Token导航 LogoToken导航TokenDH.com
研究检索只读github未标认证来源可访问许可证需确认审计提醒

privacy-policy-malik-taiar隐私政策 马利克·泰尔

Agent Skill

privacy-policy-malik-taiar 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,448

周安装

58

GitHub Stars

302

下载量

469
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:privacy-policy-malik-taiar(隐私政策 马利克·泰尔)
来源仓库:https://github.com/lawvable/awesome-legal-skills
仓库路径:skills/privacy-policy-malik-taiar
安装命令:
npx skills add https://github.com/lawvable/awesome-legal-skills --skill privacy-policy-malik-taiar
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/lawvable/awesome-legal-skills --skill privacy-policy-malik-taiar

简介

privacy-policy-malik-taiar 用于查找、检索和筛选相关信息。

  • 适合在需要根据关键词或任务场景快速定位候选结果时使用。
  • 可结合来源仓库和原始 README 核验具体用法。
  • 安装前建议确认权限范围、维护状态及是否会触发联网或命令执行。
  • 适用于 Codex、Claude、Cursor、Gemini CLI 等宿主环境。

SKILL.md

Privacy Policy Guide - GDPR

Overview

The privacy policy is the main document for informing data subjects under Articles 13 and 14 of the GDPR. It must be clear, accessible, and comprehensive.

Policy Objectives

ObjectiveGDPR Requirement
TransparencyClearly inform about data processing (Art. 12)
InformationProvide all mandatory disclosures (Art. 13-14)
RightsEnable exercise of data subject rights (Art. 15-22)
TrustReassure users about data protection

Reference Resources

Templates

TemplateDescription
assets/sample_template_politique_confidentialite.docxDefault template to use if no private template is provided
Internal template provided by lawyerUse if the lawyer has a more suitable private template
IMPORTANT: The default template sample_template_politique_confidentialite is designed for a brochure website without user accounts. If the request concerns an application or platform with users, additional data categories will need to be added, such as: - User account management (creation, authentication, profile) - Login data and activity history - Data generated by application usage - User-to-user communications (messages, comments, etc.) - User preferences and settings Adapt the template according to the platform type (brochure site, e-commerce, SaaS, mobile app, marketplace, etc.).

CNIL Documentation

DocumentContent
CNIL_droits_personnes.pdfGuide on data subject rights (access, rectification, erasure, etc.)
CNIL_durees_conservation.pdfRetention period recommendations by data type
CNIL_finalites.pdfHow to properly define processing purposes
CNIL_transparence.pdfGuide on information and transparency towards data subjects
CNIL_principes_rgpd.pdfFundamental GDPR principles
RGPD_texte_officiel.pdfFull text of EU Regulation 2016/679

Knowledge Base

DocumentContent
BASES_LEGALES.mdThe 6 legal bases for processing (Art. 6 GDPR) with examples and wording
DROITS_PERSONNES.mdThe 8 data subject rights (Art. 15-22 GDPR) with exercise procedures
COOKIES.mdCNIL 2020 recommendations on cookies, categories, banners, sanctions
DUREES_CONSERVATION.mdRetention period tables by data type with legal justifications

Information to Collect from Client

IMPORTANT: Before drafting the policy, collect ALL the information below from the client.

1. Data Controller Information

  • Full company name
  • Legal form (SAS, SARL, Ltd, etc.)
  • Company registration number (SIREN/SIRET)
  • Registered office address
  • Legal representative (name and title)
  • General contact email
  • DPO appointed? If yes, contact details

2. Nature of the Site/Application

  • Existing website URL (for analysis)
  • Platform type:

- Brochure website - E-commerce - SaaS / Web application - Mobile application - Marketplace - Other: ___________

  • Business sector
  • Target audience (B2B, B2C, both)
  • Target countries (France only, EU, international)

3. Data Collected

For each category, specify if applicable:

  • IDENTIFICATION DATA

- First name, last name - Email - Phone - Postal address - Date of birth - Photo / Avatar

  • CONNECTION DATA

- IP address - Connection logs - Device ID - Account identifiers

  • BROWSING DATA

- Pages visited - Time spent - Clicks - Traffic source

  • TRANSACTION DATA

- Order history - Payment data (via provider) - Invoices

  • SENSITIVE DATA (special attention)

- Health data - Political/religious opinions - Ethnic origin - Biometric data

4. Legal Bases for Processing

KEY QUESTION: For each processing activity, what is the legal basis?
Legal BasisWhen to UseExample
Contract Performance (Art. 6.1.b)Processing necessary to provide the serviceOrder delivery, account creation
Consent (Art. 6.1.a)Free choice by the person, withdrawable at any timeNewsletter, marketing cookies, sharing with partners
Legitimate Interest (Art. 6.1.f)Company interest, balanced against data subject rightsAnonymized statistics, security, B2B prospecting
Legal Obligation (Art. 6.1.c)Required by lawInvoice retention 10 years, tax obligations

TABLE TO COMPLETE WITH CLIENT:

Processing PurposeLegal BasisData Concerned
Order management
Account creation
Newsletter
Statistics
Customer service
Commercial prospecting
___________________

5. Recipients and Processors

  • TECHNICAL PROCESSORS

- Host: ___________ - Email provider: ___________ - Payment provider: ___________ - Analytics: ___________ - CRM: ___________ - Support/Ticketing: ___________

  • TRANSFERS OUTSIDE EU

- Yes / No - If yes, to which countries? ___________ - Safeguards in place: - Standard contractual clauses - Adequacy decision - Other: ___________

6. Cookies and Trackers

  • COOKIES USED

- Strictly necessary cookies (session, cart, authentication) - Analytics cookies (Google Analytics, Matomo, etc.) - Advertising cookies (Facebook Pixel, Google Ads, etc.) - Social media cookies (share buttons) - Other: ___________

  • CONSENT MANAGEMENT PLATFORM

- None - Axeptio - Didomi - Cookiebot - Other: ___________

7. Retention Periods

Data TypeProposed DurationJustification
Active customer accountDuration of relationship
Inactive customer account3 years after last activityProspecting
Prospects3 years without interactionCNIL recommendation
Invoices10 yearsLegal obligation
Connection logs1 yearLCEN
Cookies13 months maxCNIL recommendation

Drafting Workflow

Step 1: Template Selection (MANDATORY)

NEVER DRAFT A POLICY FROM SCRATCH. Always start from a given template for drafting, either: - the default template in assets/sample_template_politique_confidentialite.docx; - another internal template provided by the user. This template is your base reference. You must: - Faithfully reproduce the template's structure and wording - Keep the exact template phrasing (they are validated) - Only replace placeholders with client information - Do NOT rewrite sentences even if you think you can phrase them better - Do NOT add sections that are not in the template The collected information (T&Cs, site, etc.) is used to fill in the template, not to rewrite it.

1. FIRST ACTION: Confirm the template to use BEFORE any drafting. Ask the user:

"I will draft the privacy policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"
OptionAction
Default templateUse assets/sample_template_politique_confidentialite.docx
Internal templateUse the document provided by the lawyer

2. Consider the user's choice and select the starting template.


Step 2: Understand the Client's Business

MAIN OBJECTIVE: Truly understand what the client does, their business, the user journey on their platform.

1. Ask the lawyer for available information:

"To draft a perfectly tailored policy, please provide:
- Information you have about the client and their business
- Existing documents (T&Cs, sales conditions, order forms, contracts...)
- Exchanges or key points raised by the client
- The site/application URL (if accessible)
- Points that must absolutely be included according to you

You may anonymize this information if necessary for confidentiality reasons.

The more information you provide, the better adapted the policy will be to the actual case. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."

2. Analyze the documents provided:

DocumentWhat we extract
T&Cs / Sales ConditionsPlatform operation, services offered, obligations
Order formsData collected, services, potential processors
Client exchangesKey points, specific concerns, business particularities

3. Additional research on the site (if accessible):

Note: Some sites only display a "Request a quote" form without access to the platform. In that case, rely primarily on the documents provided.

The objective is to understand the business AND identify technical elements:

  • Understand what the company actually does
  • Read the existing privacy policy (if present)
  • Read the existing T&Cs/Legal notices
  • Identify the typical user journey (if visible)
  • Identify data collection forms (registration, contact, order...)
  • Spot cookies/trackers via the banner
  • List features (account, newsletter, chat, payment...)

4. Summary before drafting:

CLIENT: [Name]
BUSINESS: [Description in 2-3 sentences]
PLATFORM TYPE: [SaaS, e-commerce, mobile app, etc.]
USER JOURNEY: [Key steps]
DATA COLLECTED: [List by collection point]
COOKIES IDENTIFIED: [Types of cookies spotted]
FORMS: [List of collection points]
KEY LAWYER POINTS: [What must absolutely be included]
SPECIFICITIES: [What makes this case particular]
Once the summary is ready → Proceed to Draft 1

Step 3: Draft 1

ABSOLUTE RULE: The template is your validated base. - START from the template: structure, wording, tone → this is your reference - ADAPT to the client case: integrate the specific information collected - DO NOT rewrite everything: keep the template wording, only adapt what needs to be In summary: Template + client information = Draft 1. Not a complete rewrite.

Complete the template section by section with the collected information:

  1. Identity of the data controller
  2. Data collected (by category)
  3. Purposes and legal bases (table)
  4. Recipients and processors
  5. International transfers
  6. Retention periods (table)
  7. Data subject rights
  8. How to exercise rights
  9. Cookies and trackers
  10. Data security
  11. Policy changes
  12. Contact
Immediate compliance check: Before presenting Draft 1, verify the mandatory disclosures checklist (Art. 13 GDPR): - Controller identity and contact details - DPO contact details (if appointed) - Processing purposes - Legal basis for each purpose - Legitimate interests pursued (if applicable) - Recipients or categories of recipients - Transfers outside EU and safeguards - Retention period or criteria for determination - Data subject rights (access, rectification, erasure, restriction, portability, objection) - Right to withdraw consent (if applicable) - Right to lodge a complaint with the CNIL - Whether data provision is mandatory/optional - Existence of automated decision-making (if applicable) If Draft 1 is compliant → Proceed to Step 3.

