1---2name: hls-draft-data-privacy-compliance-manual3description: Drafts a comprehensive data privacy compliance policy manual and gap analysis for a digital health company operating under overlapping healthcare-privacy obligations, addressing biometric privacy laws, consumer health data statutes, advertising SDK data sharing, and implementation deadlines.4---56# Skill: Draft Comprehensive Data Privacy Compliance Policy Manual for Digital Health Company78## 1. Subject-matter triage9- Separate the company’s regulated healthcare functions from any other privacy-regulated processing before drafting controls.10- Identify whether the source set reflects a single operating model or multiple business lines with distinct data flows, user populations, or regulatory regimes.11- If the documents implicate more than one jurisdiction, product, or data category, enumerate them first and analyze each on its own footing.1213## 2. Failure modes the skill is correcting14- The policy manual is drafted as a generic privacy template and does not map controls to the actual data flows, products, or legal regimes in the source record.15- The gap analysis is omitted, embedded only as narrative, or lacks a standalone remediation view.16- Advertising SDK handling, employee offboarding access revocation, biometric retention/destruction, and consumer health data handling are treated as operational trivia rather than compliance obligations.17- Distinct healthcare-privacy obligations are collapsed into one section even when different activities trigger different rules.18- Deadlines embedded in transaction, financing, or implementation materials are ignored.19- Conclusions are stated without identifying the governing authority that supports them.2021## 3. Legal frameworks / domain conventions that apply22- Overlapping healthcare privacy status: map each activity to the applicable privacy and security regime, and keep regulated healthcare processing separate from non-healthcare processing where the source facts require it.23- Biometric data: address notice, consent, retention, destruction, and publication requirements under each implicated state biometric regime.24- Consumer health data: draft a distinct section for consumer health data statutes, including scope, notice, consent, sharing restrictions, and consumer-rights handling.25- De-identification: do not treat shared data as outside privacy regulation unless the manual explains the recognized de-identification method being used and its limitations.26- Advertising SDKs: treat mobile advertising integrations as a distinct risk area because third-party transmission can occur without user awareness or authorization.27- Access revocation: build a documented offboarding workflow for timely removal of access, with verification and accountability.28- Leadership designation: formally assign privacy and security responsibility, even if one person holds multiple roles.29- Deadlines: align the implementation plan with any external milestone in governing commercial, financing, or regulatory documents.30- Controlling authority: when stating a legal proposition, name the statute, regulation, or other authority that supports it instead of relying on bare conclusions.3132## 4. Analytical scaffolds33- Start with a data-map: source, collection point, purpose, storage location, sharing path, retention rule, deletion trigger, and responsible owner.34- Separate the analysis by function: regulated healthcare operations, consumer-facing privacy obligations, employee/access controls, technical integrations, and governance.35- For each applicable law or regime, identify: scope, covered data, required notice, consent or authorization trigger, rights-handling process, retention/destruction requirement, and enforcement exposure.36- For each identified gap, state: what the source documents show, what should exist, who owns remediation, what must change, and why the gap matters.37- If more than one product, entity, jurisdiction, or data category is implicated, list them explicitly first and then run the same analytical sequence for each.38- For statutory or regulatory claims, cite the controlling authority by name and section, and tie the conclusion to the text of that authority.39- When deadlines appear in the record, anchor recommendations to those deadlines rather than generic “ASAP” language.4041## 5. Vertical / structural / temporal relationships42- Show how company-level privacy governance sits above product-level notices, technical controls, and workforce procedures.43- Distinguish upstream collection, in-process use, downstream disclosure, and end-of-life retention/destruction.44- Track temporal controls separately: onboarding authorization, ongoing access review, offboarding revocation, retention expiration, and destruction.45- Where a control depends on another document or process, state the dependency so the manual reads as an operational system rather than a standalone memo.46- If the source record contains multiple time-sensitive obligations, order them by due date or implementation sequence.4748## 6. Output structure conventions49- Produce two distinct documents: a comprehensive compliance policy manual and a separate gap analysis summary.50- The manual should be organized by functional area and should read like a usable policy document, not a project plan or legal memo.51- Include clear policy statements, responsible roles, procedures, escalation paths, recordkeeping expectations, and review cadence.52- Include any required public-facing retention or destruction statements in the relevant policy section where the source law requires publication.53- The gap analysis summary should use a consistent ordinal severity scale stated once at the top, then apply it uniformly to each gap.54- Each gap entry should identify the affected control, the risk or exposure, the responsible party, the remediation deadline or milestone, and the operational or regulatory consequence.55- Close the gap analysis with explicit recommended actions that assign an owner and a timing anchor.56- Keep the deliverables separate in substance as well as format; the summary should not replace the manual, and the manual should not absorb the gap matrix.