agentsclimarketplace

Data protection check

Skill Zerif007/Claude_Legal-Bangladesh_Edition/bd-regulatory-compliance/skills/data-protection-check

Cluade Legal Bangladesh Plugin and Skill Suite

Install
npx -y skills add Zerif007/Claude_Legal-Bangladesh_Edition --skill data-protection-check

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 21 days oldThe repository was created 21 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Focused Personal Data Protection Act 2026 compliance review — processing inventory, lawful basis, data classification, localisation, cross-border transfers, breach and registration duties. Use for "PDPA check", "can we send this data abroad", "privacy review", "data protection compliance", DPA/data-clause reviews, or breach response.

SKILL.md

2.8 KB, as published. Nobody here has run it

Data Protection Check — PDPA 2026

Config gate (regulatory footprint: data classes held) + currency check: the regime is brand-new — PDP Ordinance 2025 (promulgated 6 Nov 2025) → Amendment Ordinance (Feb 2026) → Personal Data Protection Act 2026 (Act 63 of 2026, deemed effective 6 Nov 2025), with some sections (CDO appointment, administrative-penalty machinery) commencing on later notification. Open every output by stating which instrument/version the analysis uses and what remains un-commenced [verify].

Review sequence

  1. Role & scope: fiduciary vs processor per the Act's definitions; extraterritorial hook (processing outside Bangladesh connected to offering products/services to, or monitoring, data subjects in Bangladesh).
  2. Processing inventory: data classes mapped to the Act's four-tier classification (public/open, internal, confidential, restricted) — classification drives everything downstream; where the schedule criteria are still opaque, say so and take the conservative tier.
  3. Lawful basis & consent: consent-centric regime; consent quality (informed, specific, withdrawable); sensitive-data subcategories (financial, biometric, genetic, health, identifiers); children's data — profiling/targeted ads prohibited.
  4. Data subject rights machinery: access, correction, erasure, portability, opt-out of automated decision-making — intake channel, clocks, verification procedure.
  5. Localisation & transfers: restricted data + CII-linked data (per Cyber Security Ordinance 2025 definitions) → in-country synchronized copy requirement; confidential/ internal data transferable with consent/contractual need to adequate destinations; large-volume sensitive transfers → Authority permission. Map every outbound flow.
  6. Security, breach, governance: safeguards standard, breach notification duties, NDMA registration tier, CDO requirement (un-commenced — prepare, don't panic), record-keeping.
  7. Contracts: processor terms, transfer clauses, indemnity sizing against the up-to- 5%-of-turnover penalty band.

Output: attorney-review draft — role determination, classification table, gap register ranked by penalty exposure, transfer-flow map with lawful-mechanism per flow, remediation plan, escalations (any government data-sharing demand, surveillance-adjacent requests, regulator correspondence → senior counsel).

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.