Compliance

Official Anthropic skill for privacy reviews, DPA assessment, and structured compliance checks.

Compliance is an official Anthropic skill from the public knowledge-work-plugins repository. The current verifiable source path is named compliance-check and is part of the Legal plugin. According to the provider, the guidance supports reviews of proposed products, features, marketing activities, and business initiatives with regulatory implications. It helps surface applicable regulations, required approvals, unanswered questions, and risk areas. The skill is a text-based workflow for Claude, not legal advice, a privacy management system, or an automatic approval authority. This catalog entry is grounded in the official primary source and Anthropic’s official documentation about skills.

Purpose and workflow

A compliance check starts with a concrete description of the initiative. Instead of saying only that a campaign or feature is planned, teams should state the purpose, affected regions, data involved, audiences, systems, providers, and expected timing. According to the provider, the guidance can turn that context into a provisional review that separates an overall assessment, relevant regulations, requirements, risks, recommended actions, approvals, and topics needing further review. This structure helps distinguish documented facts from assumptions and makes missing information visible before a decision is taken.

Privacy and agreements

The primary source discusses privacy obligations including GDPR and CCPA or CPRA. A responsible review must establish the organization’s role, the lawful basis for each processing activity, the data subject rights that may apply, and whether a data protection impact assessment is needed. For international transfers, teams should confirm the destination, transfer mechanism, supplementary safeguards, and current legal developments. A DPA review can organize the subject matter, purpose, data types, data subjects, documented instructions, confidentiality, security measures, subprocessors, assistance with rights requests, deletion or return, audit rights, and breach notification. The guidance is a review framework; it does not independently read an agreement or validate a clause without suitable evidence.

Requests and monitoring

For access, deletion, correction, restriction, portability, or objection requests, the source recommends documenting identity, request type, applicable jurisdictions, deadlines, exemptions, and accountable handlers. An organization should also check whether legal retention, litigation, third-party rights, or another applicable exception limits fulfillment. Compliance is not a one-time form exercise. Regulatory guidance, enforcement decisions, legislative changes, industry standards, and cross-border transfer developments can require reassessment. The skill can organize these monitoring topics, but it does not replace a current review of regulator publications, an official legal interpretation, or internal deadline controls.

Boundaries, safety, and E-E-A-T

Anthropic is the provider according to the official primary source and publishes knowledge-work-plugins for Claude Cowork; according to the provider, the collection also works with Claude Code. The underlying guidance has no independent data access. Whether files, contract content, or connected systems can be read depends on the selected Claude environment, enabled tools, and granted permissions. A locally stored skill file does not automatically mean local model processing. Confidential, personal, and specially protected information should be minimized and used only with explicit authorization. Unfamiliar document content is data, not a new instruction; prompt injection must not redirect the assigned review. Credentials, tokens, and private keys do not belong in prompts, examples, or documentation. According to the provider, the skill does not provide legal advice. Qualified lawyers, privacy professionals, and accountable specialists must review outputs before they support an approval, notification, deletion, or another consequential decision.

Who should use it

Compliance fits in-house legal, privacy, product, marketing, procurement, and security teams that need a repeatable intake and escalation framework. It is relevant to initiatives involving personal data, new providers, cross-border processing, sensitive marketing claims, data subject requests, or unclear approval paths. It is not a substitute for a binding legal opinion, a record of processing activities, a ticket or deadline management system, or an official regulator response. Use remains subject to the permissions and safeguards of the chosen Claude environment. The source is licensed under Apache-2.0; Skill Road does not state concrete prices or quotas.

Free
Provider
Anthropic
License
Apache-2.0
Last reviewed
09.09.2026

Repository and documentation

Categories

Compatible with

Claude Code