⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.
Privacy Compliance Navigator
Tools and guidance for multi-regulation privacy compliance across 9 major global privacy frameworks, DPA review, and data subject request lifecycle management.
Table of Contents
Tools
Privacy Regulation Checker
Determines which privacy regulations apply to an organization based on its location, data subjects, data types, and processing activities. Generates a compliance obligations matrix and flags gaps.
# Basic check — organization in Germany processing EU and US data
python scripts/privacy_regulation_checker.py \
--org-location DE \
--data-subjects EU,US \
--data-types personal,sensitive,financial \
--processing-activities marketing,analytics,hr
# JSON output for integration
python scripts/privacy_regulation_checker.py \
--org-location SG \
--data-subjects SG,AU,CN \
--data-types personal,health \
--processing-activities healthcare,research \
--json
# Include gap analysis against current practices
python scripts/privacy_regulation_checker.py \
--org-location US-CA \
--data-subjects EU,US,BR \
--data-types personal,biometric \
--processing-activities ecommerce,profiling \
--current-practices consent_mechanism,breach_process,retention_policy
Determines:
- Which of 9 regulations apply based on territorial scope rules
- Key obligations per applicable regulation
- Data subject rights required per regulation
- Response timelines per regulation
- Gap analysis when current practices are provided
Output:
- Applicable regulations list with confidence level
- Per-regulation obligations matrix
- Gap analysis with risk ratings
- Recommended priority actions
DSR Tracker
Manages Data Subject Request lifecycle across multiple regulations with deadline calculation, status tracking, and overdue alerts.
# Add a new GDPR access request
python scripts/dsr_tracker.py add \
--type access --regulation gdpr \
--subject "Jane Smith" --email "jane@example.com"
# Add CCPA deletion request
python scripts/dsr_tracker.py add \
--type deletion --regulation ccpa \
--subject "John Doe" --email "john@example.com"
# List all open requests
python scripts/dsr_tracker.py list
# List overdue requests only
python scripts/dsr_tracker.py list --overdue
# Update request status
python scripts/dsr_tracker.py update --id DSR-0001 --status verified
# Dashboard view with time remaining
python scripts/dsr_tracker.py dashboard
# Export as JSON
python scripts/dsr_tracker.py dashboard --json
Supported Request Types:
| Type |
GDPR Art. |
CCPA Section |
LGPD Art. |
| Access |
Art. 15 |
§1798.100 |
Art. 18 |
| Deletion/Erasure |
Art. 17 |
§1798.105 |
Art. 18(VI) |
| Correction/Rectification |
Art. 16 |
§1798.106 |
Art. 18(III) |
| Portability |
Art. 20 |
§1798.130 |
Art. 18(V) |
| Restriction |
Art. 18 |
— |
Art. 18(IV) |
| Objection |
Art. 21 |
§1798.120 |
Art. 18(IV) |
| Automated Decision Opt-Out |
Art. 22 |
§1798.185 |
Art. 20 |
| Withdraw Consent |
Art. 7(3) |
— |
Art. 18(IX) |
Deadline Calculation:
| Regulation |
Initial Deadline |
Extension |
Extension Deadline |
| GDPR |
30 calendar days |
+60 days (complex) |
90 calendar days |
| CCPA |
10 business days (ack) + 45 calendar days |
+45 days |
90 calendar days |
| LGPD |
15 calendar days |
— |
— |
| POPIA |
30 calendar days |
— |
— |
| PIPEDA |
30 calendar days |
+30 days |
60 calendar days |
| PDPA (SG) |
30 calendar days |
— |
— |
| Privacy Act (AU) |
30 calendar days |
+30 days |
60 calendar days |
| PIPL |
15 calendar days |
+15 days |
30 calendar days |
| UK GDPR |
30 calendar days |
+60 days |
90 calendar days |
Statuses: received → verified → processing → completed | denied | extended
Reference Guides
Global Privacy Regulations
references/global_privacy_regulations.md
Comprehensive comparison of 9 major privacy regulations covering:
- Territorial scope and applicability criteria
- Legal bases for processing
- Data subject rights comparison matrix
- Breach notification requirements and timelines
- Cross-border transfer mechanisms
- DPO requirements
- Penalty structures
DPA Review Checklist
references/dpa_review_checklist.md
Complete Data Processing Agreement review guide:
- Art. 28 GDPR required elements
- 10 processor obligations with analysis points
- International transfer mechanisms (SCCs June 2021, module selection)
- Transfer impact assessment requirements
- Common DPA issues with risk levels
- Practical negotiation considerations
DSR Handling Guide
references/dsr_handling_guide.md
Data Subject Request handling reference:
- 8 request types with intake procedures
- Identity verification methods
- Response timelines per regulation
- Exemptions by regulation
- 6-step response process
- Regulatory monitoring approach
Workflows
Workflow 1: Regulation Applicability Assessment
Step 1: Identify organization parameters
→ Location, data subjects, data types, processing activities
Step 2: Run regulation checker
→ python scripts/privacy_regulation_checker.py --org-location [LOC] ...
Step 3: Review applicable regulations and obligations
→ Prioritize by risk (penalties, data volume, enforcement activity)
Step 4: Gap analysis against current practices
→ Re-run with --current-practices flag
Step 5: Build remediation roadmap
→ Address critical gaps first (missing legal basis, no breach process)
Workflow 2: Data Subject Request Handling
Step 1: Receive and log request
→ python scripts/dsr_tracker.py add --type [type] --regulation [reg] ...
Step 2: Verify identity (proportionate to sensitivity)
→ See references/dsr_handling_guide.md for methods
→ python scripts/dsr_tracker.py update --id [ID] --status verified
Step 3: Gather data from all systems
→ python scripts/dsr_tracker.py update --id [ID] --status processing
Step 4: Apply exemptions if applicable
→ Check references/dsr_handling_guide.md exemptions table
Step 5: Prepare and send response within deadline
→ python scripts/dsr_tracker.py update --id [ID] --status completed
Step 6: Monitor dashboard for overdue requests
→ python scripts/dsr_tracker.py dashboard
Workflow 3: DPA Review
Step 1: Check DPA against Art. 28 required elements
→ Use references/dpa_review_checklist.md
Step 2: Verify processor obligations (10 items)
→ Sub-processing, deletion, audit rights, etc.
Step 3: Assess international transfer provisions
→ SCC module selection (C2P, C2C, P2P, P2C)
→ Transfer impact assessment
→ Supplementary measures
Step 4: Review practical considerations
→ Liability caps, insurance, termination, data locations
Step 5: Document findings and negotiate amendments
Workflow 4: Multi-Regulation Compliance Program
Step 1: Run regulation checker for full scope
→ python scripts/privacy_regulation_checker.py [params]
Step 2: Map overlapping obligations across regulations
→ Use references/global_privacy_regulations.md comparison matrix
Step 3: Build unified controls (satisfy strictest requirement)
→ GDPR-first approach covers most other regulations
Step 4: Layer regulation-specific requirements
→ CCPA opt-out mechanisms, LGPD DPO, PIPL localization
Step 5: Monitor regulatory changes
→ See references/dsr_handling_guide.md monitoring approach
Troubleshooting
| Problem |
Possible Cause |
Resolution |
| Regulation checker flags unexpected regulation |
Data subjects in jurisdiction not considered |
Review data flow maps; even indirect data collection (analytics, cookies) can trigger territorial scope |
| DSR deadline missed |
Request not logged promptly or status not updated |
Implement intake SLA (log within 24 hours); use dashboard daily for overdue alerts |
| DPA missing Art. 28 elements |
Template from processor is incomplete |
Use DPA review checklist to identify gaps; require amendments before signing |
| Cross-border transfer mechanism unclear |
Multiple transfer layers (controller → processor → sub-processor) |
Map full data flow chain; each transfer leg needs its own mechanism |
| Conflicting obligations across regulations |
Retention vs. deletion requirements differ |
Document conflicts; apply strictest obligation unless local law mandates otherwise; seek legal counsel |
| Identity verification proportionality unclear |
Over-verification deters legitimate requests |
Match verification to risk: low-risk data = email confirmation; high-risk = ID verification |
Success Criteria
- All applicable regulations identified and mapped — regulation checker confirms coverage with zero unaddressed jurisdictions where data subjects reside
- 100% of DSRs responded within statutory deadlines — dashboard shows zero overdue requests; extension documented where used
- DPAs reviewed against Art. 28 checklist before signing — all 10 processor obligations addressed; international transfer mechanisms validated
- Compliance matrix maintained and current — quarterly review of obligations per regulation with change log
- Regulatory monitoring active — escalation criteria defined; new regulation applicability assessed within 30 days of enactment
Scope & Limitations
In Scope:
- Applicability assessment for 9 major privacy regulations
- Data subject request tracking with multi-regulation deadline calculation
- DPA review against Art. 28 GDPR requirements
- Cross-regulation obligation mapping
- Gap analysis against current practices
- International transfer mechanism assessment
Out of Scope:
- Legal advice on specific legal basis selection — consult qualified privacy counsel
