Skills
Privacy Notice Generator
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
Domain skillsBy Oliver Schmidt-PrietzPublished on Lawvable
What this skill does
Draft GDPR-compliant privacy notices as .docx for any EU/EEA jurisdiction and audience. Supports five notice types (Website/App, Applicant, Employee, Business Partner, B2C Customer) across DE, FR, AT, IT, ES, NL, BE, IE, and UK GDPR. Covers Art. 13/14 disclosures, AI Act transparency, cookie policies, multi-language support, DPIA indicators, and post-generation compliance checklists.
Get this skill on Lawvable
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Oliver Schmidt-Prietz
- DPIA SentinelGDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklists/whitelists. Covers threshold assessment, multi-jurisdictional blacklist checks (DE, FR, IE, BE, NL, IT, PL), 5x5 risk scoring, necessity/proportionality analysis, mitigation mapping, Art. 36 prior consultation, AI dual-phase analysis, an
- GDPR Breach SentinelIncident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Covers breach risk assessment using ENISA severity methodology, Controller vs Processor obligations, 72-hour notification clock management, EDPB case matching, cross-border Lead SA determination, AI Act Art. 62 intersection, mitigation playbooks, and audit-ready .docx document generation.
- Data Processing Agreement Art. 28 GDPRReview, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or prepare a Joint Controller Arrangement under Art. 26 GDPR (basic). Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and two review depths — quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring).
- EU AI Act System ClassifierDetermine whether a technology qualifies as an AI system under Art. 3(1) and classify its risk tier (prohibited, high-risk, GPAI with systemic risk, limited risk, minimal risk). Covers scope exclusions (Art. 2), AI system definition test (7 criteria), prohibited practice screening (Art. 5), high-risk assessment (Annex I + III with Art. 6(3) exception), GPAI check, and Art. 50 transparency triggers.
- EU AI Act High-Risk ClassifierDepth assessment of whether an AI system is high-risk under Art. 6 of the EU AI Act, grounded in the Commission's draft Art. 6(5) classification guidelines (general principles + Annex I + Annex III). Covers the Annex I product-safety route, all eight Annex III areas with worked examples, the Art. 6(3) exception and its profiling re-exception, and the Art. 25 quasi-provider trap. Outputs a structured decision block, a practitioner memo, and a JSON interchange artefact.
- EU AI Act Knowledge BaseAuthoritative regulatory Q&A grounded in 70 official EU source documents, including the 2026 Commission draft guidelines on Art. 6 high-risk classification. Answers any EU AI Act question with article-level citations from the full regulation text, Commission guidelines, EDPB/EDPS opinions, codes of practice, harmonised standards, FRIA guides, and sector-specific guidance — covering penalties, timelines, GPAI obligations, high-risk and prohibited practices, and the AI Act / GDPR interplay.
Skills that do related work
- Azerbaijan + EU Website Privacy Compliance AuditAudits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventori
- Cookie Policy GeneratorGuide for drafting cookie policies compliant with GDPR and the ePrivacy Directive. Includes CNIL 2020 recommendations, a reference template, and best practices.
- Dpa ReviewReview a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. U
- Dsar ResponseWalk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system
- EU AI Act Examination Report GeneratorGenerate a formal, structured AI Act compliance assessment report suitable for legal files, audit trails, and regulatory inquiries. Supports multiple output for
- Icelandic Privacy ReviewUse this skill when asked to review data protection or privacy compliance under Icelandic law and GDPR. Triggers on requests involving personal data processing,