vendor-privacy-policy-first-pass
Installation
SKILL.md
Vendor Privacy Policy First Pass
Conduct a fast triage assessment of a vendor's privacy policy to help the user decide whether deeper diligence is warranted before sharing data with the vendor. The output is a structured summary plus red-flag identification, not a full privacy assessment.
This skill is calibrated for the in-house counsel use case: a vendor has been proposed, the user has limited time, and the question is "does this policy contain anything that would change our decision to proceed, or does it look standard enough that we can move to DPA negotiation and security review?"
When this skill applies
Apply when the user provides a vendor's privacy policy (or what is presented as one) and asks for a quick assessment. Common triggers:
- Vendor proposed during procurement; quick read needed before deeper review.
- Vendor's published policy used as a baseline for DPA negotiation (the policy describes what the vendor says it does; the DPA captures what the vendor commits to do).
- Periodic re-review of an existing vendor's updated privacy policy.
- Pre-meeting prep before a vendor security/privacy review call.
Do not apply when: