Loading...
Loading...
Analyze data privacy compliance requirements under GDPR, Taiwan's Personal Data Protection Act (PDPA), and related regulations. Use this skill when the user needs to assess data privacy obligations, design compliant data handling processes, evaluate cross-border data transfer risks, or understand data subject rights — even if they say 'do we comply with GDPR', 'can we collect this data', 'what are our privacy obligations', or 'how do we handle user data in Taiwan'.
npx skill4agent add asgard-ai-platform/skills law-gdpr-pdpaIRON LAW: No Collection Without Legal Basis
You CANNOT collect or process personal data just because you want to.
Every data processing activity requires a legal basis:
- GDPR: 6 legal bases (consent, contract, legal obligation, vital interests, public task, legitimate interests)
- Taiwan PDPA: Specific purposes listed in the act, with consent as primary basis
"We need this data for analytics" is NOT a legal basis.| Aspect | GDPR | Taiwan PDPA |
|---|---|---|
| Scope | Any org processing EU residents' data | Any org processing personal data in Taiwan |
| Legal bases | 6 enumerated bases | Consent-centric + specific purpose limitation |
| Consent standard | Freely given, specific, informed, unambiguous, opt-in | Written consent required for sensitive data; implied consent possible for non-sensitive |
| Data subject rights | Access, rectification, erasure, portability, restriction, objection | Access, correction, deletion, cessation of processing |
| Cross-border transfer | Adequacy decision, SCCs, BCRs | Requires central authority approval or adequate protection |
| Breach notification | 72 hours to authority | Report to authority + notify affected individuals "without delay" |
| Penalties | Up to €20M or 4% global turnover | Up to NT$500K per violation (criminal penalties possible) |
| DPO required? | Yes (in certain cases) | Not explicitly required |
# Privacy Compliance Assessment: {Organization}
## Data Inventory
| Data Category | Types | Legal Basis | Purpose | Retention |
|-------------|-------|-------------|---------|-----------|
| {category} | {specific fields} | {basis} | {why collected} | {period} |
## Compliance Gaps
| Requirement | Status | Gap | Priority |
|------------|--------|-----|----------|
| Legal basis | ✓/✗ | {detail} | H/M/L |
| Consent mechanism | ✓/✗ | ... | ... |
| Data subject rights | ✓/✗ | ... | ... |
| Breach notification | ✓/✗ | ... | ... |
| Cross-border transfer | ✓/✗ | ... | ... |
## Remediation Plan
1. {action} — priority: {H/M/L} — timeline: {X weeks}references/gdpr-articles.mdreferences/taiwan-pdpa.md