---
name: legal-counsel
description: >-
Structured legal reference for GDPR, EU AI Act, DSA/DMA, CCPA/CPRA, HIPAA (2026 updates),
ADA/WCAG digital accessibility, DMCA, US state privacy laws (15+ states), and contract review.
triggers:
- user asks about GDPR compliance, privacy law, cookie consent, data protection
- user asks about AI regulation, EU AI Act, AI compliance
- user asks about HIPAA, healthcare data, ePHI requirements
- user asks about ADA, WCAG, digital accessibility
- user asks about DMCA, copyright takedown, safe harbor
- user asks about CCPA, CPRA, US state privacy laws
- user asks about contract review, DPA, BAA, legal clauses
- user asks about DSA, DMA, Digital Services Act, Digital Markets Act
negatives:
- litigation strategy, courtroom procedure, criminal defense
- employment law disputes, labor rights, union matters
- immigration law, visa applications, citizenship
- tax law, estate planning, family law, real estate transactions
- trademark filing, patent prosecution (copyright DMCA is covered)
- specific monetary damages calculations for a particular case
license: MIT
compatibility: opencode
metadata:
workflow: legal
audience: developers
version: "3.0.0"
IMPORTANT DISCLAIMER: Reference information for educational and preliminary analysis. NOT legal advice. No attorney-client relationship. Laws vary by jurisdiction and change frequently. Always consult a qualified attorney.
Workflow
When asked a legal compliance question, follow these steps:
| Step |
Action |
Notes |
| 1 |
Identify jurisdiction(s) |
EU, US federal, US state(s), UK — may overlap |
| 2 |
Map the Obligation Matrix |
Core Analysis Framework (below) |
| 3 |
Cross-reference enforcement |
Fines, private right of action, regulator trends |
| 4 |
Check effective dates |
Phased enforcement is common (AI Act, HIPAA 2026) |
| 5 |
Return applicable code |
Use sub-sections below — do not invent thresholds |
| 6 |
Append disclaimer |
Always close with "verify with qualified attorney" |
Core Analysis Framework
| Lens |
What it asks |
| Jurisdiction |
Which law applies? (EU, UK, US federal, US state) |
| Obligation |
What must you do? (mandatory vs recommended) |
| Risk |
What happens if you don't? (fines, lawsuits, reputation) |
| Timeline |
When must you comply? (deadlines, phased enforcement) |
Error Handling
| Scenario |
What to do |
Don't do |
| User asks "is this legal?" |
Frame as checklist — never a yes/no opinion |
Give definitive legal judgment |
| Jurisdiction unclear |
Ask which country/state the business operates in |
Assume US or EU by default |
| Threshold question (revenue, user count) |
Clarify exact figures before answering |
Give partial guidance |
| Law recently updated |
Check effective date; note "proposed/not yet in force" if applicable |
Cite outdated text as current |
| User asks about pending legislation |
Flag "not yet law — monitor progress" |
Present as binding requirement |
| Cross-border data transfer (EU→US) |
Reference DPF / SCCs / BCRs |
Oversimplify transfer mechanism |
3. EU Law
3.1 GDPR (Regulation EU 2016/679)
Applies to: Any organization processing personal data of EU residents.
Lawful basis (6): Consent, contract, legal obligation, vital interest, public task, legitimate interest.
Consent: Specific, informed, unambiguous, freely given, revocable. No pre-ticked boxes.
DSAR: 30 days. Mostly free. Can extend 60 days for complex.
Breach notification: 72 hours to authority. Notify subjects if high risk.
DPIA: Required for high-risk processing (profiling, large-scale sensitive data).
Fines: Up to 4% of annual global turnover or EUR 20M.
3.2 DSA (Digital Services Act)
Applies to: Platforms, marketplaces, social media reaching EU users.
Key requirements:
- Notice-and-action for illegal content
- Transparency reporting (quarterly for VLOPs)
- User redress (internal complaint system + out-of-court dispute)
- Risk assessments for VLOPs (Very Large Online Platforms)
- Recommendation system transparency
3.3 DMA (Digital Markets Act)
Applies to: Gatekeepers (platforms >45M EU users, >75B EUR market cap).