Step 4: Deliver Draft 1 + Benchmark + Improvement Suggestions

1. Deliver Draft 1 with explanation:

Here is Draft 1 of the privacy policy.

**What I took into account:**
- [Summary of key elements integrated]
- [Client specificities considered]
- [Particular points mentioned by the lawyer]

**Compliance:** The document meets Art. 13 GDPR requirements.

2. Present the benchmark (systematic):

Research 3-5 privacy policies from companies in the same sector, then present:

**Benchmark conducted:**

I analyzed the privacy policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]

**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
- [Improvement 3]: [explanation]

Would you like to incorporate these elements into the provided Draft?

3. If the lawyer approves improvements → Produce Draft 2.


Step 5: Final Verification

Final review before definitive delivery:

  • All Art. 13 GDPR disclosures present
  • Client information correctly integrated
  • Clear and accessible language
  • No internal references (template, sources) in final document
  • Update date present

Standard Policy Structure

PRIVACY POLICY
[Company Name]
Last updated: [DATE]

TABLE OF CONTENTS (if long document)

1. WHO ARE WE?
   - Controller identity
   - DPO contact details

2. WHAT DATA DO WE COLLECT?
   - Identification data
   - Browsing data
   - Transaction data
   - Etc.

3. WHY DO WE COLLECT YOUR DATA?
   - Purposes / legal bases table

4. WITH WHOM DO WE SHARE YOUR DATA?
   - Internal services
   - Processors
   - Partners (if consent)
   - Authorities (legal obligations)

5. IS YOUR DATA TRANSFERRED OUTSIDE THE EU?
   - Countries concerned
   - Safeguards

6. HOW LONG DO WE KEEP YOUR DATA?
   - Retention periods table by data type

7. WHAT ARE YOUR RIGHTS?
   - List of rights with simple explanation
   - How to exercise them

8. COOKIES AND TRACKERS
   - Types of cookies used
   - Preference management

9. SECURITY
   - Measures in place (without sensitive technical details)

10. CHANGES TO THIS POLICY
    - Notification procedure

11. CONTACT US
    - Email
    - Postal address
    - Link to form

Drafting Best Practices

Writing Style

DoAvoid
Use "you" / "your data"Use "the user" / "the data subject"
Short and simple sentencesExcessive legal jargon
Concrete examplesVague wording ("various data")
Tables for clarityDense paragraphs
Clear and explicit headingsMultiple cross-references without explanation

Accessibility

  • Clear language: understandable by a non-lawyer user
  • Visible structure: table of contents, numbered headings
  • Layered information: summary + details if needed
  • Update date: visible at top of document

Common Mistakes to Avoid

MistakeConsequenceSolution
Copy-paste from generic templateNon-compliance, inconsistencyAdapt to each case
Incorrect legal basesUnlawful processingAnalyze each purpose
Missing retention periodsNon-compliance Art. 13Systematic table
Forgetting transfers outside EUPotential fineCheck processors
Rights mentioned without proceduresRights unexercisableDedicated email address
Cookie wallProhibited by CNILRefusing as easy as accepting

CNIL Reference Sanctions

CompanyAmountMain Reason
Google€150MCookies: refusing more difficult than accepting
Facebook€60MCookies: no "reject all" button
Carrefour€3MInsufficient information, excessive retention
Amazon€35MCookies placed without consent
These sanctions illustrate the importance of a compliant policy and rigorous cookie management.

Frequently Asked Questions

1. Must the policy be in French?

Yes, if the site targets French users. It can be bilingual if the site is international.

2. Is a separate policy needed for the mobile app?

Not necessarily, but the policy must cover app-specific aspects (permissions, data collected by the device).

3. How to handle updates?

  • Date each version
  • Inform users of substantial changes
  • Keep previous versions

4. Is a DPO mandatory?

Not systematically. Mandatory if:

  • Public authority
  • Large-scale processing of sensitive data
  • Regular and systematic large-scale monitoring

Using This Guide

  1. Step 1 - Choose the template: Default, or lawyer's internal template
  2. Step 2 - Understand the business: Collect lawyer docs + site research
  3. Step 3 - Draft Draft 1: Complete template + compliance check
  4. Step 4 - Deliver + Benchmark: Present Draft 1 + systematic benchmark + improvement suggestions
  5. Step 5 - Finalize: Integrate approved improvements + final verification
TEMPLATE REMINDER: Never draft from scratch. Always start from the template and adapt it. SOURCES REMINDER: The CNIL and GDPR references in this guide are for the drafter. They should not appear in the final document, except for mandatory legal disclosures (right to lodge a complaint with CNIL, etc.).

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

32.36%
按下载量换算152

Claude

29.53%
按下载量换算138

Cursor

19.58%
按下载量换算92

Gemini CLI

10.1%
按下载量换算47

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills