Agent skill

Privacy Policy Drafting

by seb1n in seb1n/awesome-ai-agent-skills

Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions.

MITAuto-check passedLegal & Compliance

Install Privacy Policy Drafting

skills CLI
$ npx skills add seb1n/awesome-ai-agent-skills --skill privacy-policy-drafting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seb1n/awesome-ai-agent-skills privacy-policy-drafting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal-and-compliance/privacy-policy-drafting .claude/skills/privacy-policy-drafting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-policy-drafting
GitHub stars
206
Token cost
~2.3k tokens
SKILL.md length
1,167 words
Files
1
Skills in repo
101
Repo updated
First seen
Licence
MIT

At a glance

Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions.

  • Works in 5 steps: Gather Business Information — Collect… → Identify Data Collection Practices — Map… → Map Legal Requirements — Cross-reference… → …
  • The user requests a privacy policy
  • SKILL.md covers Workflow, Usage, Examples and Best Practices, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Policy Drafting is an agent skill from seb1n/awesome-ai-agent-skills. Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions. Use when the user requests a privacy policy or needs to map disclosures for GDPR, CCPA, or similar frameworks; do not use it to guarantee legal compliance.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.

When your agent uses it

  • The user requests a privacy policy
  • Needs to map disclosures for GDPR
  • Similar frameworks
  • Do not use it to guarantee legal compliance

Example prompts

  • “/privacy-policy-drafting”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Gather Business Information — Collect details about the business entity (name, jurisdiction, contact info), the product or service…
  2. Identify Data Collection Practices — Map every category of personal data collected: direct inputs (forms, account creation), automatic…
  3. Map Legal Requirements — Cross-reference collected data types against applicable frameworks. GDPR requires lawful basis for each…
  4. Draft Policy Sections — Generate each section with plain-language explanations alongside legally precise disclosures. Required sections…
  5. Review for Compliance Gaps — Audit the draft against a regulatory checklist. Verify that every data processing activity has a stated legal…

What it can do on your machine

Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Policy Drafting loads about 2.3k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 1,167 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 1,167 words, ~2,311 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-policy-drafting/SKILL.md (or your agent's skills folder).
name
privacy-policy-drafting
description
Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions. Use when the user requests a privacy policy or needs to map disclosures for GDPR, CCPA, or similar frameworks; do not use it to guarantee legal compliance.
license
MIT
metadata.author
community
metadata.version
1.0

Privacy Policy Drafting

Draft legally informed privacy-policy language that addresses potentially applicable privacy frameworks and exposes unresolved business inputs. Treat the result as a working draft and review checklist, not proof of compliance. Verify current law, regulator guidance, product behavior, and jurisdiction with qualified counsel before publication.

Workflow

  1. Gather Business Information — Collect details about the business entity (name, jurisdiction, contact info), the product or service offered, target user demographics, and geographic reach. Determine which regulations apply based on where users are located, not just where the business is incorporated. A US-based SaaS serving EU customers must address GDPR.

  2. Identify Data Collection Practices — Map every category of personal data collected: direct inputs (forms, account creation), automatic collection (cookies, analytics, device info, IP addresses), third-party sources (OAuth providers, data brokers), and derived data (usage patterns, preferences). For each category, document the collection method, storage location, retention period, and whether it includes sensitive/special category data.

  3. Map Legal Requirements — Cross-reference collected data types against applicable frameworks. GDPR requires lawful basis for each processing activity, CCPA requires disclosure of sale/sharing practices and opt-out mechanisms, COPPA applies if users under 13 may access the service, and sector-specific rules (HIPAA, FERPA, GLBA) may layer additional requirements. Identify all required policy sections.

  4. Draft Policy Sections — Generate each section with plain-language explanations alongside legally precise disclosures. Required sections include: data collected and purposes, legal basis for processing (GDPR), data sharing and third parties, cookies and tracking technologies, data retention, user rights and how to exercise them, international data transfers, children's privacy, security measures, and policy change notification procedures.

