
Claude Skills by sunyifeisb-art
github.com/sunyifeisb-artGuides preparation of a gap analysis memorandum for an acquisition transaction by cross-referencing disclosure schedules against diligence findings and relevant representations to identify omissions, inconsistencies, and disclosure concerns.
Guides completion of a consent tracker, preparation of a consent analysis memo, and drafting of tailored consent request letters for an acquisition closing where multiple material contracts require consent, notice, or payoff coordination.
Redlining analysis loses discipline when the agent skips playbook hierarchy and fails to anchor each deviation to the governing transfer mechanism and transfer impact findings.
DPA redline reviews lose rigour when the agent treats playbook positions as optional and fails to cross-reference the broader commercial agreement when assessing risk of counterparty changes.
Gap analyses can fail when the agent treats privacy disclosures in isolation, misclassifies third-party data disclosures, omits sensitive-data limitation rights, or fails to reconcile policy statements against the actual processing inventory and vendor arrangements.
Portfolio-level data processing agreement amendment impact analyses fail when the agent assesses each agreement in isolation rather than systematically mapping every new or amended obligation across the portfolio and the agreement register matrix.
Multi-jurisdiction breach notification memos fail when the agent applies only federal frameworks and omits state-by-state notification deadlines, business-associate reporting chains, and cyber-insurance reporting obligations that may be triggered by the same incident.
Assess privacy-regulatory impact on counterparty relationships by classifying each relationship under the applicable privacy framework, checking whether the actual data flows and contract terms match that classification, and identifying any missing contractual, disclosure, registration, or consumer-rights steps.
Privacy policy compliance audits for fintech apps fail when the agent reviews the policy as a standalone document rather than reconciling it against the data inventory, sharing agreement, breach log, and investor due-diligence memo for cross-document consistency gaps.
Privacy policy compliance audits for fintech apps fail when the agent reviews the policy as a standalone document rather than reconciling it against the data inventory, sharing agreement, breach log, and investor due-diligence memo for cross-document consistency gaps.
Gap analyses for breach notification matters should use the internal threshold guidance as the primary benchmark, compare the draft report against the underlying forensic findings and incident timeline, and identify any omissions or inconsistencies affecting notification thresholds, timing, and content.
Breach notification schedule gap analyses require comparing each scheduled notification action against the applicable regulatory deadline, identifying whether notifications are past due or still pending, and checking whether the schedule is complete, timely, and aligned with the governing guidance.
Vendor DPA deviation reports are strongest when the agent benchmarks the agreement against the relevant internal privacy standards and any applicable external requirements, then converts each gap into a structured deviation analysis with practical negotiation guidance.
Regulatory undertaking gap analyses are strongest when the agent maps each undertaking commitment individually to the remediation plan and tests whether implementation evidence, timelines, ownership, and verification measures satisfy the commitment's specific requirements.
PIA/DPIA gap analyses fail when the agent uses only one benchmark, omits key elements of the applicable DPIA framework, or skips task-specific scope materials that may shape the memo's priorities.
Multi-regime privacy notice gap analyses improve when the agent uses the data processing inventory as the factual baseline, cross-checks current and planned processing against applicable disclosure requirements, and distinguishes present gaps from prospective ones.
Enterprise privacy program gap analyses fail when the agent reviews documents serially rather than building a cross-document picture of the program and reconciling it against applicable data-protection obligations simultaneously.
Healthcare breach notification letters fail when the agent does not anchor factual representations to the forensic investigation findings and does not flag inconsistencies between the notification template, incident memo, and compliance matrix in an accompanying cover memo.
Incident response policies for regulated manufacturers fail when the agent drafts a generic template rather than integrating the organisation-specific gap analysis findings, governance mandate, operational runbook, and regulatory guidance into a facility- and product-context-specific policy.
Board-level breach remediation memos fail when the agent does not integrate the forensic investigation findings, prior risk assessment gaps, and applicable regulatory obligations into a sequenced remediation plan with specific owners, timelines, and evidence of completion.
Drafting a GDPR-compliant data processing agreement for a cross-border health data analytics engagement fails when the agent does not reconcile conflicts among the controller’s data governance materials, the processor’s standard template, and the transfer-impact analysis before drafting, and does not apply the more protective standard where instructed.
External privacy notice drafts for digital health platforms fail when the agent does not anchor the notice's disclosures in the current data processing inventory and does not address additional jurisdiction-specific expansion and AI product integration obligations as distinct disclosure workstreams.
Cross-border data transfer agreement markups for clinical trial data fail when the agent applies generic negotiation positions rather than integrating the organisation's playbook, the applicable commercial agreement context, the due-diligence summary, and the internal email escalation positions into a coherent redline.
DPA markups with commentary memos fail when the analysis does not distinguish mandatory legal requirements from policy-driven positions and commercial preferences, and when the commentary does not connect security-history concerns to the relevant privacy and security provisions.
Regulatory inquiry responses involving health data sharing should be drafted by mapping each inquiry item to a corresponding response, preserving the distinction between the external response and any privileged internal analysis, and checking that representations align with the underlying factual record.
