hermes
16 entries · 14 prompts, 2 personas

Compliance

Privacy, data protection and regulatory checklists for small organisations.

  • Answer a security questionnaire

    Drafts answers to a customer's security or vendor due-diligence questionnaire strictly from documented practices, citing evidence for each answer and marking gaps instead of overclaiming.

  • Assess EU AI Act obligations

    Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

  • Audit a product for data protection

    Audits a software product, its code and processes against data protection expectations such as GDPR and CCPA, with a pass, partial or gap status per requirement and the product change each gap needs.

  • Audit a website's privacy compliance

    Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.

  • Build a compliance readiness checklist

    Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

  • Check email and SMS marketing compliance

    Checks an email or SMS marketing programme against consent and content rules such as GDPR, ePrivacy, CAN-SPAM and CASL for each market, and lists concrete fixes ranked by risk.

  • Check endorsement disclosures

    Checks influencer, affiliate and endorsement content against advertising disclosure expectations for the market and platform, flags hidden or unclear disclosures, and suggests compliant wording.

  • Compliance officer
    PersonaCompliance

    Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.

  • Draft a data protection impact assessment

    Drafts a data protection impact assessment for a project, covering screening, the processing, necessity, risks to people by likelihood and severity, mitigations and residual risk.

  • Handle a personal data request

    Guides a small organisation through answering a personal-data access or deletion request, covering identity checks, where to search, exemptions to check, deadlines and the reply.

  • Map personal data processing

    Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

  • Plan a personal data breach response

    Plans a small organisation's personal data breach response covering containment, risk assessment, notification thresholds and deadlines to verify, notice templates and a breach log.

  • Review a vendor data processing agreement

    Reviews a SaaS vendor's data processing agreement against core requirements such as instructions, security, subprocessors, transfers, breach notice, audits and deletion, and lists the gaps to raise.

  • Technology law guide
    PersonaCompliance

    Acts as a technology-law information guide for software teams on privacy, licences, product terms and contracts, drafting for counsel review and separating general information from legal advice.

  • Write a data retention schedule

    Drafts a records and data retention schedule listing each record type, owner, system, retention trigger, period to verify, basis, and deletion or archiving method, with legal holds and review steps.

  • Write a workplace risk assessment

    Writes a workplace health and safety risk assessment covering hazards, who is at risk, existing controls, risk ratings, further actions with owners and a review date.

Not: secure coding (security).