  5. Review for Compliance Gaps — Audit the draft against a regulatory checklist. Verify that every data processing activity has a stated legal basis, all required rights are enumerated, contact information for DPO or privacy inquiries is included, cookie consent mechanisms are described, and data breach notification procedures are referenced. Flag any gaps or areas needing business input.

Usage

Describe your business, what data you collect, and which jurisdictions your users are in. Include technical details about cookies, analytics tools, and third-party integrations.

Example prompt:

Draft a privacy policy for my SaaS app "TaskFlow" — a project management tool. We collect email, name, and usage analytics via Mixpanel. Users are in the US and EU. We use Stripe for payments and Google OAuth for login.

Examples

Example 1: SaaS App with Email and Usage Data

Input: TaskFlow, a project management SaaS. Collects email, name, profile photo, usage analytics (Mixpanel), payment info (Stripe), Google OAuth login. Users in US and EU.

Output (key sections):

Information We Collect

Information you provide: When you create an account, we collect your name, email address, and profile photo (if provided via Google OAuth). When you subscribe to a paid plan, our payment processor Stripe collects your payment card details — we do not store full card numbers on our servers.

Information collected automatically: We collect usage data including features accessed, session duration, and interaction patterns through Mixpanel. We collect device information (browser type, operating system, screen resolution), IP address, and approximate location derived from IP. We use cookies and similar technologies as described in our Cookie Policy section below.

Information from third parties: If you sign in via Google OAuth, we receive your name, email, and profile photo from Google per your Google account settings.

Legal Basis for Processing (EEA/UK Users)

Processing ActivityLegal Basis
Account creation and service deliveryPerformance of contract
Payment processingPerformance of contract
Usage analytics for product improvementLegitimate interest (improving service quality)
Email notifications about your accountPerformance of contract
Marketing communicationsConsent (opt-in)

Your Rights

Under GDPR (EEA/UK users): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Under CCPA (California residents): right to know, right to delete, right to opt-out of sale (we do not sell personal information), and right to non-discrimination.

Show full SKILL.md (570 more words)Show less
Example 2: Mobile App with Location Tracking

Input: FitRoute, a fitness tracking mobile app. Collects GPS location (continuous during workouts), health data (heart rate from wearables), email, age, weight. Users are global.

Output (additional sections):

Location Data

FitRoute collects precise GPS location data during active workout sessions to map your route and calculate distance. Location tracking begins only when you start a workout and stops when you end it. We do not track your location in the background. You can revoke location permissions at any time through your device settings, though this will prevent route mapping features from functioning.

Health and Sensitive Data

We collect health-related data including heart rate (synced from connected wearables), workout duration, calories burned, and body metrics you voluntarily provide (age, weight, height). Under GDPR, health data is a special category requiring explicit consent — we obtain this consent during onboarding. Under California law, this constitutes sensitive personal information subject to additional protections. This data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Consent Requirements

Given the sensitive nature of location and health data, we implement layered consent: (1) initial consent during onboarding covering core data processing, (2) separate granular consent for location tracking activated at first workout, (3) separate consent for wearable data syncing, and (4) optional consent for anonymized data contribution to aggregate fitness research.

Best Practices

  • Use plain language alongside legal terms — define jargon on first use and write at an 8th-grade reading level where possible.
  • Be specific about third-party services by name (Mixpanel, Stripe, Google Analytics) rather than vague references to "service providers."
  • Include a "last updated" date and describe how users will be notified of material changes (email, in-app banner, etc.).
  • Provide a data retention schedule with specific timeframes rather than "as long as necessary."
  • Address cookie consent with granular categories (strictly necessary, functional, analytics, advertising) per ePrivacy Directive requirements.
  • Include a direct contact method (email, form) for privacy inquiries with a stated response timeframe (e.g., 30 days for GDPR requests).