Requirements: Interoperability, data portability, no self-preferencing, no anti-steering.
3.4 EU AI Act (Regulation 2024/1689)
| Tier |
Examples |
Requirements |
| Minimal |
Chatbots, spam filters |
Transparency: label AI |
| Limited |
AI customer support |
User must know it's AI |
| High-risk |
CV screening, credit scoring, medical AI |
Conformity assessment, risk mgmt, human oversight |
| Unacceptable |
Social scoring, predictive policing |
Prohibited entirely |
Fines: Up to 7% of annual global turnover for prohibited practices.
Enforcement timeline: Phased 2025-2027. Codes of Practice expected mid-2026.
3.5 ePrivacy Directive (Cookie Law)
- Strict opt-in for non-essential cookies
- No cookie walls (blocking unless user accepts all)
- Granular: necessary, preferences, statistics, marketing
- Consent stored with proof
4. US Law
4.1 DMCA (17 U.S.C. § 512)
- Safe harbor for OSPs with notice-and-takedown
- Repeat infringer policy required
- DMCA registered agent (Copyright Office)
- Counter-notice: content restored in 10-14 business days
4.2 HIPAA (2026 Security Rule Updates)
- Encryption of all ePHI at rest and in transit (mandatory, no longer "addressable")
- MFA required for all ePHI access
- 72-hour breach notification (reduced from 60 days)
- Annual penetration testing
- Fines: $100-$50,000 per violation, up to $1.5M per year per category
4.3 ADA / WCAG Digital Accessibility
- 2026: DOJ adopted WCAG 2.1 Level AA for public entities (Title II)
- Deadlines: April 24, 2026 (populations 50K+), April 26, 2027 (under 50K)
- POUR: Perceivable, Operable, Understandable, Robust
- Private sector: No specific rule but 5,000+ ADA website lawsuits in 2025
4.4 State Privacy Laws (15+)
| State |
Law |
Effective |
Revenue Threshold |
| California |
CCPA/CPRA |
2020/2023 |
$25M |
| Virginia |
VCDPA |
2023 |
100K consumers |
| Colorado |
CPA |
2023 |
100K consumers |
| Connecticut |
CTDPA |
2023 |
100K / $25M revenue |
| Utah |
UCPA |
2023 |
$25M + 100K |
| Iowa |
ICDPA |
2025 |
100K consumers |
| Tennessee |
TIPA |
2025 |
100K consumers |
| Texas |
TDPSA |
2025 |
$25M + data processing |
| Delaware |
DDPA |
2025 |
100K consumers |
Practical approach: Implement one program meeting California's (most stringent) requirements. Most states share: access, delete, correct, portability, opt-out.
