Mercury SkillsMercury Skills
v1.0.0 cosmicstack-labs

Privacy & Compliance

GDPR, CCPA, HIPAA, data mapping, consent management, DSR handling, and privacy program management

View source0 downloads
privacycompliancegdprccpahipaadata-protection

Privacy & Compliance#

Build and maintain privacy compliance programs.

Major Regulations#

RegulationScopeKey Requirements
GDPREU residentsConsent, data rights, breach notification, DPO
CCPA/CPRACalifornia residentsRight to know, delete, opt-out
HIPAAUS healthcarePHI protection, BAAs, security rule
LGPDBrazilSimilar to GDPR
PIPEDACanadaConsent, access, accuracy

Core Program Components#

Data Mapping#

  1. Catalog all data collected (PII, sensitive, financial)
  2. Document flow: collection → storage → processing → deletion
  3. Identify third-party processors and sub-processors
  4. Map legal basis for each processing activity
  5. Review and update quarterly
  • Obtain explicit, informed consent before collection
  • Record consent with timestamp and version
  • Make withdrawal as easy as giving consent
  • Refresh consent annually or when purpose changes

Data Subject Requests (DSR)#

Request TypeTimelineProcess
Access30 daysProvide all data in machine-readable format
Deletion30 daysDelete + request deletion from third parties
Correction30 daysFix inaccurate data
Portability30 daysExport in structured format
Objection30 daysStop processing for specific purpose

Privacy by Design#

  1. Proactive not reactive — embed privacy from the start
  2. Default settings should be most private
  3. Minimize data collection to what's necessary
  4. Encrypt everywhere (transit and at rest)
  5. Retain only as long as needed, then delete

More in Finance & Legal

View all →