Safety Boundaries

  • Treat the output as informational drafting or issue spotting, not legal advice.
  • Identify the governing jurisdiction and relevant effective date; verify changing requirements against current primary sources.
  • Do not claim that language is compliant, enforceable, or complete. Flag uncertainty and recommend qualified counsel for material decisions.
  • Do not file, publish, accept, sign, or send legal terms without the user reviewing and explicitly authorizing that action.

Edge Cases

  • Apps targeting children or mixed-age audiences — COPPA (under 13, US) and Age Appropriate Design Code (UK) impose strict requirements including verifiable parental consent and data minimization. If age-gating isn't enforced, assume the policy must address child users.
  • Businesses that share data with affiliates or ad networks — CCPA considers this "selling" or "sharing" personal information even without monetary exchange. The policy must include a "Do Not Sell or Share" link and honor Global Privacy Control signals.
  • International data transfers post-Schrems II — If transferring EU data to the US, reference the EU-US Data Privacy Framework or Standard Contractual Clauses. Vague statements about "appropriate safeguards" are insufficient.
  • AI/ML model training on user data — If user data feeds into machine learning models, disclose this as a processing purpose with its own legal basis. Users may object under GDPR Article 22 to automated decision-making.
  • Acquisitions and data portability — The policy should state what happens to user data if the business is sold, merged, or goes bankrupt, as this is a required CCPA disclosure.

© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in legal-and-compliance/privacy-policy-drafting of seb1n/awesome-ai-agent-skills.

Open the folder on GitHubat commit 75865a5

Compare with similar skills

Privacy Policy Drafting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Policy Drafting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Policy Drafting this skillseb1n/awesome-ai-agent-skills206—~2.3kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from seb1n/awesome-ai-agent-skills

All 101 skills in this repo
  • Agent Red Teaming

    seb1n/awesome-ai-agent-skills

    Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

    206 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Human In The Loop

    seb1n/awesome-ai-agent-skills

    Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • MCP Server Building

    seb1n/awesome-ai-agent-skills

    Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • PDF Processing

    seb1n/awesome-ai-agent-skills

    Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Supply Chain Audit

    seb1n/awesome-ai-agent-skills

    Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

    206 GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Privacy Policy Drafting

What does Privacy Policy Drafting do?

Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions. Privacy Policy Drafting is an agent skill from seb1n/awesome-ai-agent-skills. Draft privacy-policy language and a review checklist tailored to a business model, data practices, and relevant jurisdictions.

When should I use Privacy Policy Drafting?

Privacy Policy Drafting fits situations like: the user requests a privacy policy; needs to map disclosures for GDPR; similar frameworks; do not use it to guarantee legal compliance.

How do I install Privacy Policy Drafting in Claude Code?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill privacy-policy-drafting -a claude-code`. Or copy the skill folder (legal-and-compliance/privacy-policy-drafting in seb1n/awesome-ai-agent-skills) into .claude/skills/privacy-policy-drafting in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Policy Drafting in Codex?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill privacy-policy-drafting -a codex`. Or copy the skill folder (legal-and-compliance/privacy-policy-drafting in seb1n/awesome-ai-agent-skills) into .agents/skills/privacy-policy-drafting in your project. Codex loads it when a task matches its description.

Can I use Privacy Policy Drafting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill privacy-policy-drafting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-policy-drafting, .gemini/skills/privacy-policy-drafting, .github/skills/privacy-policy-drafting and .opencode/skills/privacy-policy-drafting in your project.

What does Privacy Policy Drafting need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Policy Drafting is instructions for the agent only.

Does Privacy Policy Drafting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Policy Drafting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Policy Drafting use?

Privacy Policy Drafting is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Policy Drafting use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Policy Drafting?

Skills that share tags, products or a category with Privacy Policy Drafting: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Policy Drafting?

seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on August 9, 2026.

Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.