc2-prep]
reads: [startup-context]
---
# Privacy Policy
## When to Use
Activate when a founder needs to create a privacy policy for a new product launch, update an existing policy for new data practices or features, expand into a new jurisdiction (EU, California, etc.), or assess whether current data handling is properly disclosed. Also activate when the user asks about GDPR, CCPA, CPRA, or general data privacy compliance.
## Context Required
- **From startup-context:** product type, platform (web/mobile/API), target customer segments, geographic markets, business model, tech stack.
- **From the user:** product name and URL, company legal name and address, contact email for privacy inquiries, what personal data is collected and how, which third-party services process data (analytics, payment processors, CRMs, AI providers), applicable jurisdictions, whether the product targets minors, and any existing privacy documentation.
## Workflow
1. **Research the product** -- Visit the product website or review the product description. Identify all data collection methods, third-party integrations, and primary features that involve personal data.
2. **Map data collection** -- Categorize all data into: directly provided (forms, account creation), automatically collected (cookies, device info, usage data, IP addresses), third-party sources, and special/sensitive categories. Build a structured data inventory.
3. **Identify applicable laws** -- Based on where users are located and where the company operates, determine which privacy frameworks apply: GDPR, CCPA/CPRA, state privacy laws, COPPA, industry-specific regulations. Note specific obligations per jurisdiction.
4. **Structure the policy** -- Organize using the 15-section template below. Write in plain language at an 8th-grade reading level. Be specific about actual practices -- say "We collect your email address when you sign up" rather than "We may process identifiers."
5. **Flag legal review areas** -- Mark sections requiring attorney review with `[LEGAL REVIEW REQUIRED]` notation. These include legal basis determinations, international transfer mechanisms, and jurisdiction-specific rights.
6. **Provide implementation context** -- Explain why each section matters, what company decisions are needed, and what compliance considerations apply. Include a pre-publication checklist.
7. **Generate compliance summary** -- Produce a separate document with data inventory table, jurisdiction applicability matrix, risk flags, and implementation checklist.
… load the full skill through Skill Me