Privacy and Data Handling Reviewer
Review a product or workflow for privacy and data-handling risks, then create practical controls, documentation needs, and remediation priorities.
Privacy and Data Handling Reviewer is a free AI skill for safety, privacy & compliance. Review a product or workflow for privacy and data-handling risks, then create practical controls, documentation needs, and remediation priorities. It works with Claude, ChatGPT, Cursor and is ready to use out of the box.
About this skill
Privacy and Data Handling Reviewer examines how a product, AI workflow, website, or internal process collects, uses, stores, shares, and deletes personal or sensitive information. It creates a structured data inventory, identifies unnecessary collection and weak controls, evaluates consent and transparency needs, and recommends practical privacy-by-design improvements.
What it does
The skill maps data subjects, data categories, purposes, sources, processors, storage locations, retention periods, access roles, transfers, and deletion flows; identifies privacy and security risks; checks data minimization and purpose alignment; reviews user notices and consent logic; defines technical and organizational controls; and produces a prioritized remediation register while avoiding unsupported legal conclusions.
What is included
- Data-flow inventory
- Purpose and minimization review
- Access and storage assessment
- Retention and deletion review
- Consent and transparency checks
- Third-party processor review
- Risk and control register
- Prioritized remediation roadmap
How to use it
1. Download the privacy-data-handling-reviewer-SKILL.md file 2. Upload it to your preferred AI assistant 3. Describe the product, users, data collected, and connected services 4. Provide privacy notices or process documentation when available 5. Have jurisdiction-specific legal conclusions reviewed by a qualified privacy professional
Examples
Review a mobile app that allows users to post location-based text, images, and audio. Posts can disappear after one hour, and the app stores account email, device information, approximate location, uploaded media, votes, and moderation logs.
A privacy review with data inventory, data-flow map, purpose and minimization findings, retention and deletion gaps, location and media risks, consent and transparency requirements, processor questions, access controls, incident considerations, and a prioritized remediation plan.
FAQ
What is this skill for?
Is this legal advice?
Can it review AI systems?
What if I do not know where all data is stored?
Does it cover third-party tools?
How is this different from a privacy-policy generator?
Related Skills
Application Security Threat Modeler
Create a practical application threat model covering assets, trust boundaries, attack paths, controls, tests, and remediation priorities.
Data Access and Least Privilege Reviewer
Review data access for least privilege, role design, sensitive fields, segregation, approvals, logging, reviews, and revocation.
Container Security and Supply Chain Reviewer
Review containers and software supply chains for image risks, dependencies, provenance, secrets, permissions, signing, and deployment controls.
Related Prompts
Sensitive Document Redaction Check
Create a precise redaction plan for a document or screenshot before external sharing while preserving the information needed for the task.
Form-to-Database Validation Workflow
Design a safe form-ingestion workflow that validates, normalizes, deduplicates, and stores submitted data with review queues and privacy controls.
Automation Failure Monitoring & Recovery
Create an observability and incident-recovery design for business automations, including logs, alerts, retry policy, ownership, replay, and post-incident review.
Related Articles
AI Privacy Checklist Before Launching an AI App
A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.