Skip to content

Privacy Notice Generator Skill

The Privacy Notice Generator is a specialized skill designed to automate the drafting of comprehensive, regulatory-compliant privacy policies and notices. It is tailored to address the strict compliance standards of the European Union, European Economic Area (EEA), and related international frameworks.

1. Description

This skill configures the AI Agent to draft highly structured, legally compliant privacy notices formatted in Markdown. It aligns generated documents with modern transparency standards, ensuring all mandatory legal declarations are correctly addressed for the selected audience and jurisdiction.

2. Jurisdictions

The skill incorporates specific local statutory additions and national derogations across the EU/EEA and UK:

  • Germany: GDPR (DSGVO) + Federal Data Protection Act (BDSG) + Telecommunications Digital Services Data Protection Act (TDDDG).
  • France: GDPR (RGPD) + Data Protection Act (Loi Informatique et Libertés - LIL) + Law for Confidence in the Digital Economy (LCEN).
  • United Kingdom: UK General Data Protection Regulation (UK GDPR) + Data Protection Act 2018 (DPA 2018).
  • Other Covered Jurisdictions: Austria, Italy, Spain, Netherlands, Belgium, Ireland, and general EU/EEA compliance templates.

3. What It Does in Detail

When activated, the Privacy Notice Generator directs the agent's reasoning engine to systematically address critical data privacy requirements. It performs the following functions:

Mandatory Disclosures Ingestion

  • Article 13 GDPR (Direct Collection): Automatically drafts notices for scenarios where data is collected directly from the data subject (e.g., website signup forms, contact forms).
  • Article 14 GDPR (Indirect Collection): Builds compliant disclosures for cases where personal data is obtained from third parties or public sources, outlining the categories of data and original sources.

Specific Notice Types Supported

  1. Website/App Privacy Policy: Covers cookie declarations, tracking technologies, analytics, external integrations (e.g., Google Analytics, Stripe, HubSpot), and public-facing processing activities.
  2. Applicant Notice (Bewerber-Datenschutz): Informational clauses specifically tailored for HR recruitment pipelines, candidate screening, application storage retention limits, and candidate rights.
  3. Employee Notice (Beschäftigten-Datenschutz): Internal processing statements for active staff members covering payroll, performance management, system monitoring, and internal tool usage.
  4. Business Partner Notice: Optimized disclosures for B2B vendors, suppliers, contractors, and client representatives.
  5. B2C Customer Notice: Structured disclosures addressing consumer transactions, purchasing habits, marketing consents, and customer service records.

Regulatory Alignments

  • EU AI Act Transparency: Integrates necessary declarations if the application uses AI tools, automated decision-making, or profiling systems.
  • International Data Transfers: Includes provisions for data transfers outside the EEA/UK, referencing specific transfer mechanisms such as adequacy decisions or Standard Contractual Clauses (SCCs).
  • Data Subject Rights: Automatically outlines rights to access, rectification, erasure, restriction, objection, portability, and the right to lodge a complaint with a supervisory authority.

4. Recommendation (When to use)

Enable this skill whenever you need to:

  • Draft a new privacy policy or notice for a digital product, mobile application, or marketing landing page.
  • Respond to user inquiries containing terms such as "Datenschutzerklärung", "politique de confidentialité", or "privacy notice".
  • Audit or update existing employee, candidate, or business partner data documentation to ensure they align with the latest regional amendments.
  • Incorporate EU AI Act transparency disclosures into existing public-facing policies.

Contact Us