5. Contract Review Framework
| Clause |
Red Flag |
| Indemnification |
Unlimited IP indemnity; no reciprocal |
| Limitation of liability |
No cap; cap < contract value |
| Data processing |
No DPA/BAA; no sub-processor approval |
| Termination |
Auto-renewal without notice; no data export |
| IP ownership |
Assignment of improvements |
| SLA |
99% or below; credits as sole remedy |
| Governing law |
Non-mutual venue; inconvenient forum |
6. Production Checklist
Anti-Patterns
| Anti-pattern |
Why it's wrong |
Instead |
| "Just add a privacy policy" |
Privacy policy alone doesn't operationalize rights (DSAR, deletion, opt-out) |
Build full data-rights workflow (access → fulfill → log) |
| "GDPR doesn't apply to us — we're in the US" |
GDPR applies to any org processing EU resident data, regardless of location |
Always check: do you have EU users? |
| "Cookie banner = compliance" |
Consent must be granular, revocable, and provable |
Log consent with timestamp + scope + user ID |
| "AI Act is just about big AI" |
High-risk tier covers HR, credit, medical, insurance — affects many companies |
Classify your use case against Annex III before building |
| "HIPAA encryption was 'addressable' — we're fine" |
2026 update makes encryption + MFA mandatory, not addressable |
Treat all addressable items as mandatory going forward |
| "We just need DMCA safe harbor" |
Safe harbor requires registered agent + repeat infringer policy + prompt takedown |
Complete all three requirements or safe harbor is void |
| "One privacy program fits all states" |
California, Colorado, and Connecticut have material differences (opt-out, profiling, sensitive data) |
Build CA-level as baseline, then diff for CO/CT unique obligations |
| "We don't process health data, HIPAA doesn't apply" |
HIPAA also covers payment, treatment, operations data from covered entities — including apps that receive ePHI from providers |
Sign BAA before receiving any data from covered entity |
Sources
- GDPR: Regulation EU 2016/679
- EU AI Act: Regulation EU 2024/1689
- DSA: Regulation EU 2022/2065
- DMCA: 17 U.S.C. § 512
- HIPAA: 45 CFR Parts 160, 164
- ICO guidance (ico.org.uk)
- EDPB guidelines
- Sourcepoint "US State Privacy Law Comparison"
- DOJ Title II WCAG rule (2024)
Checklist
1---2name: legal-counsel3description: ---4---5---6name: legal-counsel7description: >-8 Structured legal reference for GDPR, EU AI Act, DSA/DMA, CCPA/CPRA, HIPAA (2026 updates),9 ADA/WCAG digital accessibility, DMCA, US state privacy laws (15+ states), and contract review.10triggers:11 - user asks about GDPR compliance, privacy law, cookie consent, data protection12 - user asks about AI regulation, EU AI Act, AI compliance13 - user asks about HIPAA, healthcare data, ePHI requirements14 - user asks about ADA, WCAG, digital accessibility15 - user asks about DMCA, copyright takedown, safe harbor16 - user asks about CCPA, CPRA, US state privacy laws17 - user asks about contract review, DPA, BAA, legal clauses18 - user asks about DSA, DMA, Digital Services Act, Digital Markets Act19negatives:20 - litigation strategy, courtroom procedure, criminal defense21 - employment law disputes, labor rights, union matters22 - immigration law, visa applications, citizenship23 - tax law, estate planning, family law, real estate transactions24 - trademark filing, patent prosecution (copyright DMCA is covered)25 - specific monetary damages calculations for a particular case26license: MIT27compatibility: opencode28metadata:29 workflow: legal30 audience: developers31 version: "3.0.0"32---333435**IMPORTANT DISCLAIMER**: Reference information for educational and preliminary analysis. NOT legal advice. No attorney-client relationship. Laws vary by jurisdiction and change frequently. Always consult a qualified attorney.3637## Workflow3839When asked a legal compliance question, follow these steps:4041| Step | Action | Notes |42|------|--------|-------|43| 1 | Identify jurisdiction(s) | EU, US federal, US state(s), UK — may overlap |44| 2 | Map the Obligation Matrix | Core Analysis Framework (below) |45| 3 | Cross-reference enforcement | Fines, private right of action, regulator trends |46| 4 | Check effective dates | Phased enforcement is common (AI Act, HIPAA 2026) |47| 5 | Return applicable code | Use sub-sections below — do not invent thresholds |48| 6 | Append disclaimer | Always close with "verify with qualified attorney" |4950### Core Analysis Framework5152| Lens | What it asks |53|------|-------------|54| Jurisdiction | Which law applies? (EU, UK, US federal, US state) |55| Obligation | What must you do? (mandatory vs recommended) |56| Risk | What happens if you don't? (fines, lawsuits, reputation) |57| Timeline | When must you comply? (deadlines, phased enforcement) |5859## Error Handling6061| Scenario | What to do | Don't do |62|----------|-----------|----------|63| User asks "is this legal?" | Frame as checklist — never a yes/no opinion | Give definitive legal judgment |64| Jurisdiction unclear | Ask which country/state the business operates in | Assume US or EU by default |65| Threshold question (revenue, user count) | Clarify exact figures before answering | Give partial guidance |66| Law recently updated | Check effective date; note "proposed/not yet in force" if applicable | Cite outdated text as current |67| User asks about pending legislation | Flag "not yet law — monitor progress" | Present as binding requirement |68| Cross-border data transfer (EU→US) | Reference DPF / SCCs / BCRs | Oversimplify transfer mechanism |6970## 3. EU Law7172### 3.1 GDPR (Regulation EU 2016/679)7374**Applies to**: Any organization processing personal data of EU residents.75**Lawful basis** (6): Consent, contract, legal obligation, vital interest, public task, legitimate interest.76**Consent**: Specific, informed, unambiguous, freely given, revocable. No pre-ticked boxes.77**DSAR**: 30 days. Mostly free. Can extend 60 days for complex.78**Breach notification**: 72 hours to authority. Notify subjects if high risk.79**DPIA**: Required for high-risk processing (profiling, large-scale sensitive data).80**Fines**: Up to 4% of annual global turnover or EUR 20M.8182### 3.2 DSA (Digital Services Act)8384**Applies to**: Platforms, marketplaces, social media reaching EU users.85**Key requirements**:86- Notice-and-action for illegal content87- Transparency reporting (quarterly for VLOPs)88- User redress (internal complaint system + out-of-court dispute)89- Risk assessments for VLOPs (Very Large Online Platforms)90- Recommendation system transparency9192### 3.3 DMA (Digital Markets Act)9394**Applies to**: Gatekeepers (platforms >45M EU users, >75B EUR market cap).95**Requirements**: Interoperability, data portability, no self-preferencing, no anti-steering.9697### 3.4 EU AI Act (Regulation 2024/1689)9899| Tier | Examples | Requirements |100|------|----------|-------------|101| Minimal | Chatbots, spam filters | Transparency: label AI |102| Limited | AI customer support | User must know it's AI |103| High-risk | CV screening, credit scoring, medical AI | Conformity assessment, risk mgmt, human oversight |104| Unacceptable | Social scoring, predictive policing | Prohibited entirely |105106**Fines**: Up to 7% of annual global turnover for prohibited practices.107**Enforcement timeline**: Phased 2025-2027. Codes of Practice expected mid-2026.108109### 3.5 ePrivacy Directive (Cookie Law)110111- Strict opt-in for non-essential cookies112- No cookie walls (blocking unless user accepts all)113- Granular: necessary, preferences, statistics, marketing114- Consent stored with proof115116## 4. US Law117118### 4.1 DMCA (17 U.S.C. § 512)119120- Safe harbor for OSPs with notice-and-takedown121- Repeat infringer policy required122- DMCA registered agent (Copyright Office)123- Counter-notice: content restored in 10-14 business days124125### 4.2 HIPAA (2026 Security Rule Updates)126127- Encryption of all ePHI at rest and in transit (mandatory, no longer "addressable")128- MFA required for all ePHI access129- 72-hour breach notification (reduced from 60 days)130- Annual penetration testing131- Fines: $100-$50,000 per violation, up to $1.5M per year per category132133### 4.3 ADA / WCAG Digital Accessibility134135- 2026: DOJ adopted WCAG 2.1 Level AA for public entities (Title II)136- Deadlines: April 24, 2026 (populations 50K+), April 26, 2027 (under 50K)137- POUR: Perceivable, Operable, Understandable, Robust138- Private sector: No specific rule but 5,000+ ADA website lawsuits in 2025139140### 4.4 State Privacy Laws (15+)141142| State | Law | Effective | Revenue Threshold |143|-------|-----|-----------|-------------------|144| California | CCPA/CPRA | 2020/2023 | $25M |145| Virginia | VCDPA | 2023 | 100K consumers |146| Colorado | CPA | 2023 | 100K consumers |147| Connecticut | CTDPA | 2023 | 100K / $25M revenue |148| Utah | UCPA | 2023 | $25M + 100K |149| Iowa | ICDPA | 2025 | 100K consumers |150| Tennessee | TIPA | 2025 | 100K consumers |151| Texas | TDPSA | 2025 | $25M + data processing |152| Delaware | DDPA | 2025 | 100K consumers |153154**Practical approach**: Implement one program meeting California's (most stringent) requirements. Most states share: access, delete, correct, portability, opt-out.155156## 5. Contract Review Framework157158| Clause | Red Flag |159|--------|----------|160| Indemnification | Unlimited IP indemnity; no reciprocal |161| Limitation of liability | No cap; cap < contract value |162| Data processing | No DPA/BAA; no sub-processor approval |163| Termination | Auto-renewal without notice; no data export |164| IP ownership | Assignment of improvements |165| SLA | 99% or below; credits as sole remedy |166| Governing law | Non-mutual venue; inconvenient forum |167168## 6. Production Checklist169170- [ ] Privacy policy posted, complete, jurisdiction-specific171- [ ] Cookie consent banner with granular categories172- [ ] DSAR handling procedure documented173- [ ] DPAs/BAAs with all vendors174- [ ] Data mapping completed175- [ ] DMCA takedown agent registered (US)176- [ ] Alt text on all meaningful images177- [ ] Keyboard navigation on all interactive elements178- [ ] Color contrast WCAG 2.1 AA (4.5:1)179- [ ] HTTPS enforced (TLS 1.2+)180- [ ] MFA on all administrative access181- [ ] Incident response plan tested annually182- [ ] Lawful basis documented for each processing activity183- [ ] Cross-border transfer mechanism in place (DPF/SCCs/BCRs)184- [ ] AI Act tier classification documented (if applicable)185- [ ] HIPAA BAAs with all subcontractors handling ePHI186- [ ] Breach notification procedure tested with drill187- [ ] Cookie consent records auditable (proof of consent)188189## Anti-Patterns190191| Anti-pattern | Why it's wrong | Instead |192|-------------|----------------|---------|193| "Just add a privacy policy" | Privacy policy alone doesn't operationalize rights (DSAR, deletion, opt-out) | Build full data-rights workflow (access → fulfill → log) |194| "GDPR doesn't apply to us — we're in the US" | GDPR applies to any org processing EU resident data, regardless of location | Always check: do you have EU users? |195| "Cookie banner = compliance" | Consent must be granular, revocable, and provable | Log consent with timestamp + scope + user ID |196| "AI Act is just about big AI" | High-risk tier covers HR, credit, medical, insurance — affects many companies | Classify your use case against Annex III before building |197| "HIPAA encryption was 'addressable' — we're fine" | 2026 update makes encryption + MFA mandatory, not addressable | Treat all addressable items as mandatory going forward |198| "We just need DMCA safe harbor" | Safe harbor requires registered agent + repeat infringer policy + prompt takedown | Complete all three requirements or safe harbor is void |199| "One privacy program fits all states" | California, Colorado, and Connecticut have material differences (opt-out, profiling, sensitive data) | Build CA-level as baseline, then diff for CO/CT unique obligations |200| "We don't process health data, HIPAA doesn't apply" | HIPAA also covers payment, treatment, operations data from covered entities — including apps that receive ePHI from providers | Sign BAA before receiving any data from covered entity |201202## Sources203204- GDPR: Regulation EU 2016/679205- EU AI Act: Regulation EU 2024/1689206- DSA: Regulation EU 2022/2065207- DMCA: 17 U.S.C. § 512208- HIPAA: 45 CFR Parts 160, 164209- ICO guidance (ico.org.uk)210- EDPB guidelines211- Sourcepoint "US State Privacy Law Comparison"212- DOJ Title II WCAG rule (2024)213214## Checklist215216- [ ] Skill loads without errors in the AI agent217- [ ] YAML frontmatter is valid (description, compatibility, audience)218- [ ] Workflow section provides clear step-by-step instructions219- [ ] Error handling section covers common failure modes220- [ ] All referenced files (references/, scripts/, assets/) exist221- [ ] Skill triggers correctly for intended use cases222- [ ] No broken links or missing resources