Web legal compliance
Skill sebastian-software/skills.sebastian-software.com/skills/web-legal-compliance
Practice-built skills that give AI agents practical judgment for product, web, engineering, delivery, go-to-market, communication, and compliance work.
npx -y skills add sebastian-software/skills.sebastian-software.com --skill web-legal-complianceAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Scope, research, draft, and review legal disclosures and compliance surfaces for websites, web apps, online stores, and digital services across the European Union and EEA states, the United Kingdom, Canada and its provinces, and the United States and its states. Use for Impressum or legal notice requests, operator and company disclosures, privacy and cookie notices, consent and tracking, online-sales information, marketing and endorsement disclosures, or multi-jurisdiction web compliance audits. Do not use as a substitute for qualified legal advice or for backend-only security and governance work.
SKILL.md
5.3 KB, 946 tokens by cl100k_base, as published. Nobody here has run it
Web Legal Compliance
Turn a vague request for an "Impressum" or a "compliant website" into a jurisdiction-aware, evidence-backed work product. Treat legal text as the visible result of facts and operational decisions, not as boilerplate.
Workflow
- Define the requested result: issue inventory, implementation review, page map, questionnaire, draft with placeholders, or counsel-ready brief.
- Read Scoping and evidence. Establish the operator, places of establishment, targeted markets, audience, transactions, data flows, marketing channels, publishing model, and regulated activities. Mark unknown facts; never invent them.
- Load every matching regional reference:
- European Union and EEA
- United Kingdom
- Canada
- United States
- California when California residents, transactions, tracking, or business activity are in scope
- For cookies, tracking, privacy choices, or consent interfaces, also read Consent and tracking.
- Verify current law and regulator guidance from primary official sources. Record jurisdiction, applicability trigger, effective date or as-of date, obligation, source, and unresolved interpretation. Use secondary sources only to find primary authority or explain a disputed point.
- Build an applicability matrix before drafting. Separate requirements that likely apply, conditional requirements, recommendations, and questions for counsel. Never merge them into one generic checklist.
- Inspect the real implementation when available: footer and navigation, checkout, forms, analytics and tags, consent state, account flows, email or SMS capture, user-generated content, localization, and mobile variants.
- Read Deliverables and produce the smallest useful artifact. Keep entity facts, legal assertions, product copy, and code changes separately reviewable.
- Recheck every draft against the fact inventory, source log, language and accessibility needs, link reachability, and mobile presentation. State the review date and remaining gaps.
Operating Rules
- State that the work is legal information and implementation support, not a legal opinion. Recommend qualified local counsel where applicability, interpretation, risk tolerance, or regulated activity is uncertain.
- Do not call a site "compliant" from a page review alone. Prefer precise statements such as "the disclosed facts match the supplied records" or "this requirement appears applicable under the cited source."
- Do not treat a domain suffix, visitor IP, translated page, or globally accessible site as sufficient proof that a jurisdiction applies. Evaluate establishment, intentional targeting, affected people, and activity-specific rules.
- Do not assume one strict global template is safest. Extra statements can be inaccurate, create commitments, expose unnecessary personal data, or obscure locally required information.
- Do not conflate operator identification, privacy notice, consent interface, terms, checkout disclosures, accessibility information, and marketing disclosures. They may share navigation but have different triggers.
- Prefer live official sources over remembered thresholds, penalty amounts, regulator names, required wording, or lists of covered states and provinces.
- Treat geo-routing, privacy signals, consent categories, and fallback behavior as explicit Product/Legal policy backed by current sources. Do not silently turn a market heuristic into a legal conclusion.
- Preserve a source-backed distinction between mandatory content, conditional content, recommended trust information, and optional house style.
- Draft with conspicuous placeholders such as
[LEGAL ENTITY NAME]and an explicit missing-facts list. Never produce plausible-looking fictional registration, tax, representative, address, or contact data.
Routing Boundaries
- Route layout, footer navigation, forms, consent UI, accessibility
implementation, and frontend testing to
effective-webafter this skill has established the legal and factual requirements. - Route locale-specific punctuation, spacing, dates, numbers, and visible
prose typography to
locale-typographyafter counsel-approved wording and target locales are known. - Keep penetration testing, security architecture, records of processing, vendor contracting, tax advice, employment law, and corporate filings outside this skill unless they directly determine a web disclosure.
What ships with it: 11 files
52.6 KB alongside SKILL.md
agents/
- openai.yaml211 B
evals/
- evals.json5.7 KB
references/
- canada.md4.2 KB
- consent-and-tracking.md7.5 KB
- deliverables.md3.3 KB
- european-union.md6.9 KB
- scoping-and-evidence.md4.1 KB
- united-kingdom.md3.2 KB
- united-states-california.md8.1 KB
- united-states.md5.4 KB
- README.md3.9 KB