v1.0.0 cosmicstack-labs
Privacy & Compliance
GDPR, CCPA, HIPAA, data mapping, consent management, DSR handling, and privacy program management
View source0 downloads
privacycompliancegdprccpahipaadata-protection
Privacy & Compliance#
Build and maintain privacy compliance programs.
Major Regulations#
| Regulation | Scope | Key Requirements |
|---|---|---|
| GDPR | EU residents | Consent, data rights, breach notification, DPO |
| CCPA/CPRA | California residents | Right to know, delete, opt-out |
| HIPAA | US healthcare | PHI protection, BAAs, security rule |
| LGPD | Brazil | Similar to GDPR |
| PIPEDA | Canada | Consent, access, accuracy |
Core Program Components#
Data Mapping#
- Catalog all data collected (PII, sensitive, financial)
- Document flow: collection → storage → processing → deletion
- Identify third-party processors and sub-processors
- Map legal basis for each processing activity
- Review and update quarterly
Consent Management#
- Obtain explicit, informed consent before collection
- Record consent with timestamp and version
- Make withdrawal as easy as giving consent
- Refresh consent annually or when purpose changes
Data Subject Requests (DSR)#
| Request Type | Timeline | Process |
|---|---|---|
| Access | 30 days | Provide all data in machine-readable format |
| Deletion | 30 days | Delete + request deletion from third parties |
| Correction | 30 days | Fix inaccurate data |
| Portability | 30 days | Export in structured format |
| Objection | 30 days | Stop processing for specific purpose |
Privacy by Design#
- Proactive not reactive — embed privacy from the start
- Default settings should be most private
- Minimize data collection to what's necessary
- Encrypt everywhere (transit and at rest)
- Retain only as long as needed, then delete
More in Finance & Legal
View all →Finance & Legalv1.0.0
Contract Review
Contract types, key clauses (indemnification, liability, termination), redlining, and negotiation strategy
contractlegalreview
Finance & Legalv1.0.0
Risk Management
Risk identification, assessment matrices, mitigation strategies, BCP, and risk reporting
riskmanagementcompliance
Finance & Legalv1.0.0
Budgeting & Forecasting
Zero-based budgeting, rolling forecasts, variance analysis, scenario planning, and budget management
budgetingforecastingfinance