
Privacy Compliance Checker
Audit code and data flows for GDPR/CCPA compliance violations
What You Can Do
You can systematically audit your code and data flows to uncover privacy compliance risks across GDPR, CCPA, and other regulatory frameworks. The skill maps where personally identifiable information is collected, processed, stored, and transmitted—then validates that consent mechanisms, data minimization practices, retention policies, and deletion implementations meet legal requirements. This catches compliance gaps early, before they result in regulatory fines or enforcement actions.
Features
Identifies all collection, processing, storage, and transmission points for personal data
Checks that consent mechanisms are properly implemented, documented, and auditable
Verifies you're only collecting and retaining data necessary for stated purposes
Ensures data retention schedules align with GDPR/CCPA timelines and legal holds
Confirms GDPR Article 17 and CCPA deletion request implementations work end-to-end
Flags unreachable or undocumented data storage locations
Identifies privacy gaps created by vendor integrations and APIs
Validates documented legal grounds for each data processing activity
Example Output
Example 1: PII Collection Gap
- ⚠️ FINDING: Uncontrolled PII Collection
Location: /src/signup.js, line 47
Issue: Email collected without explicit opt-in consent checkbox
Severity: HIGH (GDPR Art. 7 violation)
Fix: Add checkbox for marketing consent before form submission
Example 2: Retention Policy Issue
✗ FINDING: Missing Data Retention Policy
Location: user_analytics_pipeline.sql
Issue: No deletion trigger for inactive user records after 36 months
Severity: MEDIUM (CCPA non-compliance)
Fix: Implement automated purge job for records > 3 years old
Recommendation: Document retention rationale in DPA
Example 3: Vendor Risk
- ⚠️ FINDING: Unvetted Third-Party Data Flow
Location: config/integrations.json
Issue: User events sent to analytics vendor without DPA in place
Severity: CRITICAL (GDPR Art. 28 violation)
Fix: Execute Data Processing Agreement before data transfer resumes
What's Included
- SKILL.md: Full compliance checker instruction set with GDPR/CCPA framework
- PII Mapping Template: Spreadsheet to catalog all data flows and processing activities
- Consent Mechanism Checklist: Step-by-step validation framework for consent collection
- Data Retention Policy Worksheet: Table for documenting legal retention periods per data type
- Compliance Audit Report Template: Structured findings format with severity levels and remediation steps
Who It's For
- Compliance Officers — Conducting privacy audits and building compliance frameworks
- Privacy Engineers — Building privacy-by-design into data architectures
- Security Teams — Assessing privacy and data protection risk in code reviews
- General Counsel & Legal — Preparing compliance evidence and DPA documentation
- Product Managers — Vetting new features for privacy violations before launch
Best For
- Privacy compliance audits — Quarterly or bi-annual reviews of code and data flows
- Third-party vendor assessments — Checking integrations before adding analytics, CRM, or payment processors
- New feature launches — Reviewing data collection, consent forms, and preference centers before shipping
- Incident response — Validating deletion request implementations and tracking down orphaned data
- Regulatory preparation — Building evidence packages for GDPR/CCPA assessments and audits