SCC addendum drafts fail when the agent selects the wrong SCC module for the controller-processor relationship, does not populate the Annexes from the engagement documents, and omits any separate UK transfer instrument when both EU and UK personal data are in scope.
Draft a supervisory-authority breach notification and a privileged internal memo by identifying the correct controller role, the applicable notification deadline, the required factual content, and the strategic disclosure risks created by the incident record.
Privacy policy updates for AI-powered health tools fail when the agent does not ground new disclosures in the product description and the privacy impact assessment, and does not separately memo the legal risks arising from the new product's data uses.
Data flow extraction from processing records fails when the agent does not systematically reconcile the primary record of processing against supporting agreements, transfer assessments, and technical architecture to surface discrepancies between the documented and actual data flows.
Regulatory response tracker construction benefits from reconciling requests across multiple regulatory inquiries into a unified tracker that accounts for overlapping requests, privilege implications, and preservation scope for each request.
Incident summary memos fail when the agent does not reconcile conflicting accounts across multiple incident-related documents into a single authoritative incident narrative with discrepancies explicitly flagged.
State privacy regulation obligation extraction fails when the agent does not apply each statute's applicability thresholds to the company's actual data profile and does not map extracted obligations against existing compliance gaps evidenced by the company's own documents.
Multi-state privacy obligation extraction memos fail when the agent does not apply each statute's applicability threshold to the company's actual profile before extracting obligations and does not differentiate between obligations that are unique to one state and those that are shared across states.
Multi-jurisdictional compliance obligation matrices for health-tech platforms fail when the agent does not assess each statute's applicability to the company's current and planned data architecture and does not use prior incidents as evidence of existing compliance gaps.
Incident response plan issue memos for healthcare organisations fail when the agent does not cross-reference the incident response plan against supporting materials such as audit findings, insurance terms, vendor agreements, and compliance memoranda to identify structural gaps between the plan's written requirements and the organisation's actual capabilities.
AG data breach CID issue memos fail when the agent identifies compliance gaps in the abstract rather than connecting each gap to the specific requests in the CID and the evidence (or absence of evidence) in the company’s own documents.
TIA issue memos for cross-border EU data transfers fail when the agent does not assess the TIA's methodology and conclusions against the destination-country legal analysis required by Schrems II, and does not identify where multiple transfer mechanisms in the same engagement have been incorrectly applied or are inconsistent.
Data transfer agreement issue memoranda should be framed by the relevant supervisory communications and guidance, and should reconcile transfer-mechanism status, anonymisation analysis, and the actual data inventory against the agreement’s provisions.
Data subject rights gap analyses are strongest when the agent maps the applicable rights framework against operational evidence showing how requests are actually handled in practice, rather than relying only on written policies or procedures.
Multi-jurisdiction breach notification deadline matrices fail when the agent does not use the jurisdiction map as the authoritative source for identifying which jurisdictions have affected individuals and does not separate overdue notifications from pending notifications.
Data localisation memos for multi-country market expansions fail when the agent applies generic cross-border transfer analysis without addressing each target jurisdiction's specific localisation or residency requirements and without assessing whether the current cloud and infrastructure architecture can be adapted to satisfy those requirements.
Counterparty DPA issue identification memos fail when the agent does not use the internal data protection playbook as the primary benchmark and does not reconcile the executed MSA's scope and liability provisions against the DPA's terms before producing an issue-focused memorandum.
IRP review memos fail when the agent assesses the updated plan against general regulatory standards without using prior incident materials as evidence of specific gaps the new plan must close, and without assessing whether governance materials and audit findings impose additional requirements the plan must satisfy.
GDPR enforcement guidance executive briefs fail when the agent summarizes the guidance generically rather than filtering its implications through the company's specific processing activities and compliance tracker to produce actionable, company-specific takeaways for cross-functional leadership.
CPRA service-provider contract triage requires first classifying each counterparty by its correct legal relationship before assessing contractual adequacy, and using any existing internal gap analysis and enforcement materials as framing inputs that set triage priorities.
Cross-border vendor transfer triage fails when the agent does not use the inventory baseline provided in the task materials, does not verify claimed transfer mechanisms against independent confirmation materials, and does not assess each vendor relationship against the transfer destinations and data categories evidenced by the record.
Counterparty bridge loan markups require analysis that connects conversion mechanics, investor control provisions, runway implications, and pay-to-play interactions — not just issue-by-issue enumeration.
IRA markup analysis requires evaluating the cumulative effect of changes to registration rights, information rights, pay-to-play provisions, and consistency with the agreed term sheet — not treating revisions as isolated issues.
Purchase agreement markup analysis should detect economically important changes hidden in definitions, schedules, and exhibits; assess the impact of preference, conversion, redemption, and control mechanics across scenarios; and cross-check representation changes against diligence materials rather than only listing revised provisions.
Term-sheet-to-agreement comparison requires classifying each deviation by type and affected party, reading defined-term exceptions that may embed substantive changes, and assessing cumulative dilution impact rather than merely listing differences.