Data protection check
Skill Zerif007/Claude_Legal-Bangladesh_Edition/bd-regulatory-compliance/skills/data-protection-check
Focused Personal Data Protection Act 2026 compliance review — processing inventory, lawful basis, data classification, localisation, cross-border transfers, breach and registration duties. Use for "PDPA check", "can we send this data abroad", "privacy review", "data protection compliance", DPA/data-clause reviews, or breach response.From its SKILL.md
npx -y skills add Zerif007/Claude_Legal-Bangladesh_Edition --skill data-protection-checkAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
2.8 KB, 522 tokens by cl100k_base, as published. Nobody here has run it
Data Protection Check — PDPA 2026
Config gate (regulatory footprint: data classes held) + currency check: the regime is
brand-new — PDP Ordinance 2025 (promulgated 6 Nov 2025) → Amendment Ordinance (Feb 2026)
→ Personal Data Protection Act 2026 (Act 63 of 2026, deemed effective 6 Nov 2025),
with some sections (CDO appointment, administrative-penalty machinery) commencing on
later notification. Open every output by stating which instrument/version the analysis
uses and what remains un-commenced [verify].
Review sequence
- Role & scope: fiduciary vs processor per the Act's definitions; extraterritorial hook (processing outside Bangladesh connected to offering products/services to, or monitoring, data subjects in Bangladesh).
- Processing inventory: data classes mapped to the Act's four-tier classification (public/open, internal, confidential, restricted) — classification drives everything downstream; where the schedule criteria are still opaque, say so and take the conservative tier.
- Lawful basis & consent: consent-centric regime; consent quality (informed, specific, withdrawable); sensitive-data subcategories (financial, biometric, genetic, health, identifiers); children's data — profiling/targeted ads prohibited.
- Data subject rights machinery: access, correction, erasure, portability, opt-out of automated decision-making — intake channel, clocks, verification procedure.
- Localisation & transfers: restricted data + CII-linked data (per Cyber Security Ordinance 2025 definitions) → in-country synchronized copy requirement; confidential/ internal data transferable with consent/contractual need to adequate destinations; large-volume sensitive transfers → Authority permission. Map every outbound flow.
- Security, breach, governance: safeguards standard, breach notification duties, NDMA registration tier, CDO requirement (un-commenced — prepare, don't panic), record-keeping.
- Contracts: processor terms, transfer clauses, indemnity sizing against the up-to- 5%-of-turnover penalty band.
Output: attorney-review draft — role determination, classification table, gap register ranked by penalty exposure, transfer-flow map with lawful-mechanism per flow, remediation plan, escalations (any government data-sharing demand, surveillance-adjacent requests, regulator correspondence → senior counsel).
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.