Home
cd ../playbooks
Legal & ComplianceAdvanced

Compliance Review Checker

Compliance review for proposed actions covering GDPR, CCPA, DPA, and privacy regulations

10 minutes
By AnthropicSource
#compliance#gdpr#ccpa#privacy#data-protection

You're about to launch a new feature that collects user data, and your legal team is a 3-week backlog. You need to know now — does this violate GDPR? Do we need consent? What about CCPA?

Who it's for: product teams launching features with data implications, startup founders without in-house legal, compliance officers triaging regulatory reviews, DPOs managing privacy impact assessments, engineering leads implementing data collection

Example

"Review our new analytics feature for GDPR and CCPA compliance" → Applicable regulations identified, consent requirements mapped, DPA checklist completed, data subject request handling guidance, and a prioritized list of required changes before launch

CLAUDE.md Template

New here? 3-minute setup guide → | Already set up? Copy the template below.

# Compliance Review Checker

Run a compliance check on a proposed action, product feature, marketing campaign, or business initiative.

**Important**: This workflow assists with legal processes but does not provide legal advice. Compliance assessments should be reviewed by qualified legal professionals. Regulatory requirements change frequently; always verify current requirements with authoritative sources.

## Usage

Describe what you're planning to do. Examples:
- "We want to launch a referral program with cash rewards"
- "We're adding biometric authentication to our mobile app"
- "We need to process EU customer data in our US data center"
- "Marketing wants to use customer testimonials in ads"

## Output Format

```markdown
## Compliance Check: [Initiative]

### Summary
[Quick assessment: Proceed / Proceed with conditions / Requires further review]

### Applicable Regulations and Policies
| Regulation/Policy | Relevance | Key Requirements |
|-------------------|-----------|--------------------|
| [GDPR / CCPA / HIPAA / etc.] | [How it applies] | [What you need to do] |

### Requirements
| # | Requirement | Status | Action Needed |
|---|-------------|--------|---------------|
| 1 | [Requirement] | [Met / Not Met / Unknown] | [What to do] |

### Risk Areas
| Risk | Severity | Mitigation |
|------|----------|------------|
| [Risk] | [High/Med/Low] | [How to address] |

### Recommended Actions
1. [Most important action]
2. [Second priority]
3. [Third priority]

### Approvals Needed
| Approver | Why | Status |
|----------|-----|--------|
| [Person/Team] | [Reason] | [Pending] |

### Further Review Recommended
[Areas where outside counsel or specialist review is advised]
```

## Privacy Regulation Overview

### GDPR (General Data Protection Regulation)

**Scope**: Applies to processing of personal data of individuals in the EU/EEA, regardless of where the processing organization is located.

**Key Obligations for In-House Legal Teams**:
- **Lawful basis**: Identify and document lawful basis for each processing activity (consent, contract, legitimate interest, legal obligation, vital interest, public task)
- **Data subject rights**: Respond to access, rectification, erasure, portability, restriction, and objection requests within 30 days (extendable by 60 days for complex requests)
- **Data protection impact assessments (DPIAs)**: Required for processing likely to result in high risk to individuals
- **Breach notification**: Notify supervisory authority within 72 hours of becoming aware of a personal data breach; notify affected individuals without undue delay if high risk
- **Records of processing**: Maintain Article 30 records of processing activities
- **International transfers**: Ensure appropriate safeguards for transfers outside EEA (SCCs, adequacy decisions, BCRs)
- **DPO requirement**: Appoint a Data Protection Officer if required

### CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)

**Scope**: Applies to businesses that collect personal information of California residents and meet revenue, data volume, or data sale thresholds.

**Key Obligations**:
- **Right to know**: Consumers can request disclosure of personal information collected, used, and shared
- **Right to delete**: Consumers can request deletion of their personal information
- **Right to opt-out**: Consumers can opt out of the sale or sharing of personal information
- **Right to correct**: Consumers can request correction of inaccurate personal information (CPRA addition)
- **Right to limit use of sensitive personal information**: Consumers can limit use of sensitive PI to specific purposes (CPRA addition)
- **Non-discrimination**: Cannot discriminate against consumers who exercise their rights
- **Privacy notice**: Must provide a privacy notice at or before collection
- **Service provider agreements**: Contracts with service providers must restrict use of PI to the specified business purpose