- Supervisory authority filings or breach notifications
- Cookie consent implementation or consent management platform configuration
- Binding Corporate Rules (BCR) application process
- Sector-specific regulations (HIPAA, FERPA, GLBA) beyond the 9 covered frameworks
- Data Protection Impact Assessments (see
dpia-assessment skill)
Anti-Patterns
| Anti-Pattern |
Why It Fails |
Better Approach |
| GDPR-only compliance |
Organizations assume GDPR covers all obligations; miss CCPA opt-out requirements, LGPD DPO mandate, PIPL data localization |
Run regulation checker against all jurisdictions where data subjects reside; layer regulation-specific controls |
| One-size-fits-all DSR process |
Applying GDPR 30-day timeline to all regulations misses CCPA 10-business-day acknowledgment or PIPL 15-day deadline |
Configure per-regulation deadlines; use DSR tracker with regulation parameter for accurate deadline calculation |
| Ignoring sub-processor chains in DPA review |
DPA covers direct processor but sub-processors transfer data to third countries without TIA |
Map full processing chain in DPA review; require Art. 28(2) sub-processor obligations; validate each transfer leg |
| Treating privacy as a one-time project |
Regulations evolve; new laws enacted; enforcement priorities shift |
Implement regulatory monitoring with escalation criteria; quarterly compliance reviews |
Tool Reference
privacy_regulation_checker.py
Determines applicable privacy regulations and maps obligations based on organization parameters.
| Flag |
Required |
Description |
--org-location <code> |
Yes |
Organization headquarters (ISO country code, e.g., DE, US-CA, SG) |
--data-subjects <list> |
Yes |
Comma-separated locations of data subjects (EU, US, BR, ZA, CA, SG, AU, CN, UK) |
--data-types <list> |
Yes |
Comma-separated data types (personal, sensitive, financial, health, biometric, children) |
--processing-activities <list> |
Yes |
Comma-separated activities (marketing, analytics, hr, ecommerce, profiling, healthcare, research) |
--current-practices <list> |
No |
Comma-separated current practices for gap analysis |
--json |
No |
Output in JSON format |
dsr_tracker.py
Tracks Data Subject Request lifecycle with multi-regulation deadline calculation.
| Subcommand |
Description |
add |
Add new DSR (--type, --regulation, --subject, --email required) |
list |
List all requests (--overdue for overdue only) |
update |
Update request status (--id, --status required) |
dashboard |
Show dashboard with time remaining and alerts |
| Flag |
Description |
--type <type> |
Request type: access, deletion, correction, portability, restriction, objection, automated_decision, withdraw_consent |
--regulation <reg> |
Regulation: gdpr, ccpa, lgpd, popia, pipeda, pdpa, privacy_act_au, pipl, uk_gdpr |
--subject <name> |
Data subject name |
--email <email> |
Data subject email |
--id <id> |
Request ID (e.g., DSR-0001) |
--status <status> |
Status: received, verified, processing, completed, denied, extended |
--overdue |
Filter to overdue requests only |
--json |
Output in JSON format |
--data-file <path> |
Custom data file path (default: dsr_requests.json) |
1---2name: privacy-compliance3description: Multi-regulation privacy compliance navigator. Use for GDPR, CCPA, LGPD, POPIA, PIPEDA, PDPA, Privacy Act, PIPL, UK GDPR compliance assessments, DPA reviews, and data subject request management.4license: MIT + Commons Clause5---6> **⚠️ EXPERIMENTAL** — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.
7
8# Privacy Compliance Navigator
9
10Tools and guidance for multi-regulation privacy compliance across 9 major global privacy frameworks, DPA review, and data subject request lifecycle management.
11
12---
13
14## Table of Contents
15
16- [Tools](#tools)
17 - [Privacy Regulation Checker](#privacy-regulation-checker)
18 - [DSR Tracker](#dsr-tracker)
19- [Reference Guides](#reference-guides)
20- [Workflows](#workflows)
21- [Troubleshooting](#troubleshooting)
22- [Success Criteria](#success-criteria)
23- [Scope & Limitations](#scope--limitations)
24- [Anti-Patterns](#anti-patterns)
25- [Tool Reference](#tool-reference)
26
27---
28
29## Tools
30
31### Privacy Regulation Checker
32
33Determines which privacy regulations apply to an organization based on its location, data subjects, data types, and processing activities. Generates a compliance obligations matrix and flags gaps.
