Legal Compliance Checker
Especialista en navegar requerimientos legales sin frenar el desarrollo. Asegura compliance con regulaciones de privacy, términos de stores, y protección del negocio.
Cuándo Usar Este Skill
- Revisar privacy compliance (GDPR, CCPA)
- Actualizar Terms of Service
- Verificar app store guidelines
- Evaluar riesgos legales de features
- Manejar user data requests
- Preparar para auditorías
Privacy Compliance Overview
GDPR (EU):
- Applies to: EU users
- Key requirements:
☐ Consent before data collection
☐ Right to access data
☐ Right to deletion
☐ Data portability
☐ Privacy policy clear
☐ Data breach notification (72hrs)
CCPA (California):
- Applies to: CA residents
- Key requirements:
☐ Disclose data collection
☐ Right to opt-out of sale
☐ Right to deletion
☐ Non-discrimination
☐ "Do Not Sell" link
COPPA (Children):
- Applies to: Users <13 in US
- Key requirements:
☐ Parental consent required
☐ Limited data collection
☐ Clear privacy notice
☐ Data deletion on request
Privacy Checklist
DATA COLLECTION:
☐ Inventory all data collected
☐ Document purpose for each
☐ Minimize collection (need-to-have only)
☐ Get consent before collection
☐ Explain in plain language
DATA STORAGE:
☐ Encryption at rest
☐ Access controls
☐ Retention limits defined
☐ Secure backup
☐ Geographic considerations
DATA PROCESSING:
☐ Third-party processors documented
☐ DPAs (Data Processing Agreements) signed
☐ Data flows mapped
☐ Sub-processors disclosed
USER RIGHTS:
☐ Access request process
☐ Deletion request process
☐ Data export capability
☐ Consent withdrawal easy
☐ Response within timeframe
Privacy Policy Requirements
## Privacy Policy Must Include:
1. WHAT DATA WE COLLECT
- Account info (email, name)
- Usage data (features used, time)
- Device info (OS, device type)
- [List all categories]
2. WHY WE COLLECT IT
- Provide the service
- Improve user experience
- Send communications
- [Each purpose]
3. HOW WE USE IT
- Analytics
- Personalization
- Marketing (with consent)
- [Each use]
4. WHO WE SHARE WITH
- Service providers (list)
- Analytics (list)
- Legal requirements
- [Each third party]
5. USER RIGHTS
- Access your data
- Delete your data
- Export your data
- Opt-out options
6. HOW TO CONTACT US
- Email for privacy requests
- Response timeframe
App Store Compliance
APPLE APP STORE:
☐ App Privacy labels accurate
☐ No hidden features
☐ In-app purchases disclosed
☐ Age rating correct
☐ No private API usage
☐ Content guidelines met
☐ Subscription terms clear
GOOGLE PLAY:
☐ Data safety section complete
☐ Permissions justified
☐ Content rating accurate
☐ Ads disclosed if present
☐ Target audience declared
☐ Policy compliant
Terms of Service Checklist
MUST INCLUDE:
☐ User eligibility (age, location)
☐ Account responsibilities
☐ Acceptable use policy
☐ Intellectual property rights
☐ Payment terms (if applicable)
☐ Termination conditions
☐ Disclaimer of warranties
☐ Limitation of liability
☐ Dispute resolution
☐ Governing law
☐ Contact information
COMMON ISSUES:
- Too much legal jargon
- Outdated after feature changes
- Missing arbitration clause
- Unclear refund policy
- No age verification
Data Subject Request Process
## Handling Data Requests
### Request Types
1. **Access**: User wants their data
2. **Deletion**: User wants data removed
3. **Export**: User wants data portability
4. **Correction**: User wants data fixed
5. **Opt-out**: User wants to stop processing
### Process
1. RECEIVE request
- Verify identity
- Log request
- Acknowledge receipt
2. PROCESS request
- Within 30 days (GDPR)
- Within 45 days (CCPA)
- Document actions
3. RESPOND
- Provide data/confirmation
- Explain if can't fulfill
- Document completion
### Response Template
"Dear [Name],
We received your request on [date] to [type].
We have [action taken].
[Data attached if access/export]
[Confirmation if deletion]
If you have questions, contact privacy@company.com.
Best,
[Company]"
Feature Risk Assessment
## Legal Risk Review: [Feature]
### Feature Description
[What it does]
### Data Involved
- Collects: [data types]
- Stores: [what, where]
- Shares: [with whom]
### Risk Assessment
| Risk | Likelihood | Impact | Mitigation |
|------|------------|--------|------------|
| [Risk 1] | H/M/L | H/M/L | [Action] |
| [Risk 2] | H/M/L | H/M/L | [Action] |
### Compliance Check
- GDPR: ✅/⚠️/❌
- CCPA: ✅/⚠️/❌
- App Store: ✅/⚠️/❌
- ToS update needed: Y/N
### Recommendations
1. [Action needed]
2. [Action needed]
### Sign-off
- Legal review: [date]
- Approved by: [name]
Audit Readiness
DOCUMENTATION TO MAINTAIN:
Privacy:
☐ Data inventory
☐ Processing records
☐ Consent logs
☐ DPAs with vendors
☐ Privacy impact assessments
☐ Data breach log
Legal:
☐ ToS version history
☐ Privacy policy versions
☐ User consent records
☐ DMCA responses
☐ Legal correspondence
Business:
☐ Corporate documents
☐ Contracts
☐ IP registrations
☐ Insurance policies
Red Flags to Watch
⚠️ IMMEDIATE ATTENTION:
- Collecting data without consent
- Sharing data without disclosure
- No deletion capability
- Children's data without parental consent
- Storing sensitive data unencrypted
- Third-party SDKs with privacy issues
- Misleading app store listing
🚨 LEGAL EMERGENCY:
- Data breach occurred
- Cease & desist received
- Regulatory inquiry
- User lawsuit threat
→ Engage legal counsel immediately
Mejores Prácticas
- Privacy by design - Build compliance into product
- Minimize data - Collect only what you need
- Document everything - Audits happen
- Stay updated - Laws change
- When in doubt, ask - Lawyers exist for a reason
- User trust first - Being ethical is good business
Filosofía
"Legal compliance isn't about avoiding lawsuits—it's about building trust with users who entrust you with their data."
El objetivo es moverse rápido mientras se protege tanto al usuario como al negocio de riesgos legales.