**Response Timelines**:
- Acknowledge receipt within 10 business days
- Respond substantively within 45 calendar days (extendable by 45 days with notice)

### Other Key Regulations to Monitor

| Regulation | Jurisdiction | Key Differentiators |
|---|---|---|
| **LGPD** (Brazil) | Brazil | Similar to GDPR; requires DPO appointment; ANPD enforcement |
| **POPIA** (South Africa) | South Africa | Information Regulator oversight; required registration of processing |
| **PIPEDA** (Canada) | Canada (federal) | Consent-based framework; OPC oversight |
| **PDPA** (Singapore) | Singapore | Do Not Call registry; mandatory breach notification |
| **Privacy Act** (Australia) | Australia | Australian Privacy Principles (APPs); notifiable data breaches scheme |
| **PIPL** (China) | China | Strict cross-border transfer rules; data localization requirements |
| **UK GDPR** | United Kingdom | Post-Brexit UK version; ICO oversight |

## DPA Review Checklist

When reviewing a Data Processing Agreement or Data Processing Addendum, verify the following:

### Required Elements (GDPR Article 28)

- [ ] **Subject matter and duration**: Clearly defined scope and term of processing
- [ ] **Nature and purpose**: Specific description of what processing will occur and why
- [ ] **Type of personal data**: Categories of personal data being processed
- [ ] **Categories of data subjects**: Whose personal data is being processed
- [ ] **Controller obligations and rights**: Controller's instructions and oversight rights

### Processor Obligations

- [ ] **Process only on documented instructions**
- [ ] **Confidentiality**: Personnel authorized to process have committed to confidentiality
- [ ] **Security measures**: Appropriate technical and organizational measures described
- [ ] **Sub-processor requirements**: Written authorization, notification of changes, same obligations
- [ ] **Data subject rights assistance**
- [ ] **Security and breach assistance**
- [ ] **Deletion or return**: On termination, delete or return all personal data
- [ ] **Audit rights**: Controller has right to conduct audits and inspections
- [ ] **Breach notification**: Processor will notify controller without undue delay

### International Transfers

- [ ] **Transfer mechanism identified**: SCCs, adequacy decision, BCRs, or other valid mechanism
- [ ] **SCCs version**: Using current EU SCCs (June 2021 version) if applicable
- [ ] **Correct module**: Appropriate SCC module selected (C2P, C2C, P2P, P2C)
- [ ] **Transfer impact assessment**: Completed if transferring to countries without adequacy decisions
- [ ] **UK addendum**: If UK personal data is in scope, UK International Data Transfer Addendum included

### Common DPA Issues

| Issue | Risk | Standard Position |
|---|---|---|
| Blanket sub-processor authorization without notification | Loss of control over processing chain | Require notification with right to object |
| Breach notification timeline > 72 hours | May prevent timely regulatory notification | Require notification within 24-48 hours |
| No audit rights | Cannot verify compliance | Accept SOC 2 Type II + right to audit upon cause |
| Data deletion timeline not specified | Data retained indefinitely | Require deletion within 30-90 days of termination |
| Outdated SCCs | Invalid transfer mechanism | Require current EU SCCs (2021 version) |

## Data Subject Request Handling

### Request Intake

When a data subject request is received:

1. **Identify the request type**: Access, rectification, erasure, restriction, portability, objection, opt-out, limit use
2. **Identify applicable regulation(s)**: Where is the data subject located? Which laws apply?
3. **Verify identity**: Confirm the requester is who they claim to be
4. **Log the request**: Date received, request type, applicable regulation, response deadline, assigned handler

### Response Timelines

| Regulation | Initial Acknowledgment | Substantive Response | Extension |
|---|---|---|---|
| GDPR | Best practice: promptly | 30 days | +60 days (with notice) |
| CCPA/CPRA | 10 business days | 45 calendar days | +45 days (with notice) |
| UK GDPR | Best practice: promptly | 30 days | +60 days (with notice) |
| LGPD | Not specified | 15 days | Limited extensions |

## Tips

1. **Be specific** -- "We want to email all our users" is better than "marketing campaign."
2. **Include the geography** -- Compliance requirements vary by jurisdiction.
3. **Mention the data** -- What personal data is involved? This drives most compliance requirements.
README.md

What This Does

Runs a compliance check on a proposed action, product feature, or business initiative -- surfacing applicable regulations (GDPR, CCPA, HIPAA, and more), required approvals, risk areas, and recommended actions. Includes a full DPA review checklist and data subject request handling guidance.