34
35```bash
36# Basic check — organization in Germany processing EU and US data
37python scripts/privacy_regulation_checker.py \
38 --org-location DE \
39 --data-subjects EU,US \
40 --data-types personal,sensitive,financial \
41 --processing-activities marketing,analytics,hr
42
43# JSON output for integration
44python scripts/privacy_regulation_checker.py \
45 --org-location SG \
46 --data-subjects SG,AU,CN \
47 --data-types personal,health \
48 --processing-activities healthcare,research \
49 --json
50
51# Include gap analysis against current practices
52python scripts/privacy_regulation_checker.py \
53 --org-location US-CA \
54 --data-subjects EU,US,BR \
55 --data-types personal,biometric \
56 --processing-activities ecommerce,profiling \
57 --current-practices consent_mechanism,breach_process,retention_policy
58```
59
60**Determines:**
61- Which of 9 regulations apply based on territorial scope rules
62- Key obligations per applicable regulation
63- Data subject rights required per regulation
64- Response timelines per regulation
65- Gap analysis when current practices are provided
66
67**Output:**
68- Applicable regulations list with confidence level
69- Per-regulation obligations matrix
70- Gap analysis with risk ratings
71- Recommended priority actions
72
73---
74
75### DSR Tracker
76
77Manages Data Subject Request lifecycle across multiple regulations with deadline calculation, status tracking, and overdue alerts.
78
79```bash
80# Add a new GDPR access request
81python scripts/dsr_tracker.py add \
82 --type access --regulation gdpr \
83 --subject "Jane Smith" --email "jane@example.com"
84
85# Add CCPA deletion request
86python scripts/dsr_tracker.py add \
87 --type deletion --regulation ccpa \
88 --subject "John Doe" --email "john@example.com"
89
90# List all open requests
91python scripts/dsr_tracker.py list
92
93# List overdue requests only
94python scripts/dsr_tracker.py list --overdue
95
96# Update request status
97python scripts/dsr_tracker.py update --id DSR-0001 --status verified
98
99# Dashboard view with time remaining
100python scripts/dsr_tracker.py dashboard
101
102# Export as JSON
103python scripts/dsr_tracker.py dashboard --json
104```
105
106**Supported Request Types:**
107
108| Type | GDPR Art. | CCPA Section | LGPD Art. |
109|------|-----------|-------------|-----------|
110| Access | Art. 15 | §1798.100 | Art. 18 |
111| Deletion/Erasure | Art. 17 | §1798.105 | Art. 18(VI) |
112| Correction/Rectification | Art. 16 | §1798.106 | Art. 18(III) |
113| Portability | Art. 20 | §1798.130 | Art. 18(V) |
114| Restriction | Art. 18 | — | Art. 18(IV) |
115| Objection | Art. 21 | §1798.120 | Art. 18(IV) |
116| Automated Decision Opt-Out | Art. 22 | §1798.185 | Art. 20 |
117| Withdraw Consent | Art. 7(3) | — | Art. 18(IX) |
118
119**Deadline Calculation:**
120
121| Regulation | Initial Deadline | Extension | Extension Deadline |
122|-----------|-----------------|-----------|-------------------|
123| GDPR | 30 calendar days | +60 days (complex) | 90 calendar days |
124| CCPA | 10 business days (ack) + 45 calendar days | +45 days | 90 calendar days |
125| LGPD | 15 calendar days | — | — |
126| POPIA | 30 calendar days | — | — |
127| PIPEDA | 30 calendar days | +30 days | 60 calendar days |
128| PDPA (SG) | 30 calendar days | — | — |
129| Privacy Act (AU) | 30 calendar days | +30 days | 60 calendar days |
130| PIPL | 15 calendar days | +15 days | 30 calendar days |
131| UK GDPR | 30 calendar days | +60 days | 90 calendar days |
132
133**Statuses:** received → verified → processing → completed | denied | extended
134
135---
136
137## Reference Guides
138
139### Global Privacy Regulations
140`references/global_privacy_regulations.md`
141
142Comprehensive comparison of 9 major privacy regulations covering:
143- Territorial scope and applicability criteria
144- Legal bases for processing
145- Data subject rights comparison matrix
146- Breach notification requirements and timelines
147- Cross-border transfer mechanisms
148- DPO requirements
149- Penalty structures
150
151### DPA Review Checklist
152`references/dpa_review_checklist.md`
153
154Complete Data Processing Agreement review guide:
155- Art. 28 GDPR required elements
156- 10 processor obligations with analysis points
157- International transfer mechanisms (SCCs June 2021, module selection)
158- Transfer impact assessment requirements
159- Common DPA issues with risk levels
160- Practical negotiation considerations
161
162### DSR Handling Guide
163`references/dsr_handling_guide.md`
164
165Data Subject Request handling reference:
166- 8 request types with intake procedures
167- Identity verification methods
168- Response timelines per regulation
169- Exemptions by regulation
170- 6-step response process
171- Regulatory monitoring approach
172
173---
174
175## Workflows
176
177### Workflow 1: Regulation Applicability Assessment
178
179```
180Step 1: Identify organization parameters
181 → Location, data subjects, data types, processing activities
182
183Step 2: Run regulation checker
184 → python scripts/privacy_regulation_checker.py --org-location [LOC] ...
