Reference · plugin fact sheet

privacy-legal

The ground-truth summary behind Module 5. Every line below was read from the plugin's actual files (version 1.0.2, checked 2026-06-29) — paths cite the live repo.

Identity

From .claude-plugin/plugin.json: “Triages processing activities, generates PIAs, reviews DPAs as controller or processor, drafts DSAR responses within statutory timelines, and monitors policy drift against practice.”

The 9 skills, by job

JobSkills
Set up & tune the profilecold-start-interview (controller/processor + which regs apply), customize (one change at a time; refuses sub-minimum DSAR deadlines), matter-workspace (multi-client only — off for in-house)
Decide before you shipuse-case-triage (4-way verdict: PROCEED / PIA REQUIRED / DPIA MANDATORY / STOP), pia-generation (PIA in house format; lawful-basis table; “the policy or the feature has to change”)
Review the paperdpa-review (term-by-term, processor or controller side auto-detected, with the GLBA / HIPAA-BAA / FERPA / COPPA sectoral overlay)
Answer the data subjectdsar-response (clock-driven access/deletion/portability → two letters: acknowledgment now + substantive by the deadline)
Keep it currentpolicy-monitor (internal drift across five surfaces — policy, cookie banner, App Store / Data Safety labels, consent flows, sectoral notices), reg-gap-analysis (external change — scope-first, delta-not-full-text, owners + dates)

No subagents, empty hooks

Unlike commercial-legal (3 subagents) or litigation-legal (1), privacy-legal ships no subagents and an empty hooks/hooks.json ({ "hooks": {} }). The “monitor” here is a skill you run (policy-monitor), not a scheduled agent — and its weekly cadence would need a scheduled-tasks connector, which this plugin doesn't bundle, so sweeps run on demand.

The 2 bundled connectors — and the one that's missing

From .mcp.json: Slack and Google Drive only. No research / statute / case-law connector is bundled — so every citation-bearing skill defaults its cites to [model knowledge — verify], dates stable references [settled — last confirmed YYYY-MM-DD], leans on references/currency-watch.md for fast-moving areas, and records the connector status in the reviewer note's Sources line. (Add a statute/regulator tool yourself for verified cites.)

State it keeps on your machine

Conventions worth knowing

Sources: the plugin's CLAUDE.md, .mcp.json, and the skill files — all under privacy-legal/ on GitHub.

← Back to Module 5