Quick Start

Step 1: Download the Template

Click Download above to get the CLAUDE.md file.

Step 2: Set Up Your Project

Create a project folder and place the template inside:

compliance-review/
├── CLAUDE.md
├── reviews/         # Completed compliance reviews
├── policies/        # Internal policies and regulations
└── checklists/      # DPA and compliance checklists

Step 3: Start Working

claude

Say: "Run a compliance check on our plan to process EU customer data in a US data center"


What Gets Checked

Area Details
Applicable Regulations GDPR, CCPA/CPRA, HIPAA, LGPD, POPIA, PIPEDA, PIPL, UK GDPR
Requirements Mapped with Met / Not Met / Unknown status
Risk Areas Severity-rated with mitigation strategies
Approvals Who needs to sign off and why
DPA Review Full Article 28 checklist for data processing agreements

Tips

  1. Be specific -- describe the exact action you plan to take, not a vague category
  2. Include the geography -- compliance requirements vary dramatically by jurisdiction
  3. Mention the data -- specify what personal data is involved, as this drives most compliance requirements
  4. Regulatory requirements change -- always verify current requirements with authoritative sources

Example Prompts

"Run a compliance check on our plan to process EU customer data in a US data center"
"We want to launch a referral program with cash rewards -- what do we need?"
"Check compliance for adding biometric authentication to our mobile app"
"Marketing wants to use customer testimonials in ads -- any issues?"
"Review this DPA for GDPR Article 28 compliance"

$Related Playbooks

Legal & Compliance

DPDPA (India) Compliance Advisor

Navigate India's Digital Personal Data Protection Act and DPDP Rules 2025 — Data Fiduciary obligations, consent and notice, children's data, SDF duties, cross-border transfers, and breach notification.

10 minutes
Intermediate
Legal & Compliance

EAR Export Compliance Advisor

Classify items under the EAR (15 CFR 730-774) — ECCN/CCL determination, EAR99, Country Chart license analysis, license exceptions, end-user controls, deemed exports, FDPR, de minimis, and ECP design.

10 minutes
Advanced
Legal & Compliance

Market-Benchmarked Contract Review

Review contracts against CUAD's 41 risk categories and market-standard benchmarks. Generates risk analysis, redline suggestions, and negotiation priorities for NDAs, SaaS, M&A, and broker agreements.

10 minutes
Intermediate
Legal & Compliance

Contract Review & Risk Analyzer

Analyze contracts for risks, check completeness, and provide actionable recommendations. Supports employment contracts, NDAs, service agreements, and more.

10 minutes
Beginner
Legal & Compliance

Contract Template Generator

Create smart, legally enforceable contract templates with embedded logic using the Accord Project framework.

10 minutes
Intermediate
Legal & Compliance

DocuSign Automation

Automate document signing workflows, envelope management, and e-signature processes

10 minutes
Advanced
Legal & Compliance

Contract Redlining Assistant

Review contracts against your standard terms, flag risky clauses, and suggest alternative language.

15 minutes
Advanced
Legal & Compliance

Due Diligence Automator

Review data room documents across contracts, litigation, IP, compliance, and employment with systematic risk flagging.

15 minutes
Advanced
Legal & Compliance

EU AI Act Advisor

Classify AI systems across the EU AI Act's four risk tiers, check the prohibited practices, map provider/deployer and GPAI obligations, plan conformity assessment and CE marking, and handle Art. 50 transparency.

10 minutes
Advanced
Legal & Compliance

GDPR Compliance Advisor

Audit code and systems for GDPR violations, draft privacy policies and DPAs, answer GDPR questions with article citations, and review data flows and PII handling.

10 minutes
Intermediate
Legal & Compliance

HIPAA Compliance Advisor

Review systems and documents for HIPAA compliance, draft privacy notices, BAAs, and policies, run security risk assessments, and get technical-safeguard guidance for PHI/ePHI.

10 minutes
Intermediate
Legal & Compliance

GDPR Privacy Expert

Run GDPR compliance assessments, generate DPIAs, map data processing activities, build breach protocols, and create privacy policies with consent frameworks.

10 minutes
Intermediate

Browse all Legal & Compliance playbooks →