185
186Step 3: Review applicable regulations and obligations
187 → Prioritize by risk (penalties, data volume, enforcement activity)
188
189Step 4: Gap analysis against current practices
190 → Re-run with --current-practices flag
191
192Step 5: Build remediation roadmap
193 → Address critical gaps first (missing legal basis, no breach process)
194```
195
196### Workflow 2: Data Subject Request Handling
197
198```
199Step 1: Receive and log request
200 → python scripts/dsr_tracker.py add --type [type] --regulation [reg] ...
201
202Step 2: Verify identity (proportionate to sensitivity)
203 → See references/dsr_handling_guide.md for methods
204 → python scripts/dsr_tracker.py update --id [ID] --status verified
205
206Step 3: Gather data from all systems
207 → python scripts/dsr_tracker.py update --id [ID] --status processing
208
209Step 4: Apply exemptions if applicable
210 → Check references/dsr_handling_guide.md exemptions table
211
212Step 5: Prepare and send response within deadline
213 → python scripts/dsr_tracker.py update --id [ID] --status completed
214
215Step 6: Monitor dashboard for overdue requests
216 → python scripts/dsr_tracker.py dashboard
217```
218
219### Workflow 3: DPA Review
220
221```
222Step 1: Check DPA against Art. 28 required elements
223 → Use references/dpa_review_checklist.md
224
225Step 2: Verify processor obligations (10 items)
226 → Sub-processing, deletion, audit rights, etc.
227
228Step 3: Assess international transfer provisions
229 → SCC module selection (C2P, C2C, P2P, P2C)
230 → Transfer impact assessment
231 → Supplementary measures
232
233Step 4: Review practical considerations
234 → Liability caps, insurance, termination, data locations
235
236Step 5: Document findings and negotiate amendments
237```
238
239### Workflow 4: Multi-Regulation Compliance Program
240
241```
242Step 1: Run regulation checker for full scope
243 → python scripts/privacy_regulation_checker.py [params]
244
245Step 2: Map overlapping obligations across regulations
246 → Use references/global_privacy_regulations.md comparison matrix
247
248Step 3: Build unified controls (satisfy strictest requirement)
249 → GDPR-first approach covers most other regulations
250
251Step 4: Layer regulation-specific requirements
252 → CCPA opt-out mechanisms, LGPD DPO, PIPL localization
253
254Step 5: Monitor regulatory changes
255 → See references/dsr_handling_guide.md monitoring approach
256```
257
258---
259
260## Troubleshooting
261
262| Problem | Possible Cause | Resolution |
263|---------|---------------|------------|
264| Regulation checker flags unexpected regulation | Data subjects in jurisdiction not considered | Review data flow maps; even indirect data collection (analytics, cookies) can trigger territorial scope |
265| DSR deadline missed | Request not logged promptly or status not updated | Implement intake SLA (log within 24 hours); use dashboard daily for overdue alerts |
266| DPA missing Art. 28 elements | Template from processor is incomplete | Use DPA review checklist to identify gaps; require amendments before signing |
267| Cross-border transfer mechanism unclear | Multiple transfer layers (controller → processor → sub-processor) | Map full data flow chain; each transfer leg needs its own mechanism |
268| Conflicting obligations across regulations | Retention vs. deletion requirements differ | Document conflicts; apply strictest obligation unless local law mandates otherwise; seek legal counsel |
269| Identity verification proportionality unclear | Over-verification deters legitimate requests | Match verification to risk: low-risk data = email confirmation; high-risk = ID verification |
270
271---
272
273## Success Criteria
274
275- **All applicable regulations identified and mapped** — regulation checker confirms coverage with zero unaddressed jurisdictions where data subjects reside
276- **100% of DSRs responded within statutory deadlines** — dashboard shows zero overdue requests; extension documented where used
277- **DPAs reviewed against Art. 28 checklist before signing** — all 10 processor obligations addressed; international transfer mechanisms validated
278- **Compliance matrix maintained and current** — quarterly review of obligations per regulation with change log
279- **Regulatory monitoring active** — escalation criteria defined; new regulation applicability assessed within 30 days of enactment
280
281---
282
283## Scope & Limitations
284
285**In Scope:**
286- Applicability assessment for 9 major privacy regulations
287- Data subject request tracking with multi-regulation deadline calculation
288- DPA review against Art. 28 GDPR requirements
289- Cross-regulation obligation mapping
290- Gap analysis against current practices
291- International transfer mechanism assessment
292
293**Out of Scope:**
294- Legal advice on specific legal basis selection — consult qualified privacy counsel
295- Supervisory authority filings or breach notifications
296- Cookie consent implementation or consent management platform configuration
297- Binding Corporate Rules (BCR) application process
298- Sector-specific regulations (HIPAA, FERPA, GLBA) beyond the 9 covered frameworks
299- Data Protection Impact Assessments (see `dpia-assessment` skill)
300
301---
302
303## Anti-Patterns
304
305| Anti-Pattern | Why It Fails | Better Approach |
306|-------------|-------------|-----------------|
307| **GDPR-only compliance** | Organizations assume GDPR covers all obligations; miss CCPA opt-out requirements, LGPD DPO mandate, PIPL data localization | Run regulation checker against all jurisdictions where data subjects reside; layer regulation-specific controls |
308| **One-size-fits-all DSR process** | Applying GDPR 30-day timeline to all regulations misses CCPA 10-business-day acknowledgment or PIPL 15-day deadline | Configure per-regulation deadlines; use DSR tracker with regulation parameter for accurate deadline calculation |
309| **Ignoring sub-processor chains in DPA review** | DPA covers direct processor but sub-processors transfer data to third countries without TIA | Map full processing chain in DPA review; require Art. 28(2) sub-processor obligations; validate each transfer leg |
310| **Treating privacy as a one-time project** | Regulations evolve; new laws enacted; enforcement priorities shift | Implement regulatory monitoring with escalation criteria; quarterly compliance reviews |
311
312---
313
314## Tool Reference
315
316### privacy_regulation_checker.py
317
318Determines applicable privacy regulations and maps obligations based on organization parameters.
319
320| Flag | Required | Description |
321|------|----------|-------------|
322| `--org-location <code>` | Yes | Organization headquarters (ISO country code, e.g., DE, US-CA, SG) |
323| `--data-subjects <list>` | Yes | Comma-separated locations of data subjects (EU, US, BR, ZA, CA, SG, AU, CN, UK) |
324| `--data-types <list>` | Yes | Comma-separated data types (personal, sensitive, financial, health, biometric, children) |
325| `--processing-activities <list>` | Yes | Comma-separated activities (marketing, analytics, hr, ecommerce, profiling, healthcare, research) |
326| `--current-practices <list>` | No | Comma-separated current practices for gap analysis |
327| `--json` | No | Output in JSON format |
328
329### dsr_tracker.py
330
331Tracks Data Subject Request lifecycle with multi-regulation deadline calculation.
332
333| Subcommand | Description |
334|------------|-------------|
335| `add` | Add new DSR (`--type`, `--regulation`, `--subject`, `--email` required) |
336| `list` | List all requests (`--overdue` for overdue only) |
337| `update` | Update request status (`--id`, `--status` required) |
338| `dashboard` | Show dashboard with time remaining and alerts |
339
340| Flag | Description |
341|------|-------------|
342| `--type <type>` | Request type: access, deletion, correction, portability, restriction, objection, automated_decision, withdraw_consent |
343| `--regulation <reg>` | Regulation: gdpr, ccpa, lgpd, popia, pipeda, pdpa, privacy_act_au, pipl, uk_gdpr |
344| `--subject <name>` | Data subject name |
345| `--email <email>` | Data subject email |
346| `--id <id>` | Request ID (e.g., DSR-0001) |
347| `--status <status>` | Status: received, verified, processing, completed, denied, extended |
348| `--overdue` | Filter to overdue requests only |
349| `--json` | Output in JSON format |
350| `--data-file <path>` | Custom data file path (default: dsr_requests.json) |