cosmicstack-labs/privacy-compliance
GDPR, CCPA, HIPAA, data mapping, consent management, DSR handling, and privacy program management
npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill privacy-compliance
Build and maintain privacy compliance programs.
| Regulation | Scope | Key Requirements |
|------------|-------|------------------|
| GDPR | EU residents | Consent, data rights, breach notification, DPO |
| CCPA/CPRA | California residents | Right to know, delete, opt-out |
| HIPAA | US healthcare | PHI protection, BAAs, security rule |
| LGPD | Brazil | Similar to GDPR |
| PIPEDA | Canada | Consent, access, accuracy |
| Request Type | Timeline | Process |
|-------------|----------|---------|
| Access | 30 days | Provide all data in machine-readable format |
| Deletion | 30 days | Delete + request deletion from third parties |
| Correction | 30 days | Fix inaccurate data |
| Portability | 30 days | Export in structured format |
| Objection | 30 days | Stop processing for specific purpose |
Take cosmicstack-labs/privacy-compliance from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.